About CyberClan
Founded in 2006, CyberClan is a global leader in cybersecurity and incident response. We help organisations recover quickly and securely from cyber incidents, ensuring minimal disruption and maximum resilience. With expert teams located across multiple time zones, we provide support and solutions around the clock, ensuring our clients receive continuous care and expertise whenever they need it.
About the Role
We’re seeking a skilled and proactive System Administrator to join our Post-Breach Remediation team. This role offers the opportunity to work within a cybersecurity-focused environment, supporting clients in restoring and strengthening their IT infrastructure following incidents.
You’ll be involved in a wide range of technical activities — from designing and deploying systems to hands-on infrastructure work such as server installation and configuration. The role spans both on-site and remote support and requires frequent travel across the US, occasionally at short notice.
Key Responsibilities
- Rapidly assess and restore client environments impacted by cybersecurity incidents, including ransomware encryption or data exfiltration.
- Build, configure, and maintain physical, virtual, and cloud-based servers, ensuring secure and stable operations.
- Design and implement tailored IT infrastructure recovery plans based on the unique needs and technologies of each client.
- Restore functionality across the full technology stack — from hypervisors and servers to desktops, laptops, and network devices.
- Work at the network, infrastructure, and user level to bring systems back online safely, securely, and efficiently.
- Manage and recover core services including Active Directory, DNS, DHCP, GPO, and remote access tools.
- Collaborate closely with client teams, adapting to their environments and tools while bringing expert-level knowledge and professionalism.
- Maintain and restore backup and disaster recovery solutions, ensuring data integrity and minimal downtime.
- Participate in an on-call rotation to provide critical infrastructure support during high-pressure recovery scenarios.
Essential Experience
- Helpdesk Support – providing frontline assistance and resolving user issues
- 3rd Line Support – handling complex escalations and advanced troubleshooting
- Field Engineer – delivering on-site technical support and installations
- Backup Engineer – managing data protection, recovery, and continuity solutions
- Server Engineer – building, configuring, and maintaining server infrastructure
- Infrastructure Engineer – designing and supporting core IT systems and networks
- Cloud Engineer – deploying and managing services across platforms such as Azure, AWS, and Microsoft 365
- System Administrator – overseeing daily operations, system health, and performance
This role suits someone who has progressed through a variety of technical positions and is confident working across both physical and virtual environments.
Essential Technical Skills
- Windows Server 2008–2025
- Active Directory, DNS, DHCP, GPO
- Remote Desktop Services, RDP and 3rd party Remoting tools.
- Virtualisation platforms (Hyper-V, VMware)
- Microsoft 365, Azure, AWS
- Backup solutions (e.g., Veeam, BackupExec)
- Desktop imaging tools (MDT, SCCM, Intune)
- Networking fundamentals (IP, routing, switching, firewalls)
- PowerShell scripting and automation
- Web and Email filtering
Desirable Skills & Experience
- Familiarity with cybersecurity environments or incident response
- Experience with:
- Security hardening (VPNs, firewalls, group policies)
- Security monitoring tools (e.g., SIEM)
- Linux / MacOS platforms
- SQL DB
Soft Skills
- Excellent communication and interpersonal abilities
- Calm and confident in high-pressure situations
- Strong organisational and time management skills
- Willingness to travel frequently and work on-site
- Self-driven and adaptable to evolving priorities
- Supportive team player with mentoring capabilities
Qualifications
- Degree in Information Technology, Computer Science, or a related field (or equivalent experience)
- Preferred certifications:
- CompTIA Network+, Server+, Security+
- Microsoft MCSA/MCSE
- Microsoft AZ-900/ AZ-104
- Cisco CCNA/CCNP
- ITIL, PRINCE2, or PMI
- CISSP, OSCP, GCIH, GCFA (desirable)
Job Type
Full-time/Exempt
Preferred Location
Illinois, Wisconsin, Indiana, and Michigan
%of Travel Required
Up to 70%
Physical Requirements
Prolonged periods of sitting at a desk and working on a computer.
CyberClan is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status