Skip to main content
AfterDuty

Cyber Response & Recovery - Manager (Remediation focus)

KPMG · London, Greater London

Type
Full-time
Posted
10 days ago

Overview

Job details *Location:*London, Manchester *Capability:*Advisory *Experience Level:*Manager *Type:*Full Time *Business Area:*Cyber *Contract type:*Permanent Job description Cyber Response & Recovery Manager (Remediation) This role requires current SC or DV clearance, or eligibility and willingness…

About this role

Job details

*Location:*London, Manchester

*Capability:*Advisory

*Experience Level:*Manager

*Type:*Full Time

*Business Area:*Cyber

*Contract type:*Permanent

Job description

Cyber Response & Recovery Manager (Remediation)

This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance.

The Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG’s Cyber Advisory practice.

Your specific focus will be in the domain of recovery and remediation post incident. Our clients continue to face increasingly destructive cyber threats, particularly ransomware, destructive malware, business email compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience.

This is a hands-on cyber response and recovery manager role, focused on supporting clients through the most operationally critical phase of a cyber incident: restoring business services safely and securely. The role will work closely with incident response leads, forensic teams, legal advisers, crisis management teams, technology teams and client executives to convert incident findings into practical remediation, rebuild and recovery actions.

As a cyber response recovery manager, you will help clients stabilise their environment, remove attacker persistence, restore identity and infrastructure services, support patching and vulnerability remediation, advise on secure rebuild patterns, review and redesign network architecture, establish isolated recovery environments, and define phased recovery and security improvement roadmaps.

This role is particularly suited to someone with strong hands-on infrastructure, systems administration and cyber security experience, who can operate effectively during high-pressure incidents and provide pragmatic, technically credible advice to clients. The successful candidate should be comfortable working across Windows, Linux, Active Directory, virtualisation, networking, cloud and enterprise infrastructure technologies, and should be able to translate technical remediation requirements into clear recovery plans for both technical and senior stakeholder audiences.

KPMG is one of a small number of Tier 1 incident response providers in the UK. As such, this role provides the opportunity to work on complex, high-profile cyber incidents across a wide range of sectors. You will gain significant experience supporting clients during moments of critical need and will have the opportunity to develop both your technical recovery expertise and incident leadership capability.

When not responding to live incidents, you may support clients with cyber resilience, recovery readiness and post-incident transformation engagements. This may include developing recovery playbooks, designing isolated recovery environments, assessing Active Directory and infrastructure resilience, supporting ransomware recovery planning, reviewing network segmentation, improving backup and restore strategies, and helping clients define cyber security improvement roadmaps.

You will also contribute to the development of KPMG’s own cyber recovery capability, including standard operating procedures, technical recovery playbooks, tooling, automation, lab environments, recovery architecture patterns and team training.

Our clients expect that cyber-incidents will be tackled with urgency, therefore, there is an expectation that you will be flexible in terms of working hours and be on call (on a rotation basis). In addition, you should be prepared to travel on short notice for periods up to 2 or 3 weeks at a time.

Above all, KPMG is looking for someone who is passionate about helping clients recover from cyber incidents in a safe, structured and sustainable way. In return, KPMG is committed to supporting your development, technical growth and progression into senior cyber response and recovery leadership roles.

Why join us?*

One of only nine UK Tier 1 incident response providers

Access to nationally significant incidents

Exposure across government and critical infrastructure

Investment in certifications and training

Opportunity to shape a rapidly growing capability

What will you be doing?*

This role is not a pure incident response role. It is a hands-on cyber recovery role focused on helping clients restore services, remediate compromised infrastructure and build stronger security foundations after a cyber incident.

The ideal candidate will combine

Deep infrastructure and systems administration experience.

Strong cyber security and incident response understanding.

Hands-on remediation and recovery capability.

Active Directory, Windows, Linux and network architecture expertise.

The ability to lead technical workstreams during high-pressure incidents.

The ability to define and execute short, medium and long-term security roadmaps.

Further responsibilities will include

The Cyber Response Recovery Manager will be responsible for leading and supporting cyber recovery workstreams during active cyber incidents and post-incident remediation programmes. Responsibilities will include:

Lead cyber recovery workstreams during major incidents, working closely with incident response, forensic, client IT, legal, insurer and senior stakeholder teams, translating incident findings into clear remediation and recovery actions.

Deliver hands-on remediation across enterprise environments, including Active Directory recovery and hardening, Windows/Linux systems, network, cloud, endpoint and security tooling, with a focus on removing attacker persistence and restoring trust.

Drive patching and vulnerability remediation activities, prioritising actions based on business risk, threat actor behaviour and incident context.

Review and redesign network architecture and security controls, including segmentation, firewall rules, and administrative access pathways, to reduce reinfection risk and improve resilience.

Establish and support secure recovery environments and rebuild strategies, including isolated environments, backup validation, restore sequencing, and secure restoration of business-critical services.

Define and execute phased recovery and transformation plans, including immediate stabilisation, structured remediation, and security improvement roadmaps and rebuild standards.

Manage end-to-end delivery of recovery engagements, including stakeholder communication, project management, reporting, proposals, capability development, and mentoring junior team members.

The Person*

You should have a strong background in cyber-security and incident response. For example: You should be able to guide a client through an unstructured incident response process (such as an advanced network intrusion) – managing resources and defining objectives at each stage of the incident response process; scoping and triage, containment, evidence preservation and extraction, eradication, recovery, forensic analysis and investigation.

A broad understanding of the cyber security threat landscape.

Strong technical background in computers and networks, and programming skills.

Significant and proven experience of dealing with cyber security incidents and associated response measures.

Experience of managing a rapid deployment incident response team.

Excellent interpersonal, written and communication skills.

Understanding of a wide range of information security and IT methodologies, principles, technologies and techniques.

A genuine interest and desire to develop and mention junior team members.

Strong attention for detail and the ability to manage multiple simultaneous cases.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 86/100

  • Incident command & response
  • Investigative casework
  • Training & coaching delivery

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Cyber Security Consultant

    Searchability · London

    Contract

    £570 a dayEstimated

    Cyber Security Consultant – Preston, Birmingham or London, UK •    Up to £570 per day, Inside IR35, •    Hybrid working with 2 days onsite •    Active SC clearance required •    3-month contract duration ABOUT THE CLIENT: Our client is a well-established technology consultancy delivering critical…

    Posted 4 days ago

  • Information Security Engineer

    Freshfields · London

    Full-time

    Role summary/purpose of job We are seeking a passionate Security Specialist with hands-on experience in working with all aspects of Azure, M365, and preferably Google Cloud Platforms (GCP).

    Posted 4 days ago

  • Cybersecurity Analyst

    Visa · London

    Full-time

    About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid.

    Posted 4 days ago

  • Data Privacy Officer

    Pipedrive · London

    Full-time

    We believe it takes great people to create a great product. That’s why our team lives our company values, and we hire based on them, too. Since 2010, Pipedrive has been on a mission to support sales and marketing teams with easy-to-use, powerful tools that make everyday work faster and…

    Posted 4 days ago