Jobs Companies GuidePoint Security Recovery & Restoration Consultant - Remote (Anywhere in the U.S.)

Sobre esta vaga de Recovery & Restoration Consultant - Remote (Anywhere in the U.S.) na GuidePoint Security

GuidePoint Security · Remoto · Remote

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

General Description

The Recovery & Restoration Consultant is a foundational member of the Incident Management & Recovery team, responsible for supporting the rebuild and securing of infrastructure environments following ransomware or other destructive cyber incidents. This role combines developing on-premises infrastructure expertise (Active Directory, VMware/Hyper-V, networking, backups) with growing Microsoft 365 and Azure/Entra ID knowledge.

You will support hands-on rebuild efforts across identity, compute, storage, networking, and cloud layers — working directly with clients, the GuidePoint Security Incident Response team, and senior engineers to restore business operations quickly, securely, and safely. This position reports to senior engineers and the R&R Engineering Manager, with the expectation of rapid growth through mentorship and real-world engagement experience.

Roles and Responsibilities:  

  • Support IT recovery projects involving on-premises endpoint and network infrastructure, Entra ID (Azure AD), and Microsoft 365 under the guidance of senior engineers
  • Assist in developing technical remediation and restoration plans tailored to the impact on a client's environment
  • Implement network containment and isolation measures on common firewall platforms in preparation for recovery efforts
  • Assist in rebuilding Active Directory domains, DNS/DHCP, and Group Policy structures to a clean baseline
  • Support restoration and validation of virtualized workloads (VMware ESXi, Hyper-V) and critical file/application servers
  • Assist in recovering and securing Entra ID identities, Conditional Access policies, and synchronization with on-prem AD via Entra Connect
  • Support rebuilds of Exchange Online, SharePoint, OneDrive, and Teams configurations
  • Validate and restore data from backups (Veeam, Rubrik, Datto, etc.), ensuring integrity and cleanliness — understanding the critical difference between snapshots and proper isolated backups
  • Utilize common remote management tools and VPN connections to assist impacted clients remotely
  • Apply industry-standard Microsoft hardening guidelines throughout recovery processes
  • Assist in implementing compliance controls such as MFA, Defender for Office 365, and Purview
  • Develop and maintain PowerShell scripts for recurring recovery workflows
  • Maintain thorough documentation of rebuilt configurations, recovery timelines, and actions taken — supporting defensible, auditable records for insurance carriers and legal counsel
  • Maintain chain of custody awareness when handling evidence, disk images, or log files

Required Experience: 

Windows & Active Directory Fundamentals

  • Solid understanding of Active Directory as a centralized directory service for authentication and authorization
  • Knowledge of AD objects (users, computers, groups, OUs) and Domain Controller roles (NTDS.dit, replication)
  • Clear understanding of the difference between local administrator accounts (SAM database) and domain administrator accounts (Domain Admins group), including the security implications of each
  • Ability to identify which domain controller a machine is authenticating against (e.g., %LOGONSERVER%, nltest, Get-ADDomainController)
  • Working knowledge of Group Policy — purpose, GPO linking (sites, domains, OUs), and common enforcement use cases (password policies, drive mappings, firewall rules, USB restrictions)
  • Understanding of why network isolation is the first step in a ransomware recovery scenario (containment, forensic preservation, preventing reintroduction of threats)

Cloud & Identity Basics

  • Understanding of the distinction between on-premises Active Directory and Entra ID (Azure AD) — their respective roles and how they coexist in hybrid identity environments
  • Familiarity with Entra Connect and hybrid identity synchronization concepts
  • Solid understanding of MFA — what it is, why it's critical during recovery, and awareness that attackers target MFA (disabling it, registering rogue devices)
  • Basic awareness of Conditional Access policies and their role in identity security

PowerShell Fundamentals

  • Understanding of PowerShell as an object-oriented shell/scripting language and how it differs from cmd.exe (structured objects vs. plain text)
  • Familiarity with cmdlet naming conventions (Verb-Noun) and basic commands (Get-Process, Get-Service, piping, Where-Object, Sort-Object)
  • Understanding of execution policies (Get-ExecutionPolicy, Set-ExecutionPolicy, RemoteSigned, Bypass) and their security purpose
  • Willingness and ability to write and modify scripts for recovery tasks; experience with AzureAD, ExchangeOnline, or Graph API modules is a plus

Virtualization Basics

  • Understanding of hypervisor concepts — what they do and the difference between Type 1 (bare-metal: ESXi, Hyper-V, Proxmox) and Type 2 (hosted: VMware Workstation, VirtualBox)
  • Clear understanding of the difference between VM snapshots and proper backups — snapshots reside on the same storage and are not a substitute for offsite/isolated backups
  • Awareness that threat actors specifically target and delete snapshots and VSS shadow copies to prevent rollback

Troubleshooting & Problem-Solving

  • Demonstrated ability to apply a logical, layered troubleshooting approach (physical → network → service) rather than random guessing
  • Instinct to start simple (power, ping, physical connectivity) and progressively narrow scope
  • Ability to isolate whether an issue is service-specific or host-wide
  • Awareness of when to escalate — knowing the limits of your knowledge is a strength, not a weakness
  • Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.

Preferred Requirements

  • 1–3 years of experience in infrastructure engineering, IT support, or systems administration roles
  • Exposure to consulting, MSP, or IT environments with diverse client infrastructure
  • Microsoft certifications (e.g., AZ-900, AZ-104, MS-900, SC-900) or equivalent hands-on experience
  • Familiarity with at least one EDR or security platform (CrowdStrike, SentinelOne, Microsoft Defender)
  • Any prior exposure to incident response, disaster recovery, or high-pressure IT scenarios
  • Home lab experience or self-driven technical projects demonstrating curiosity and initiative

Networking Fundamentals

  • Understanding of IP addressing and subnet masks (network vs. host portion, common private ranges)
  • Knowledge of the difference between TCP (connection-oriented, reliable) and UDP (connectionless, low overhead) and common use cases for each
  • Understanding of VPN concepts — encrypted tunnels over untrusted networks, their role in secure remote engagement access, and least-privilege/segmented access principles
  • Basic familiarity with firewall platforms and network segmentation concepts

Incident Response & Documentation

  • Understanding of why thorough documentation is critical during IR engagements — creating defensible, auditable records for insurance carriers, legal counsel, and forensic review
  • Awareness that undocumented actions can be indistinguishable from attacker activity during later analysis
  • Basic understanding of chain of custody — maintaining an unbroken, documented record of evidence handling (labeling, hashing, logging)
  • Ability to support clean handoffs between team members or shifts on 24/7 engagements

Disaster Recovery Awareness

  • Understanding of RTO (Recovery Time Objective) and RPO (Recovery Point Objective)
  • Basic awareness of how these objectives shape recovery prioritization during an engagement

Additional Requirements:

  • Travel up to 50% may be required to client sites as required to perform recovery activities and on-site validation.
  • Participate in after-hours response rotations.

Physical Requirements:

  • Sedentary work
  • Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
  • Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.


Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.  

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

 

Pronto para se candidatar à GuidePoint Security?
Candidatar-se à GuidePoint Security

Vagas semelhantes

Perk
Senior Business Travel Consultant - French Speaking - Remote
Perk
⚡ Candidate-se cedo Portugal (Remote) · local restrito
● Nova 👁 Vista ✓ Candidatada há 4h
Teecom
Principal Consultant - Telecom (Healthcare)
Teecom
⚡ Candidate-se cedo Remote - United States · local restrito
● Nova 👁 Vista ✓ Candidatada há 5h
Tenable, Inc.
Senior Security Consultant
Tenable, Inc.
⚡ Candidate-se cedo Netherlands - Remote , Italy -... · local restrito €51,500–€68,833
● Nova 👁 Vista ✓ Candidatada há 5h
Ramp
Solutions Consultant, Mid-Market
Ramp
⚡ Candidate-se cedo New York, NY (HQ) Presencial $151,000–$231,000
● Nova 👁 Vista ✓ Candidatada há 17h
PU
Sales Engineer / Solutions Consultant
PublicInput
⚡ Candidate-se cedo Remote · local restrito
● Nova 👁 Vista ✓ Candidatada há 17h
Honor
Care Solutions Consultant
Honor
⚡ Candidate-se cedo Remote Position · local restrito $20–$22
● Nova 👁 Vista ✓ Candidatada há 17h
Scrunch
Solutions Consultant
Scrunch
⚡ Candidate-se cedo Remote (USA) · local restrito $120,000–$150,000
● Nova 👁 Vista ✓ Candidatada há 18h
Nebius
Management Consultant, Infrastructure Site Selection
Nebius
⚡ Candidate-se cedo United States Presencial $180,000–$225,000
● Nova 👁 Vista ✓ Candidatada há 19h
Esri
Sr. Technical Consultant- Defense
Esri
⚡ Candidate-se cedo Fort Belvoir, Virginia, United... Presencial $107,120–$183,040
● Nova 👁 Vista ✓ Candidatada há 19h

Cadastre-se para receber sugestões sob medida com base nas vagas que você abre e nas buscas que você salva.

Mais vagas na GuidePoint Security

Ver todas as vagas na GuidePoint Security →

Candidatar-se agora
🤖

Opa — calma aí

A JobsRadar foi feita para pessoas de verdade passando por um momento difícil na busca por emprego — não para requisições automatizadas. Você está clicando rápido demais e agora está temporariamente bloqueado.

Volte mais tarde. Se você está mesmo procurando emprego, estamos com você — apenas aja como um ser humano.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Ganhe vantagem na sua busca por emprego.

Entre no nosso canal do Telegram para o que ajuda você a conseguir a vaga — referências salariais, o pulso semanal do mercado e avisos de novos recursos. Sem spam, só sinal.

Entre no canal — é grátis