Principal DFIR Consultant

🔥 17 hours ago

🇺🇸 United States – Remote

⏰ Full Time

🔴 Lead

💼 Consultant

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 10%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GuidePoint Security

GuidePoint Security

201 - 500 employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

GuidePoint Security is a cybersecurity firm offering consulting, engineering, and managed services to help organizations secure their digital assets. The company specializes in application security, cloud security, data protection, email security, threat intelligence, and identity and access management. With solutions tailored to various platforms including AWS, Microsoft, Google Cloud, and OT environments, GuidePoint Security aims to enhance cybersecurity resilience for both enterprise and government clients. They focus on integrating advanced security technologies and providing expertise in risk assessment, compliance, and security awareness education, helping clients navigate complex cybersecurity challenges and improve their security posture.

📋 Description

• Serve as the highest individual contributor and foremost technical authority within the DFIR Practice • Provide oversight and quality assurance on complex or high-severity engagements • Lead critical investigations involving ransomware, APT, nation-state, and insider threats • Conduct advanced host forensics, network analysis, malware reverse engineering and triage, cloud forensics, threat actor attribution, and intelligence-driven investigations • Provide senior-level surge capacity across concurrent engagements during high-volume periods • Design, document, and maintain DFIR investigation methodologies, playbooks, and SOPs • Mentor Senior Consultants and Analysts on technical challenges, client management, and professional development • Lead internal training, write technical blog posts and research, document lessons learned, and contribute to the knowledge base • Design and build automation, scripts, or integrations to improve investigative efficiency • Participate in candidate screening, technical interviews, and skills assessments • Build trusted relationships with key clients and stakeholders • Support pre-sales activities including technical scoping, proposal development, SOW review, and client presentations • Represent GuidePoint Security through conference presentations, webinars, publications, and DFIR community engagement • Maintain availability outside standard business hours for high-severity incident surges and team escalations • Participate in on-call rotation as appropriate for seniority • Identify and address gaps in team performance, processes, or client delivery • Set an example of professionalism, urgency, and ownership • Help organizations prepare for, respond to, and recover from cyber incidents through GuidePoint Security’s integrated DFIR and Threat Intelligence practice

🎯 Requirements

• 8+ years of hands-on DFIR experience, including complex incident response and forensic investigations • 10+ combined years of IT and information security experience • Demonstrated experience in a Lead or senior technical role on high-severity engagements involving ransomware, APT, nation-state, or insider threat • Expert-level proficiency across host forensics, network forensics, log analysis, malware triage, cloud incident response, and BEC investigation • Exceptional written and verbal communication skills, with ability to present complex technical findings to executive and legal audiences • Proven track record of mentoring and developing junior and mid-level technical staff • Experience developing or contributing to DFIR methodologies, playbooks, or tooling • Embraces emerging technologies, including AI tools • Prior consulting or professional services experience at a leading DFIR or cybersecurity firm preferred • Advanced scripting and tooling proficiency with PowerShell, Python, Bash, Go, or similar preferred • Experience building custom investigative tools preferred • Deep experience with EDR, NDR, XDR, SIEM, Velociraptor, and commercial/open-source forensic platforms preferred • Cloud incident response expertise with AWS, Microsoft 365, Azure, or Google Workspace preferred • Familiarity with cloud-native forensic techniques preferred • Experience with threat actor attribution, CTI integration, and intelligence-driven investigation preferred • Familiarity with ransomware negotiation considerations, threat actor communications, and recovery workflows preferred • External thought leadership, such as conference talks, published research, blog posts, or community contributions, preferred • Relevant certifications such as GREM, GCFA, GCFE, GDAT, GCIH, GCIA, or CISSP are a strong plus • Up to 10% travel • Sedentary work • Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day • Close visual acuity for computer terminal viewing and/or extensive reading for a minimum of 8 hours a day • U.S.-based work authorization/location requirement

🏖️ Benefits

• Remote workforce primarily (U.S. based only) • Group Medical Insurance options: Zero Deductible PPO Plan, with GuidePoint paying 90% of the employee premium and 70% of family premiums • High Deductible Health Plan with HSA, with GuidePoint paying 100% of the employee premium and 75% of family premiums • HSA contributions of $850 annually for employees or $1,750 annually for family plans • Group Dental Insurance, with GuidePoint paying 100% of the employee premium and 75% of family premiums • 12 corporate holidays • Flexible Time Off (FTO) program • Healthy mobile phone allowance • Home internet allowance • Eligibility for retirement plan after 2 months at open enrollment • Pet Benefit Option • Some travel may be required for certain positions

Apply Now

Similar Jobs

🕒 3 days ago

Summit

51 - 200

☁️ SaaS

📣 Marketing

🤝 B2B

Remote safety consultant assessing insured-property risks for Summit, a workers’ compensation insurer. Developing loss-prevention programs and advising clients on safety and compliance.

🕒 3 days ago

Great American Insurance Group

5001 - 10000

🛡️ Insurance

🤝 B2B

Safety and Loss Prevention Consultant assessing insured-property risks for Summit, a workers’ compensation insurer. Designing loss prevention programs and advising clients on safety and regulatory compliance.

🕒 3 days ago

MOXFIVE

11 - 50

💼 Consulting

🏥 Healthcare

🛡️ Insurance

Principal DFIR Consultant investigating enterprise, cloud, and multi-cloud threats for MOXFIVE clients. Shaping AI-assisted forensic tooling and incident response methodology.

🕒 3 days ago

U.S. Bank

10,000+ employees

🏦 Banking

💸 Finance

🛡️ Insurance

Business Card Consultant developing profitable business account relationships for U.S. Bank. Selling payment solutions, prospecting businesses, and growing existing portfolios.

🇺🇸 United States – Remote

💵 $104k - $127k / year

💰 $55M Post IPO debt on 2023-10

⏰ Full Time

🟠 Senior

🔴 Lead

💼 Consultant

🕒 4 days ago

Argano

1001 - 5000

💼 Consulting

🏢 Enterprise

🤖 Artificial Intelligence

Oracle Cloud HCM Principal Consultant guiding enterprise clients through strategic HR technology transformation at Argano. Managing client relationships, implementations, configurations, and account growth.