Rodeo
Get started

CyberClan

PBR Specialist

United Kingdom
Posted 1 day ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

CyberClan

CyberClan provides enterprise security, and human response to small and midsize enterprises and channel partners through comprehensive risk assessment services, 24/7/365 managed detection and response services, and lightning-fast breach response. Formerly known as Network Test Labs established in Canada and specializing in vulnerability assessments and penetration testing in the gaming industry, CyberClan has grown from three employees in 2006 in one market to over 75 employees with clients in nine countries and offices in Australia, Canada, United Kingdom, and United States as a leading Managed Services Provider.

Our mission is to make the online world a safer and more secure place by delivering sophisticated cybersecurity solutions in a highly personalized — and human — way.

PBR Specialist

CyberClan is hiring a PBR Specialist who will be technically hands-on and deployed to client environments in the wake of confirmed ransomware or destructive cyber incidents to rapidly restore business operations and harden infrastructure against re-compromise. Working under high pressure alongside DFIR, threat intelligence, and ransomware negotiation teams, the specialist takes full ownership of complex remediation workstreams while strictly operating within the chain of evidence. Beyond technical execution, the position demands strong decision-making to secure the environment and produce defensible documentation tailored for the client, cyber insurers, and external counsel.

The successful candidate will work closely with the Director of Global Incident Response Operations. The ideal candidate will have an energetic, can-do attitude and be comfortable working in a metrics-driven environment, delivering results and supporting team members.

Key Responsibilities

Incident response and recovery

  • Mobilize to client engagements (remote and on-site) within agreed CyberClan SLA windows following ransomware, wiper, or destructive intrusion events.
  • Execute the CyberClan PBR playbook across endpoint, server, hypervisor, identity, network, and backup domains.
  • Coordinate with the lead DFIR investigator to ensure remediation activity does not compromise forensic evidence or active threat actor monitoring.
  • Identify and eradicate threat actor persistence (scheduled tasks, services, run keys, web shells, rogue accounts, GPO modifications, OAuth grants).

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Systems remediation

  • Rebuild or restore Windows Server, Linux, and virtualized infrastructure (VMware vSphere, Hyper-V, Nutanix).
  • Reset and rotate domain credentials, including dual krbtgt resets, service account rotation, and KRBTGT golden ticket invalidation.
  • Restore Active Directory from clean backup or rebuild forest where compromise is total.
  • Deploy or redeploy EDR (CrowdStrike Falcon, Sentinel One, Microsoft Defender for Endpoint) across the recovered estate before reconnection.
  • Validate backup integrity, perform clean-room restoration, and document restore lineage.

Network remediation

  • Rebuild and harden firewall rule sets (Fortinet, Palo Alto, Cisco ASA/FTD, Check Point).
  • Implement segmentation between corporate, OT, management, and recovery VLANs.
  • Reissue VPN credentials and certificates. Disable legacy remote access (RDP exposed, unsupported SSL VPN versions).
  • Restore routing, switching, and wireless infrastructure to a known-good state.

Identity and cloud

  • Remediate Entra ID / Azure AD compromise: revoke tokens, audit conditional access, remove rogue applications and consent grants, reset privileged accounts.
  • Harden Microsoft 365 tenancies (MFA enforcement, legacy auth disable, mailbox forwarding audit).
  • Address AWS, Azure, and GCP compromise where in scope (IAM rotation, key revocation, cloud trail review).

Hardening and handover

  • Implement post-incident hardening: LAPS, tiered admin model, application allowlisting, attack surface reduction rules, PowerShell logging.
  • Produce client-facing remediation reports detailing actions taken, residual risk, and recommended longer-term improvements.
  • Support handover to the client's BAU IT and security teams or to CyberClan's managed services where applicable.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Reporting and continuous improvement

  • Contribute to engagement debriefs and playbook refinement.
  • Feed observed threat actor TTPs back into CyberClan's threat intelligence function.
  • Maintain accurate engagement timesheets and case notes for insurer and legal review.

Skills, Knowledge and Experience:

  • Minimum 4 years in a technical infrastructure, sysadmin, or security engineering role.
  • Demonstrable hands-on experience rebuilding compromised Active Directory environments.
  • Strong working knowledge of Windows Server (2016 through 2025), Group Policy, and PowerShell scripting.
  • Practical experience with at least one major hypervisor platform (VMware vSphere or Hyper-V).
  • Experience deploying at least one enterprise EDR product.
  • Working knowledge of enterprise backup platforms (Veeam, Rubrik, Commvault, Cohesity) including immutable backup concepts.
  • Ability to operate under pressure, in unfamiliar environments, with incomplete information.
  • Willingness to travel at short notice.

Preferred Qualifications

  • At least 1 years’ experience in incident response, DFIR, or post breach remediation.
  • Cloud incident response experience (Azure, AWS, GCP).
  • OT/ICS exposure.
  • Microsoft 365 / Entra ID forensics and remediation.
  • PowerShell, Python, or Bash automation for at-scale remediation tasks.
  • Experience working within an insurer-led engagement model and workflows.
  • Familiarity with current ransomware threat actor TTPs (LockBit successors, Akira, Kairos, Play, BlackBasta variants, RansomHub).
  • Prior consulting or MSP background.

Attributes

  • Calm under pressure. Engagements are time critical.
  • Clear written and verbal communication.
  • Capable of explaining technical decisions to non-technical stakeholders including C-suite, legal, and insurers.

Benefits

  • Annual Leave
  • Wellness Leave
  • Birthday Day
  • Pension

Job Type

Full-time

Location

100% Telecommuting

Must be authorized to work in Canada

% of Travel Required

75%

Physical Requirements

Prolonged periods of sitting at a desk and working on a computer

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Incident Response
Post Breach Remediation
Active Directory Recovery
Windows Server
PowerShell
VMware vSphere
Hyper-V
EDR Deployment
Backup Integrity Validation
Firewall Hardening
Entra ID Remediation
Cloud Security
Network Segmentation
DFIR
Threat Actor TTPs
Infrastructure Hardening

Location

United Kingdom

Sign up to applySee more jobs like this