Overview
Skills
Job Details
Job Title: IR Recovery Lead
Location: Remote
Contract Duration: 6 Months
Employment Type: Contract
Position Overview: A leading organization is seeking a seasoned Incident Response (IR) Recovery Lead for a 6-month remote contract. This role serves as the primary cybersecurity point of contact during recovery operations, providing leadership and strategic direction to internal teams and stakeholders. The IR Recovery Lead will ensure that all recovery and restoration activities follow security best practices, comply with relevant regulations, and maintain operational stability.
Key Responsibilities
Act as the lead security liaison for all stakeholders throughout incident response and recovery processes.
Coordinate and oversee the restoration of critical IT services, systems, and functions with a focus on security, manageability, and stability.
Develop, maintain, and execute incident recovery plans aligned with business continuity and disaster recovery strategies.
Prioritize and plan recovery tasks based on business needs and risk assessments.
Collaborate with the Project Management Office (PMO) to provide regular updates on progress, risks, and escalations.
Ensure adoption of industry-standard best practices in incident response, cybersecurity operations, and post-incident remediation.
Guide technical teams in applying security controls during restoration to reduce future vulnerabilities.
Participate in post-incident reviews, document lessons learned, and recommend long-term improvements.
Required Qualifications
5+ years of experience in cybersecurity incident response and recovery leadership.
Demonstrated ability to lead cross-functional recovery efforts under high-pressure conditions.
Strong understanding of security frameworks such as NIST and ISO 27035, along with the incident response lifecycle.
Experience working with security operations, forensics, and cybersecurity analysis teams.
Excellent communication, coordination, and documentation skills.
Ability to perform effectively in fully remote, high-stakes environments.
Preferred Qualifications
Relevant industry certifications (e.g., CISSP, CISM, GCIH, CRISC).
Experience in disaster recovery, business continuity, or crisis management.
Knowledge of recovery best practices for cloud environments (AWS, Azure, Google Cloud Platform).