Cyber Incident Response Consultant (On-Call Advisory – Supplemental Employment)

Cyber Incident Response Consultant (On-Call Advisory – Supplemental Employment)

Cyber Incident Response Consultant (On-Call Advisory – Supplemental Employment)

7806952438

Indeed

Remote

10 hours ago

No application

About

Cyber Incident Response Consultant (Supplemental, On-Call Advisory)

Location: Remote – Anywhere in Canada
Compensation: Up to $70/hour
Type: Supplemental / Secondary Employment – On-Call Advisory (Keep Your Full-Time Job)
Client: A leading Canadian professional services firm

A Flexible, Supplemental Cyber Role You Can Add to Your Current Job

We are partnering with a leading Canadian professional services firm to build an elite on-call Cyber Incident Response advisory roster.

This is supplemental employment — perfect for seasoned incident response professionals who want extra paid work without leaving their current job.

You remain in your full-time or contract role.
You only work when an incident occurs and only if you are available.

What Makes This Role Unique

  • Fully on-call, ad hoc, event-driven
  • Zero conflict with your current full-time role
  • No guaranteed hours — work happens only when major incidents occur
  • Minimum 20 hours/month availability outside business hours
  • 100% remote anywhere in Canada
  • Paid up to $70/hour depending on experience & engagement type

This is advisory-focused crisis work, not operational SOC work.

What You’ll Do (High-Level Overview)

As part of the on-call roster, you may be activated during high-severity cyber events such as:

  • Ransomware attacks
  • Business email compromise
  • Data breaches
  • Network intrusions
  • Cloud security events
  • Fraud or high-impact cyber investigations

Your role will be to advise and support clients during the most critical phases of an incident:

  • Provide Incident Commander–level triage and leadership
  • Guide clients on containment, remediation, and recovery
  • Analyze and interpret findings using CrowdStrike Falcon (mandatory)
  • Collaborate with the firm’s IR & DFIR teams during live events
  • Communicate with senior leadership and help them navigate decisions in real time

This is crisis consulting — short-duration, high-intensity advisory work on an as-needed basis.

What You Must Bring (Non-Negotiable)

We are looking for candidates who have:

  • Recent (within 12 months) hands-on incident response experience
  • Multiple ransomware investigations under their belt
  • Mandatory CrowdStrike Falcon expertise in real-world IR contexts
  • Experience as an Incident Commander / IR Lead
  • Strong communication skills under pressure
  • Experience advising enterprise organizations in Canada
  • Ability to work nights, weekends, and short notice during major incidents
  • Legal right to work in Canada, located anywhere nationally

Not a fit:
General security analysts, SOC-only backgrounds, or offshore-outsourcing profiles.

Nice-to-Have Skills

  • DFIR tools: Magnet, EnCase, FTK, Velociraptor, X-Ways
  • Other EDRs: SentinelOne, Defender for Endpoint, Carbon Black
  • SIEM experience: Sentinel, Splunk, ELK, ArcSight
  • Experience with cloud IR (Azure, AWS, GCP)
  • IR certifications (GCFA, GCIH, GCFE, GREM, EnCE, etc.)
  • Prior consulting experience

Who Thrives in This Role

This supplemental advisory role is ideal for:

  • Senior IR/DFIR professionals wanting additional consulting income
  • Cybersecurity leaders with flexible schedules
  • Incident Commanders who excel during high-severity crisis events
  • Professionals who want exposure to a top-tier Canadian consulting environment

Availability & Engagement Model

  • This is supplemental, on-call, advisory-only work
  • You keep your existing full-time/contract position
  • Minimum 20 hours/month availability outside business hours
  • Activation depends entirely on incident volume
  • Initial contract: 6 months, strong likelihood of extension

How to Apply

Please send:

  • Your resume with clear IR experience
  • A short overview of:
  • Recent ransomware and Falcon experience
  • Your current job & your supplemental availability
  • Your desired hourly rate (up to $70/hr)
  • Confirmation you are open to on-call, supplemental advisory work

Candidates who have held roles in the folllowing areas may be a good fit! Cyber Incident Response Consultant, Incident Commander, Ransomware Response, CrowdStrike Falcon, DFIR Consultant, Cybersecurity Consultant, On-Call Cyber Response, Supplemental Cyber Work, Remote Cyber Jobs Canada, Cybersecurity Advisor, Digital Forensics, Incident Response Canada, After-Hours Cybersecurity, High-Severity Incident Response, Ransomware Recovery Specialist, Canadian Cyber Consulting, IR Lead, Senior Incident Responder, Cyber Crisis Advisor.

Job Types: Casual, Freelance

Pay: $70.00 per hour

Application question(s):

  • Are you willing and able to complete a full background check (criminal, identity, employment verification)?
  • Have you ever failed, been denied, or withdrawn from a background check process?
  • Can you pass a criminal record check with no convictions that would prevent you from working in cyber incident response?
  • Are you willing to complete a credit check if required for client onboarding? AND Do you have no outstanding legal or financial issues that would prevent onboarding with a professional services firm?
  • Are you able to sign strict NDAs and confidentiality agreements required for accessing sensitive client incident data?
  • Are you able to work in an environment requiring secure handling of client data (e.g., encrypted devices, controlled workspace)?
  • Do you have active Incident Response experience within the last 12 months?
  • Have you led or participated in multiple real ransomware investigations (not tabletop exercises)?
  • Do you have experience supporting enterprise-level organizations within Canada?
  • Can you reliably provide at least 20 hours per month of after-hours and weekend availability for on-call work?

Work Location: Remote