The Role:
Halcyon’s goal is to deliver an anti-ransomware solution that breaks new ground as to what a security product can deliver. Halcyon’s primary focus is ransomware recovery through our key capture technology. Aligned with this focus, Halcyon is adding a Principal Recovery Specialist to lead and deliver consulting services related to our platform.
The Principal Recovery Specialist will personally deliver high touch customer service to victims of ransomware while leveraging advanced technical, forensic and communication skills in fast paced projects and will provide direction and support to other Halcyon Recovery Specialists as required. We’re looking for someone capable of effectively managing the pace and lifestyle of incident response while providing the attention to detail necessary to deliver value in stressful situations.
Responsibilities:
-
Execute the day to day activities of ransomware recovery projects, which requires engaging professionally with a diverse group of insurance, incident response, and client (executive and technical) staff
-
Provide guidance and support to other Halycon Recovery Specialists in the execution of their ransomware recovery projects as reqiured
-
Coordinate with technical employees at victims to configure and orchestrate all necessary steps to executing Halcyon’s project methodology
-
Analyze and assess the status recovery projects (your own and of others as needed) to set goals and initiatives to successfully progress through a recovery project
-
Create and provide reporting and status updates to a diverse set of stakeholders on a timely basis
-
Work closely with Halcyon’s engineering team to provide feedback on Halcyon tools and technologies for product enhancements or troubleshooting
-
Provide recommendations and implement improvements to all components of the Halcyon recovery project methodology to improve client outcomes and value realization
Skills and Qualifications:
-
BA/BS degree or 10+ years of relevant work experience in an IT-related field – specifically in a windows or linux system administration or equivalent role
-
3+ years of customer facing role either in information security consulting, managed services, or technical support role
-
3+ years of experience in a customer-facing role either in information security consulting, managed services or technical support
-
Strong customer service focus, with the ability to communicate with highly technical management teams
-
Ability to properly prioritize and execute multiple assignments simultaneously in a fast-paced, high-growth environment
-
A willingness to lead by example and participate actively in the workload
-
Excellent verbal and written communication and presentation skills
-
Maintains a positive attitude and quickly adapts to change
-
Technical Knowledge:
-
Windows software installation, monitoring, remote access configurations and components of Windows based security, including but not limited to: user / group permissions, file / folder permissions, group policies, local security policies, etc.
-
Similar topics as above related to linux administration
-
Implementation and management of virtualization solutions including but not limited to: ESXi, HyperV, VirtualBox, etc.
-
Installing, configuring, and administering network technologies or protocols including RDP, SSH, DCHP, DNS, proxies, etc.
-
Advanced file and system forensics capabilities demonstrating knowledge in NTFS, FAT, VMFS, etc.
-
Experience with GitLab CI, GitHub Actions, or other repository management systems
-
Familiarity with code build and compilation practices
-
Networking, operating systems, and malware analysis techniques
-
Good understanding of OSI Model, TCP/IP protocol suite (IP, ARP, ICMP, TCP, UDP, SMTP, FTP, TFTP)
-
Good understanding of windows operating systems and components such as sysinternals and the file system
-
Comfort in a hex editor and performing file analysis
-
Experience with common software deployment tools such as Microsoft InTune, SCCM, BigFix, etc.
-
Bonus Skills and Qualifications:
-
Experience as a penetration tester or other offensive security professional
-
Experience as an incident responder with examples of cases handled and their outcomes
-
Coding skills in python with examples of projects and how they contributed to past solutions and success
This role may require traveling on short notice to a client site up to 50% of the Monday-Friday working days within a year. Historic rates have shown travel utilization of less than 25% in the past 12 months but the willingness and ability to travel frequently within 24-48 hours notice is a must.