Cyber Response & Recovery Manager

Cyber Response & Recovery Manager (Remediation focus)

Base Location: London/Manchester plus network of 20 offices nationally: www.kpmg88careers.co.uk/experienced-professional/#LeBlender.OfficeLocations

Why Join KPMG as a Cyber Response & Recovery Manager?

The Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG’s Cyber Advisory practice, reporting into the cyber response leadership team. Cyber security is one of the areas KPMG has identified for significant investment and growth. Our clients continue to face increasingly destructive cyber threats, particularly ransomware, destructive malware, business email compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience.

This is a hands-on cyber response and recovery manager role, focused on supporting clients through the most operationally critical phase of a cyber incident: restoring business services safely and securely. The role will work closely with incident response leads, forensic teams, legal advisers, crisis management teams, technology teams and client executives to convert incident findings into practical remediation, rebuild and recovery actions.

As a cyber response recovery manager, you will help clients stabilise their environment, remove attacker persistence, restore identity and infrastructure services, support patching and vulnerability remediation, advise on secure rebuild patterns, review and redesign network architecture, establish isolated recovery environments, and define phased recovery and security improvement roadmaps.

This role is particularly suited to someone with strong hands-on infrastructure, systems administration and cyber security experience, who can operate effectively during high-pressure incidents and provide pragmatic, technically credible advice to clients. The successful candidate should be comfortable working across Windows, Linux, Active Directory, virtualisation, networking, cloud and enterprise infrastructure technologies, and should be able to translate technical remediation requirements into clear recovery plans for both technical and senior stakeholder audiences.

KPMG is one of a small number of Tier 1 incident response providers in the UK. As such, this role provides the opportunity to work on complex, high-profile cyber incidents across a wide range of sectors. You will gain significant experience supporting clients during moments of critical need and will have the opportunity to develop both your technical recovery expertise and incident leadership capability.

When not responding to live incidents, you may support clients with cyber resilience, recovery readiness and post-incident transformation engagements. This may include developing recovery playbooks, designing isolated recovery environments, assessing Active Directory and infrastructure resilience, supporting ransomware recovery planning, reviewing network segmentation, improving backup and restore strategies, and helping clients define cyber security improvement roadmaps.

You will also contribute to the development of KPMG’s own cyber recovery capability, including standard operating procedures, technical recovery playbooks, tooling, automation, lab environments, recovery architecture patterns and team training.

Clients expect cyber incidents to be tackled with urgency. Therefore, there is an expectation that you will be flexible in terms of working hours and prepared to travel at short notice, potentially for periods of up to two or three weeks at a time.

Role Summary

This role is not purely an incident response role. It is a hands-on cyber recovery leadership role focused on helping clients restore services, remediate compromised infrastructure and build stronger security foundations after a cyber incident.

The ideal candidate will combine:

  • Deep infrastructure and systems administration experience.
  • Strong cyber security and incident response understanding.
  • Hands-on remediation and recovery capability.
  • Active Directory, Windows, Linux and network architecture expertise.
  • The ability to lead technical workstreams during high-pressure incidents.
  • The ability to define and execute short, medium and long-term security roadmaps.

Responsibilities

  • The Cyber Response Recovery Manager will be responsible for leading and supporting cyber recovery workstreams during active cyber incidents and post-incident remediation programmes. Responsibilities will include:
  • Lead cyber recovery workstreams during major incidents, working closely with incident response, forensic, client IT, legal, insurer and senior stakeholder teams, translating incident findings into clear remediation and recovery actions.
  • Deliver hands-on remediation across enterprise environments, including Active Directory recovery and hardening, Windows/Linux systems, network, cloud, endpoint and security tooling, with a focus on removing attacker persistence and restoring trust.
  • Drive patching and vulnerability remediation activities, prioritising actions based on business risk, threat actor behaviour and incident context.
  • Review and redesign network architecture and security controls, including segmentation, firewall rules, and administrative access pathways, to reduce reinfection risk and improve resilience.
  • Establish and support secure recovery environments and rebuild strategies, including isolated environments, backup validation, restore sequencing, and secure restoration of business-critical services.
  • Define and execute phased recovery and transformation plans, including immediate stabilisation, structured remediation, and security improvement roadmaps and rebuild standards.
  • Manage end-to-end delivery of recovery engagements, including stakeholder communication, project management, reporting, proposals, capability development, and mentoring junior team members.

The Person

You should have a strong background in cyber-security and incident response. For example: You should be able to guide a client through an unstructured incident response process (such as an advanced network intrusion) – managing resources and defining objectives at each stage of the incident response process; scoping and triage, containment, evidence preservation and extraction, eradication, recovery, forensic analysis and investigation.

  • A broad understanding of the cyber security threat landscape.
  • Strong technical background in computers and networks, and programming skills.
  • Significant and proven experience of dealing with cyber security incidents and associated response measures.
  • Experience of managing a rapid deployment incident response team.
  • Excellent interpersonal, written and communication skills.
  • Understanding of a wide range of information security and IT methodologies, principles, technologies and techniques.
  • A genuine interest and desire to develop and mention junior team members.
  • Strong attention for detail and the ability to manage multiple simultaneous cases.

Qualifications and Skills

  • Excellent communication skills (both written and oral) and project management skills.
  • Strong hands-on experience across enterprise infrastructure, including Windows Server, Active Directory, Linux, networking, and cloud environments (e.g. Azure, AWS, Microsoft 365), with the ability to operate at a systems administrator level during recovery scenarios.
  • Proven experience supporting cyber incident recovery, including ransomware, Active Directory compromise, network intrusion, or large-scale infrastructure incidents, with the ability to translate incident findings into practical remediation and recovery actions.
  • Demonstrated capability in leading and executing remediation activities, including identity and Active Directory hardening, patching and vulnerability remediation, secure system rebuild, backup validation, and restoration of business-critical services.
  • Solid understanding of network architecture and security, including segmentation, firewall design, administrative access paths, and the ability to review and redesign environments to reduce reinfection risk and improve resilience.
  • Experience developing and delivering structured recovery plans, remediation trackers, and security roadmaps aligned to immediate recovery, medium-term stabilisation, and long-term transformation.
  • Strong stakeholder management and communication skills, with the ability to engage both technical and executive audiences, manage high-pressure situations, and produce clear, high-quality deliverables and reporting.
  • Effective project and delivery management capability, including scoping, prioritisation, financial oversight, and managing multiple workstreams during complex, time-sensitive cyber recovery engagements

Current National Security Vetting (SC/DV) or a willingness to acquire such a clearance is essential.

Find out more:

Within Consulting we have a range of divisions and specialisms. Click the links to find out more below:

  • Consulting at KPMG: www.kpmgcareers.co.uk/experienced-professional/consulting/
  • ITs Her Future Women in Tech programme: www.kpmgcareers.co.uk/people-culture/it-s-her-future/
  • KPMG Workability and Disability confidence: www.kpmgcareers.co.uk/experienced-professional/applying-to-kpmg/need-support-let-us-know/

For any additional support in applying, please click the links to find out more:

  • Applying to KPMG: www.kpmgcareers.co.uk/experienced-professional/applying-to-kpmg/
  • Tips for interview: www.kpmgcareers.co.uk/experienced-professional/applying-to-kpmg/application-advice/
  • KPMG values: www.kpmgcareers.co.uk/experienced-professional/applying-to-kpmg/our-values/
  • KPMG Competencies: www.kpmgcareers.co.uk/experienced-professional/applying-to-kpmg/kpmg-competencies/
  • KPMG Locations and FAQ: www.kpmgcareers.co.uk/faq/?category=Experienced+professionals

Job Details

Company
KPMG UK
Location
City of London, London, United Kingdom
Posted