
Principal DFIR Consultant
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in United States.
• Act as the leading individual contributor and primary technical expert within the DFIR Practice.
• Ensure oversight and quality assurance on intricate or high-severity projects.
• Direct critical investigations related to ransomware, APT, nation-state, and insider threats.
• Execute advanced host forensics, network analysis, malware reverse engineering and triage, cloud forensics, threat actor attribution, and intelligence-driven investigations.
• Offer senior-level surge capacity during peak engagement periods across multiple concurrent projects.
• Design, document, and uphold DFIR investigation methodologies, playbooks, and SOPs.
• Guide Senior Consultants and Analysts through technical challenges, client relations, and career development.
• Conduct internal training sessions, author technical blog posts and research, document lessons learned, and enrich the knowledge base.
• Develop and implement automation, scripts, or integrations to enhance investigative efficiency.
• Engage in candidate evaluations, technical interviews, and skills assessments.
• Foster trusted relationships with key clients and stakeholders.
• Assist in pre-sales activities including technical scoping, proposal creation, SOW review, and client presentations.
• Represent GuidePoint Security through conference presentations, webinars, publications, and active participation in the DFIR community.
• Remain available outside of standard business hours for high-severity incident responses and team escalations.
• Join the on-call rotation as appropriate based on seniority.
• Identify and rectify gaps in team performance, processes, or client service delivery.
• Exemplify professionalism, urgency, and accountability.
• Aid organizations in preparing for, responding to, and recovering from cyber incidents through GuidePoint Security’s integrated DFIR and Threat Intelligence practice.
• Over 8 years of practical DFIR experience, including complex incident response and forensic investigations.
• More than 10 years of combined experience in IT and information security.
• Proven experience in a Lead or senior technical capacity on high-severity engagements involving ransomware, APT, nation-state, or insider threats.
• Expert-level skills in host forensics, network forensics, log analysis, malware triage, cloud incident response, and BEC investigation.
• Outstanding written and verbal communication abilities, capable of presenting intricate technical findings to executive and legal audiences.
• A verified history of mentoring and developing junior and mid-level technical personnel.
• Experience in developing or contributing to DFIR methodologies, playbooks, or tools.
• An openness to emerging technologies, including AI tools.
• Prior consulting or professional services background at a leading DFIR or cybersecurity firm is preferred.
• Advanced proficiency in scripting and tooling with PowerShell, Python, Bash, Go, or similar languages is preferred.
• Experience in creating custom investigative tools is preferred.
• Extensive experience with EDR, NDR, XDR, SIEM, Velociraptor, and commercial/open-source forensic platforms is preferred.
• Expertise in cloud incident response with AWS, Microsoft 365, Azure, or Google Workspace is preferred.
• Familiarity with cloud-native forensic techniques is preferred.
• Experience with threat actor attribution, CTI integration, and intelligence-driven investigation is preferred.
• Understanding of ransomware negotiation considerations, threat actor communications, and recovery workflows is preferred.
• External thought leadership, such as conference presentations, published research, blog contributions, or community engagement, is preferred.
• Relevant certifications such as GREM, GCFA, GCFE, GDAT, GCIH, GCIA, or CISSP are highly advantageous.
• Up to 10% travel may be required.
• Sedentary work environment.
• Significant movement of the wrists, hands, and/or fingers for at least 8 hours a day.
• Close visual acuity for computer terminal use and/or extensive reading for a minimum of 8 hours a day.
• U.S.-based work authorization/location requirement.
• Primarily remote workforce (U.S. based only).
• Group Medical Insurance options: Zero Deductible PPO Plan, with GuidePoint covering 90% of the employee premium and 70% of family premiums.
• High Deductible Health Plan with HSA, with GuidePoint paying 100% of the employee premium and 75% of family premiums.
• HSA contributions of $850 annually for employees or $1,750 annually for family plans.
• Group Dental Insurance, with GuidePoint paying 100% of the employee premium and 75% of family premiums.
• 12 corporate holidays.
• Flexible Time Off (FTO) program.
• Healthy mobile phone allowance.
• Home internet allowance.
• Eligibility for a retirement plan after 2 months during open enrollment.
• Pet Benefit Option.
• Some travel may be necessary for certain positions.
Palo Alto Networks
Devoteam
TecnoSpeed TI
onefinestay
Get handpicked remote jobs straight to your inbox weekly.