
Senior Consultant – Cyber Resilience
Posted Aug 20

Posted Aug 20
This is a fully remote position, open to applicants in United States.
• Evaluate and enhance incident response, cyber resilience, and threat intelligence capabilities.
• Design or refine recovery operating models based on threat hunting scenarios, roles and responsibilities, escalation paths, and decision rights.
• Develop and improve cyber recovery plans, recovery runbooks, crisis playbooks, and communication procedures.
• Facilitate post-incident reviews, after-action evaluations, lessons-learned sessions, tabletop exercises, simulations, and technical recovery drills.
• Assess recovery dependencies across identity, networking, endpoints, applications, data, cloud platforms, backup infrastructure, and third-party services.
• Review backup and restore strategies, emphasizing isolation, immutability, recoverability, privileged-access controls, and validation testing.
• Identify critical attack paths, relevant threat intelligence sources, and exposure reconnaissance.
• Create strategic roadmaps to enhance anticipation and recovery capabilities.
• Assist in implementing prioritized enhancements with client technical teams and delivery partners.
• Lead purple-team-style validation of cyber recovery preparedness utilizing realistic attack paths and scenarios.
• Collaborate with both offensive and defensive security stakeholders to validate controls, telemetry, escalation paths, and recovery protocols.
• Leverage threat intelligence, exposure findings, attack-path analysis, and detection gaps to prioritize resilience enhancements.
• Identify control, telemetry, and detection improvements to decrease the time required to contain, investigate, and recover.
• Integrate vulnerability, exposure, detection, and recovery data into risk-informed resilience initiatives.
• Contribute to assessments regarding compromise assumptions, blast radius, and recovery sequencing.
• Provide insights to upstream security capabilities based on findings from incidents and exercises.
• Organize workshops with technical, operational, risk, and executive stakeholders.
• Produce assessment reports, target-state designs, strategic roadmaps, playbooks, exercise materials, and executive briefings.
• Act as a trusted advisor during high-stakes resilience and recovery efforts.
• Contribute reusable methodologies, accelerators, reference architectures, and perspectives to AHEAD’s cyber resilience practice.
• Mentor consultants and collaborate with account, delivery, and technical leadership.
• Assist in proposal development, scoping, estimation, and solution shaping.
• Extensive experience in cybersecurity consulting, incident response, cyber recovery, disaster recovery, business continuity, or a closely related field.
• Proven experience in designing, assessing, testing, or enhancing incident response and recovery capabilities.
• Strong comprehension of enterprise infrastructure and security environments, including identity, endpoints, networks, cloud, applications, data, backups, and third-party dependencies.
• Ability to differentiate and integrate cyber recovery, IT disaster recovery, business continuity, and crisis management practices.
• Experience in facilitating tabletop exercises, simulations, post-incident evaluations, or recovery testing.
• Capability to articulate complex technical risks and recovery decisions to both practitioners and executives.
• Strong consulting abilities, including workshop facilitation, structured problem-solving, written communication, and stakeholder management skills.
• Willingness to travel for client engagements as necessary.
• Preferred: Experience with ransomware recovery, destructive attacks, identity compromise, cloud recovery, or major cyber incident response.
• Preferred: Experience in developing recovery architectures, clean-room or isolated recovery environments, cyber vaults, immutable backups, or recovery validation programs.
• Preferred: Background in security operations, detection engineering, threat hunting, threat intelligence, attack-path analysis, or exposure management.
• Preferred: Familiarity with NIST CSF, NIST SP 800-61, NIST SP 800-34, CISA guidance, ISO 22301, ISO 27001, or similar frameworks.
• Preferred: Relevant certifications such as CISSP, CISM, CBCP, CRISC, GCIH, GCIA, GCFA, or equivalent experience.
• Preferred: Experience operating in regulated, complex, or highly available environments.
• Preferred: Experience in building offerings, methodologies, or delivery practices within a consulting organization.
• Medical, Dental, and Vision Insurance.
• 401(k) plan.
• Paid company holidays.
• Paid time off.
• Paid parental and caregiver leave.
• Encouragement for cross-department training and development.
• Sponsorship for certifications and credentials for ongoing learning.
• Access to a multi-million-dollar technology lab.
• Option to opt-out of AI application and resume review without penalty.
• Option to opt-out of interview recording and transcription without penalty.
Get handpicked remote jobs straight to your inbox weekly.