At-Bay Logo

At-Bay

Senior DFIR Recovery Specialist

Reposted 9 Days Ago
Easy Apply
Remote or Hybrid
Hiring Remotely in US
115K-130K Annually
Senior level
Easy Apply
Remote or Hybrid
Hiring Remotely in US
115K-130K Annually
Senior level
The Senior DFIR Recovery Specialist oversees incident response processes, engages with IT and Security teams, provides security expertise, and identifies risk gaps.
The summary above was generated by AI

Why you should join our At-Bay Security team:

At-Bay is a fast-growth InsurSec company (Insurance x Cybersecurity) on a mission to bring innovative products to the market that help protect small businesses from digital risks. As an InsurSec provider, we uniquely combine insurance with mission-critical security technologies, threat intelligence, and human expertise, to bridge the critical security capability gap that exists among SMBs in the community. We believe InsurSec is an $80B market opportunity and we are excited to introduce our Senior Incident Response Recovery Specialist role to the security team in order to help expand our reach and influence in the business and security community, of which we serve 40,000 customers.

The Role:

We seek an experienced Incident Response Recovery Specialist to join the At-Bay Response & Recovery team. The Senior DFIR Recovery Specialist will support the Response & Recovery remediation team and report to our Incident Response Engineer.

Responsibilities:

  • Accountable for overseeing, measuring, and driving efforts to systematically increase the maturity and effectiveness of cyber security incident response and recovery processes, setups, and controls for At-Bay’s Response and Recovery Team.
  • Gains and helps maintain an end-to-end understanding of relevant client landscape (networks, endpoints, platforms, applications, dependencies, cloud services, on-premise setups, etc.).
  • Engages with global and local operational Security & IT teams, collaborates closely with all relevant functions across the client base, and consults with external experts & stakeholders.
  • Provides deep security expertise in the context of reviews of detection measures, post-mortem analysis of cyber incident responses, and IT recovery exercises; supports and helps coordinate major real cyber security events.
  • Provides assurance & evidence for the formal security control objectives in this area and contributes accordingly to the overall needs of At-bay’s clients.
  • Identifies gaps in detection, response, recovery controls, and details and drives security risk reduction activities.

In this role, we value:

  • Great educational background, preferably in the fields of computer science or engineering for technical project managers.
  • Proven working experience as a project administrator in the information technology sector.
  • Solid technical background, with understanding or hands-on experience in Windows, Linux, and OSX
  • Excellent client-facing and internal communication skills.
  • Excellent written and verbal communication skills.
  • Solid organizational skills, including attention to detail and multi-tasking skills.

Required Skills:

  • Play a key role in post-breach firewall reconfiguration, including rule audits, segmentation updates, and blocklist implementations to harden perimeter defenses.
  • Collaborate with threat intel and SOC teams to develop and deploy IOCs and custom firewall rulesets (e.g., Palo Alto, Fortinet, Cisco ASA) during active incident response.
  • Create and execute firewall recovery workflows to ensure secure rollback and containment during ransomware and APT-level incidents.
  • Install/Replace, configure, and optimize network hubs, routers, and switches (e.g., higher-level protocols, tunneling).
  • Develop and implement network backup and recovery procedures.
  • Diagnose network connectivity problems.
  • Implement new system design procedures, test procedures, and quality standards.
  • Install and maintain network infrastructure device operating system software (e.g., windows OS, virtual machines).
  • Integrate new systems into existing network architecture.
  • Monitor network capacity and performance.
  • Skill in writing code in a currently supported programming language (e.g., Java, Python, PowerShell).
  • Patch network vulnerabilities to ensure that information is safeguarded against outside parties.
  • Provide feedback on network requirements, including network architecture and infrastructure.
  • Test and maintain network infrastructure, including software and hardware devices.
  • An understanding of forensic data collection tools and procedures is a plus.

Work location:

  •  USA, Remote ( EST )
  •  Travel 50–75% to client locations primarily along the East Coast; flexibility to travel nationwide as needed.

Our estimated base pay range for this role is $115,000 - $130,000 per year. Base salary is determined by a variety of factors including but not limited to market data, location, internal equitability, domain knowledge, experiences and skills. In general, if the position sparks your interest we encourage you to apply - our team prioritizes talent.

 #LI-CK1

Top Skills

Cisco Asa
Fortinet
Java
Linux
Osx
Palo Alto
Powershell
Python
Windows

Similar Jobs

2 Hours Ago
Remote or Hybrid
110K-125K Annually
Mid level
110K-125K Annually
Mid level
Fintech • Machine Learning • Payments • Software • Financial Services
The Lead Account Executive supports partners by managing operational projects, onboarding, training, resolving escalated issues, and ensuring compliance with regulations while maintaining risk management.
Top Skills: Proprietary Tools And SystemsTransaction Processing Systems
3 Hours Ago
Easy Apply
In-Office or Remote
IN, USA
Easy Apply
Mid level
Mid level
Healthtech • Pharmaceutical • Telehealth
Review consumer-facing medical content for accuracy, fact-check data, provide feedback to editors, and ensure alignment with medical guidelines and style guides.
Top Skills: Google DocsPubmed
3 Hours Ago
Remote or Hybrid
Texas, USA
73K-122K Annually
Senior level
73K-122K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
The Cloud Support Engineer collaborates with customers post-implementation, resolves support issues, and ensures high satisfaction with SailPoint's IdentityNow product.
Top Skills: .NetActive DirectoryC++HTMLJavaLdapLinuxMssqlMySQLOracleSAMLSpml/SoapSybaseUnixWindowsXML

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account