The Role
Lead technical recovery during cyber incidents: restore servers and VMs, remediate malware, deploy security tooling, collect forensic artifacts, troubleshoot Active Directory, monitor alerts, document progress, and improve recovery procedures.
Summary Generated by Built In
As a Business Resumption Engineer, you’ll be the technical backbone of high‑pressure cyber incident recoveries - stepping in when organisations are at their most vulnerable and guiding them back to stable, secure operations. You’ll work at the intersection of urgency and precision, restoring critical systems while containing active threats and helping clients regain control of their environments.
At Solis, you’ll do this as part of a global cybersecurity team trusted by thousands of organisations worldwide. Backed by deep incident response expertise, cutting‑edge tooling, and intelligence drawn from real‑world attacks, you’ll help deliver fast, resilient recoveries that minimise downtime and strengthen long‑term security.
At Solis, you’ll do this as part of a global cybersecurity team trusted by thousands of organisations worldwide. Backed by deep incident response expertise, cutting‑edge tooling, and intelligence drawn from real‑world attacks, you’ll help deliver fast, resilient recoveries that minimise downtime and strengthen long‑term security.
Key Responsibilities
- Lead server restoration efforts, including VM deployment, system rebuilds, and troubleshooting Active Directory issues to bring core business services back online
- Contain and remediate malware across diverse environments, ensuring threats are neutralised without disrupting recovery progress
- Deploy security applications across enterprise infrastructures to harden systems during and after incident response
- Monitor and remediate security alerts to maintain stability throughout the recovery process
- Collect forensic artifacts from multiple operating systems using approved DFIR tools
- Act as technical lead during incident response and restoration, providing clear documentation and structured progress updates
- Create and update procedures to support continuous improvement of response and recovery workflows
Skills, Knowledge & Expertise
- Fundamental understanding of enterprise security principles and best practices
- Knowledge of enterprise network architecture and how systems interconnect in real‑world environments
- Strong verbal and written communication skills, with the ability to collaborate effectively across all levels of an organisation
- Excellent time‑management and prioritisation abilities, especially in fast‑moving or ambiguous situations
- A resourceful, self‑directed learner able to research and apply new information quickly
- A collaborative team player who can also operate independently when required
- Degree qualified and 3+ years of experience are beneficial but not required
- SentinelOne Siren certification required within 6 months of employment
About
CFC is a specialist insurance provider, pioneering emerging risk and market leader in cyber. Our global insurance platform uses cutting-edge technology and data science to deliver smarter, faster underwriting and protect customers from today's most critical business risk.Headquartered in London with offices in New York, Melbourne, Sydney, Austin, Madrid, Brussels and Brisbane, CFC has over 1100 staff and is trusted by more than 100,000 businesses across 90 countries.At CFC, insurance isn't just about underwriting. From data science to software development, and digital marketing design, we've got something for everyone. We're passionate about pushing boundaries, thinking differently and building the insurance company of the future.CFC is committed to the principles of equal opportunities and creating an environment in which all individuals are always treated with dignity and respect. We encourage a diverse corporate culture of openness and appreciation to create an environment in which your talent can be developed in the best possible way. Should you require any reasonable adjustments at any stage of the recruitment process please let us know.
Skills Required
- Lead server restoration including VM deployment, system rebuilds, and Active Directory troubleshooting
- Contain and remediate malware across diverse enterprise environments
- Collect forensic artifacts from multiple operating systems using DFIR tools
- Deploy security applications and monitor/remediate security alerts during recovery
- Act as technical lead during incident response with clear documentation and progress updates
- Create and update procedures to improve response and recovery workflows
- Strong verbal and written communication and effective cross-level collaboration
- Knowledge of enterprise network architecture and security principles
- SentinelOne Siren certification (must obtain within 6 months of employment)
- Degree and 3+ years' experience (beneficial but not required)
CFC Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CFC and has not been reviewed or approved by CFC.
-
Strong & Reliable Incentives — Variable pay is positioned as a core part of total compensation, with a group‑wide annual bonus highlighted as a consistent feature. Expanding employee share ownership is described as enhancing overall rewards alongside bonuses.
-
Healthcare Strength — Private medical insurance is provided, complemented by dental and optical cashback and a 24/7 employee assistance programme. These elements indicate comprehensive health coverage beyond standard medical plans.
-
Leave & Time Off Breadth — Time away provisions include 25 days of holiday and paid volunteer time, signaling a broad approach to time off. Additional practices such as company social events support overall work–life rhythm, though they are not leave per se.
CFC Insights
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
CFC is a specialist insurance provider, pioneer in emerging risk and market leader in cyber. Their global insurance platform uses cutting-edge technology and data science to deliver smarter, faster underwriting and protect customers from today’s most critical business risks.









