Post Breach Remediation Specialist

CyberClan - United States

Hiring: Post Breach Remediation Specialist Company: CyberClan Location: United States Job Posted Time: 2026-09-10 13:21:18 Employment Type: Full-time / Remote Target Skills & Keywords : AWS, Azure, Azure AD, Bash, GCP, IAM, Linux, OAuth, Penetration Testing, PowerShell, Python, SSL, VPN, Windows Server About the job Experience: •4 years in a technical infrastructure, sysadmin, or security engineering role. •1 years’ experience in incident response, DFIR, or post breach remediation. •Minimum 4 years in a technical infrastructure, sysadmin, or security engineering role. •At least 1 years’ experience in incident response, DFIR, or post breach remediation. Required Skills: •The successful candidate will work closely with the Director of Global Incident Response Operations. The ideal candidate will have an energetic, can-do attitude and be comfortable working in a metrics-driven environment, delivering results and supporting team members. •Mobilize to client engagements (remote and on-site) within agreed CyberClan SLA windows following ransomware, wiper, or destructive intrusion events. •Execute the CyberClan PBR playbook across endpoint, server, hypervisor, identity, network, and backup domains. •Coordinate with the lead DFIR investigator to ensure remediation activity does not compromise forensic evidence or active threat actor monitoring. •Identify and eradicate threat actor persistence (scheduled tasks, services, run keys, web shells, rogue accounts, GPO modifications, OAuth grants). •Rebuild or restore Windows Server, Linux, and virtualized infrastructure (VMware vSphere, Hyper-V, Nutanix). •Reset and rotate domain credentials, including dual krbtgt resets, service account rotation, and KRBTGT golden ticket invalidation. •Restore Active Directory from clean backup or rebuild forest where compromise is total. Qualifications: •Cloud incident response experience (Azure, AWS, GCP). •Microsoft 365 / Entra ID forensics and remediation. •PowerShell, Python, or Bash automation for at-scale remediation tasks. •Operational familiarity with current ransomware threat actor TTPs (LockBit successors, Akira, Kairos, Play, BlackBasta variants, RansomHub). •Prior consulting or MSP background. •Calm under pressure. Engagements are time critical. •Clear written and verbal communication. •Capable of explaining technical decisions to non-technical stakeholders including C-suite, legal, and insurers. •Prolonged periods of sitting at a desk and working on a computer Compensation: •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!