Incident Recovery Lead/ Remote , 1 Months Contract

Posted yesterday

suncap technologyDenver (CO)

SENIORITY

Manager

Apply

About the role

Incident Recovery LeadThe Incident Recovery Lead is responsible for coordinating and overseeing all recovery operations following a cybersecurity incident, such as a ransomware attack, data breach, or advanced persistent threat (APT). This role ensures the timely restoration of critical business operations, infrastructure, and data while maintaining security integrity and minimizing business impact. The individual acts as the primary liaison between executive leadership, IT teams, security operations, and external partners during recovery efforts.
Key Responsibilities: Lead the end-to-end recovery process following a cybersecurity incident, ensuring containment, eradication, and secure restoration of systems. Develop and execute a structured recovery plan, including prioritization of critical systems, applications, and services. Coordinate with internal and external forensic teams to validate system integrity prior to restoration. Establish recovery milestones and provide executive-level updates on progress, risks, and estimated time to recovery. Direct efforts to rebuild or restore compromised environments, including Active Directory, backup infrastructure, storage systems, virtualization platforms, network architecture, and business applications. Validate the security posture of restored systems by leveraging endpoint detection tools, vulnerability assessments, and configuration baselines. Collaborate with SOC, IR teams, and MSSPs to ensure post-recovery monitoring is in place to detect potential re-entry attempts. Serve as the primary point of contact for stakeholders during the recovery phase, including executive leadership, regulators, and third-party vendors. Ensure consistent and transparent reporting to the Incident Commander/CISO regarding recovery status and obstacles. Facilitate cross-functional collaboration between IT operations, cybersecurity, business continuity, and legal/compliance teams. Document lessons learned and lead post-incident reviews to improve recovery playbooks and processes. Recommend enhancements to infrastructure resilience, backup architecture, and segmentation strategies based on incident findings. Ensure alignment of recovery strategies with business continuity/disaster recovery (BC/DR) requirements and compliance standards
Qualifications:
  • 7+ years of experience in cybersecurity, incident response, or IT infrastructure recovery roles.
  • Proven expertise in leading post-cyberattack recovery efforts in complex enterprise environments.
  • Strong architecture and engineering understanding of Active Directory, backup infrastructure, storage, virtualization, network architecture, and business applications.
  • Experience coordinating with forensic teams and interpreting forensic findings to guide recovery decisions.
  • Familiarity with cybersecurity frameworks such as NIST, MITRE Telecommunication&CK, and CIS Controls.
  • Exceptional leadership and crisis management capabilities.
  • Strong communication skills with the ability to present technical information to non-technical stakeholders.
  • Ability to remain calm and decisive under high-pressure, time-sensitive situations.
  • CISSP, CISM, or CISA.GIAC Certified Incident Handler (GCIH) or GIAC Certified Forensic Analyst (GCFA).ITIL or Certified Business Continuity Professional (CBCP).Key Performance Indicators (KPIs)
  • Time to restore critical business operations post-incident.
  • Reduction in recurrence of similar incidents.
  • Stakeholder satisfaction with recovery communications and outcomes.
  • Implementation of post-incident recommendations and improvements.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this