Principal DFIR Consultant

🕒 May 19

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GuidePoint Security

GuidePoint Security

201 - 500 employees

🔒 Cybersecurity

Cybersecurity

GuidePoint Security is a cybersecurity firm offering consulting, engineering, and managed services to help organizations secure their digital assets. The company specializes in application security, cloud security, data protection, email security, threat intelligence, and identity and access management. With solutions tailored to various platforms including AWS, Microsoft, Google Cloud, and OT environments, GuidePoint Security aims to enhance cybersecurity resilience for both enterprise and government clients. They focus on integrating advanced security technologies and providing expertise in risk assessment, compliance, and security awareness education, helping clients navigate complex cybersecurity challenges and improve their security posture.

📋 Description

• Serve in the Oversight role on complex or high-severity engagements, reviewing findings before client calls, providing technical depth, anticipating client questions, and ensuring quality of analysis and deliverables. • Step in as engagement Lead on the most complex or sensitive investigations (ransomware, APT, nation-state, insider threat), setting the standard for client communication and investigative rigor. • Conduct advanced host forensics, network analysis, malware reverse engineering/triage, cloud forensics, threat actor attribution, and intelligence-driven investigation. • Serve as a trusted surge resource for the team during high-volume periods, providing senior-level coverage across concurrent engagements. • Design, document, and maintain DFIR investigation methodologies, playbooks, and SOPs that raise the quality floor for the entire practice. • Actively mentor Senior Consultants and Analysts; provide guidance on technical challenges, client management, and professional development. Help develop the next generation of DFIR leads. • Lead internal training sessions, write technical blog posts and research, document lessons learned, and contribute to the team's collective knowledge base. • Identify gaps in current tooling and processes; design and build automation, scripts, or integrations that improve investigative efficiency across the team. • Participate in candidate screening, technical interviews, and skills assessment to help build a high-quality team pipeline. • Build deep, trusted relationships with key clients and stakeholders; serve as a credible senior voice during high-stakes incidents. • Support pre-sales activities including technical scoping, proposal development, SOW review, and client presentations for DFIR, Compromise Assessment, and IR Advisory engagements. • Represent GuidePoint Security externally through conference presentations, webinars, publications, and engagement with the broader DFIR community.

🎯 Requirements

• 8+ years of hands-on DFIR experience, including complex incident response and forensic investigations. • 10+ combined years of IT and information security experience. • Demonstrated experience in a Lead or senior technical role on high-severity engagements (ransomware, APT, nation-state, or insider threat). • Expert-level proficiency across multiple DFIR disciplines: host forensics, network forensics, log analysis, malware triage, cloud IR, and BEC investigation. • Exceptional written and verbal communication skills; ability to present complex technical findings to executive and legal audiences. • Proven track record of mentoring and developing junior and mid-level technical staff. • Experience developing or contributing to DFIR methodologies, playbooks, or tooling.

🏖️ Benefits

• Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions) • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options) • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans • 12 corporate holidays and a Flexible Time Off (FTO) program • Healthy mobile phone and home internet allowance • Eligibility for retirement plan after 2 months at open enrollment • Pet Benefit Option

Apply Now

Similar Jobs

🕒 May 19

Adobe

10,000+ employees

Senior consultative role at Adobe focusing on high-risk, high-value renewals for enterprise customers. Collaborate closely with account teams on renewal strategies and negotiations.

🕒 May 19

Tokio Marine HCC

1001 - 5000

🤝 B2B

💸 Finance

Principal DFIR Consultant at Vector3 providing technical expertise in incident response and cyber forensics. Leading investigations and managing a high-performing DFIR team for TMHCC insureds.

🕒 May 19

AbbVie

10,000+ employees

💊 Pharmaceuticals

🧬 Biotechnology

⚕️ Healthcare Insurance

Allergan Aesthetic Consultant supporting sales initiatives and consulting on aesthetic healthcare. Managing key account strategies and partnerships in the aesthetic health care sector.

🕒 May 19

AbbVie

10,000+ employees

💊 Pharmaceuticals

🧬 Biotechnology

⚕️ Healthcare Insurance

Allergan Practice Consultant providing consultative services for sales and marketing in the aesthetics healthcare space. Traveling 50% of the time while managing key accounts and leading initiatives.

🕒 May 19

AbbVie

10,000+ employees

💊 Pharmaceuticals

🧬 Biotechnology

⚕️ Healthcare Insurance

Allergan Practice Consultant in the Aesthetics division at AbbVie. Focused on sales support and practice management in a field-based role with travel requirements.