Sr. Remediation Specialist (AIR)

Alert Logic
Alert Logic

Marketing & Communications

United States

Posted on Aug 7, 2026
LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services.Role Expectations:The Principal Remediation Specialist is a senior level position with the scope to develop and grow the restoration capability within the AIR practice. The primary goal of each engagement is to recover our clients to an operating capacity post incident. Key Attributes:Business Support Support the development of bids / proposals associated with the opportunities identified usually from our Digital Forensics and Incident Response practice.Work clients and our sales teams with the generation of SOWs. Data Collection / Set-up Deployment of client-side data and log collection solutionsAssist with forensic collection requestsInstall Remote Monitoring and Management (“RMM”) utility and/or establish VPN credentials for remote accessDeployment of Forensic tools e.g. (SentinelOne / Velociraptor)Develop shared inventory tracking document Threat Actor Removal Technical engineering efforts to remove the threat actorsAcquire third party products and services necessary to remove the threat actors and rebuild, recover, stabilize, and secure the Customer systems and environmentsBlock IOCs within network firewalls as provided by forensics providerPerform impact assessment of servers to determine viability in cooperation with forensics provider Environment Re-Build Rebuild, recover, stabilize, and secure systemsRestoration/ rebuild/ decryption of serversAD Health review and rebuildDomain controller rebuilds and AD hardeningConfigure segregated networksHypervisor configurationsLAPS (Local Administrator Password Solution) configurationTroubleshooting, impact to and recovery options for ExchangeRemote site Firewall Firmware update assistance Legal / Comms Work with Company, Customer’s General Counsel, Customer’s insurance carrier, and any applicable third parties Desired Experience:Due to the varied nature of client systems; as wide and diverse experience across multiple technologies and solutions is preferable. Typical technologies and solutions include:Leadership More than 10 years in IT / Network / Cloud Engineering rolesLeading enterprise recovery type projectsDisaster Recovery planningVMware/Hyper-V, AWS/Azure/GCP recoveryIaC – Infrastructure as Code (Terraform, Ansible) Network Recovery SME Veeam, Commvault, Rubrik, Cohesity Cloud Recovery SME Cloud/SaaS adminAWS/Azure Security Engineer Infrastructure & Backup Tools VMware vSphere, Hyper-V, AWS Backup, Azure Site RecoveryVeeam, Commvault, Rubrik, Cohesity, ZertoImmutable storage: S3 Object Lock, Wasabi Immutable, Dell Data Domain Network Tools Firewalls: Palo Alto, Cisco ASA/FTD, SonicWall, WatchguardMonitoring: SolarWinds, NetFlow analyzers, WiresharkSegmentation: VLANs, Illumio, Guardicore Endpoint Tools EDR/XDR: CrowdStrike, Defender ATP, SentinelOneRMM: Screen Connect, Kaseya, NinjaOneMDM: Intune, JAMF, Workspace ONEImaging: MDT, Clonezilla, Acronis Cloud & SaaS Recovery Tools AWS/Azure/GCP recovery playbooksSaaS backup: Spanning, Druva, AvePointIAM monitoring: CloudTrail, Azure Sentinel Communication & Coordination Tools Project Management: Connectwise, AutoTask, AteraSecure comms: Signal, MS Teams with eDiscoveryCrisis platforms: xMatters, EverbridgeDocumentation: Confluence, SharePoint, ServiceNow Testing & Validation Tools Red/Yellow/Green segmented environmentsSandbox for malware testing: Cuckoo, AnyRunCyber range and tabletop testing platforms Qualifications: Relevant academic degreeCISM or CISSP (or a commitment to obtain within 12 months)GCWN, ITIL, DRII CertifiedCCNP Security, PCNSE, GCIAMicrosoft 365 Certified, JAMF, Security+Veeam Certified, GEBRCCSP, CCSK Education: A high school diploma or equivalent is required; a college or university degree is a plus. Why Join LevelBlue?At LevelBlue, you’re not just an employee—you’re part of a team making a real difference in the world of cybersecurity. We foster a culture of innovation and creativity where your contributions are valued, and you’ll have the support and resources to grow and thrive.Benefits and Perks: Comprehensive medical, dental, and vision insurance.401(k) with employer matching.Generous paid time off and holidays.Flexible spending accounts and health savings accounts.Employee assistance programs.Training and development opportunities.Adoption assistance program. This role is open to candidates legally authorized to work in the United States. At LevelBlue, we support flexible work and bring people together in person for key moments based on role, team, and business needs.LevelBlue is committed to a culture of respect, inclusion, and equal opportunity. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other status protected under applicable law.To all agencies: Please do not contact LevelBlue employees outside of the Talent Acquisition team. LevelBlue’s policy is to only accept resumes from agencies through its approved agency process and with a valid agreement in place. Any resume submitted outside this process will be considered the property of LevelBlue, and no fee will be paid if a candidate is hired from such a submission. #LI-MC1