
Senior Consultant – Cyber Resilience
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Evaluate and enhance incident response, cyber resilience, and threat intelligence capabilities.
• Design or refine recovery operating models based on threat hunting scenarios, roles and responsibilities, escalation paths, and decision rights.
• Develop and improve cyber recovery plans, recovery runbooks, crisis playbooks, and communication procedures.
• Facilitate post-incident reviews, after-action assessments, lessons-learned sessions, tabletop exercises, simulations, and technical recovery exercises.
• Assess recovery dependencies across identity, networking, endpoints, applications, data, cloud platforms, backup infrastructure, and third-party services.
• Evaluate backup and restore strategies, including isolation, immutability, recoverability, privileged-access controls, and validation testing.
• Define critical attack paths, relevant threat intelligence sources, and exposure reconnaissance.
• Create roadmaps to enhance anticipation and recovery capabilities.
• Assist in implementing prioritized improvements with client technical teams and delivery partners.
• Lead purple-team-style validation of cyber recovery readiness using realistic attack paths and scenarios.
• Collaborate with offensive-security and defensive-security stakeholders to validate controls, telemetry, escalation paths, and recovery procedures.
• Utilize threat intelligence, exposure findings, attack-path analysis, and detection gaps to prioritize resilience enhancements.
• Identify control, telemetry, and detection improvements to reduce the time needed to contain, investigate, and recover.
• Connect vulnerability, exposure, detection, and recovery data into risk-informed resilience strategies.
• Contribute to assessments of compromise assumptions, blast radius, and recovery sequencing.
• Provide feedback to upstream security capabilities based on incident and exercise outcomes.
• Lead workshops with technical, operational, risk, and executive stakeholders.
• Produce assessment reports, target-state designs, roadmaps, playbooks, exercise materials, and executive briefings.
• Act as a trusted advisor during high-stakes resilience and recovery initiatives.
• Contribute reusable methods, accelerators, reference architectures, and insights to AHEAD’s cyber resilience practice.
• Mentor consultants and collaborate with account, delivery, and technical leadership.
• Assist in proposal development, scoping, estimation, and solution shaping.
• Extensive experience in cybersecurity consulting, incident response, cyber recovery, disaster recovery, business continuity, or a closely related field.
• Proven experience in designing, assessing, testing, or enhancing incident response and recovery capabilities.
• Strong understanding of enterprise infrastructure and security environments, including identity, endpoints, networks, cloud, applications, data, backups, and third-party dependencies.
• Ability to differentiate and integrate cyber recovery, IT disaster recovery, business continuity, and crisis management practices.
• Experience facilitating tabletop exercises, simulations, post-incident reviews, or recovery testing.
• Ability to effectively communicate complex technical risks and recovery decisions to both practitioners and executives.
• Strong consulting skills, including workshop facilitation, structured problem solving, written communication, and stakeholder management.
• Willingness to travel for client engagements as needed.
• Preferred: Experience with ransomware recovery, destructive attacks, identity compromise, cloud recovery, or significant cyber incident response.
• Preferred: Experience in developing recovery architectures, clean-room or isolated recovery environments, cyber vaults, immutable backups, or recovery validation programs.
• Preferred: Experience with security operations, detection engineering, threat hunting, threat intelligence, attack-path analysis, or exposure management.
• Preferred: Familiarity with NIST CSF, NIST SP 800-61, NIST SP 800-34, CISA guidance, ISO 22301, ISO 27001, or similar frameworks.
• Preferred: Relevant certifications such as CISSP, CISM, CBCP, CRISC, GCIH, GCIA, GCFA, or equivalent experience.
• Preferred: Experience operating in regulated, complex, or highly available environments.
• Preferred: Experience in building offerings, methodologies, or delivery practices within a consulting organization.
• Medical, Dental, and Vision Insurance.
• 401(k) plan.
• Paid company holidays.
• Paid time off.
• Paid parental and caregiver leave.
• Promotion of cross-department training and development.
• Sponsorship of certifications and credentials for ongoing education.
• Access to a multi-million-dollar technology lab.
• Opt-out options for AI application and resume review without penalty.
• Opt-out options for interview recording and transcription without penalty.
Sprout Social, Inc.
Premier Inc.
Devoir Software Solutions
Get handpicked remote jobs straight to your inbox weekly.