Principal DFIR Consultant

Posted 21 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Act as the leading individual contributor and primary technical expert within the DFIR Practice.

• Ensure oversight and quality assurance on intricate or high-severity projects.

• Direct critical investigations related to ransomware, APT, nation-state, and insider threats.

• Execute advanced host forensics, network analysis, malware reverse engineering and triage, cloud forensics, threat actor attribution, and intelligence-driven investigations.

• Offer senior-level surge capacity during peak engagement periods across multiple concurrent projects.

• Design, document, and uphold DFIR investigation methodologies, playbooks, and SOPs.

• Guide Senior Consultants and Analysts through technical challenges, client relations, and career development.

• Conduct internal training sessions, author technical blog posts and research, document lessons learned, and enrich the knowledge base.

• Develop and implement automation, scripts, or integrations to enhance investigative efficiency.

• Engage in candidate evaluations, technical interviews, and skills assessments.

• Foster trusted relationships with key clients and stakeholders.

• Assist in pre-sales activities including technical scoping, proposal creation, SOW review, and client presentations.

• Represent GuidePoint Security through conference presentations, webinars, publications, and active participation in the DFIR community.

• Remain available outside of standard business hours for high-severity incident responses and team escalations.

• Join the on-call rotation as appropriate based on seniority.

• Identify and rectify gaps in team performance, processes, or client service delivery.

• Exemplify professionalism, urgency, and accountability.

• Aid organizations in preparing for, responding to, and recovering from cyber incidents through GuidePoint Security’s integrated DFIR and Threat Intelligence practice.


⛳️ Requirements

• Over 8 years of practical DFIR experience, including complex incident response and forensic investigations.

• More than 10 years of combined experience in IT and information security.

• Proven experience in a Lead or senior technical capacity on high-severity engagements involving ransomware, APT, nation-state, or insider threats.

• Expert-level skills in host forensics, network forensics, log analysis, malware triage, cloud incident response, and BEC investigation.

• Outstanding written and verbal communication abilities, capable of presenting intricate technical findings to executive and legal audiences.

• A verified history of mentoring and developing junior and mid-level technical personnel.

• Experience in developing or contributing to DFIR methodologies, playbooks, or tools.

• An openness to emerging technologies, including AI tools.

• Prior consulting or professional services background at a leading DFIR or cybersecurity firm is preferred.

• Advanced proficiency in scripting and tooling with PowerShell, Python, Bash, Go, or similar languages is preferred.

• Experience in creating custom investigative tools is preferred.

• Extensive experience with EDR, NDR, XDR, SIEM, Velociraptor, and commercial/open-source forensic platforms is preferred.

• Expertise in cloud incident response with AWS, Microsoft 365, Azure, or Google Workspace is preferred.

• Familiarity with cloud-native forensic techniques is preferred.

• Experience with threat actor attribution, CTI integration, and intelligence-driven investigation is preferred.

• Understanding of ransomware negotiation considerations, threat actor communications, and recovery workflows is preferred.

• External thought leadership, such as conference presentations, published research, blog contributions, or community engagement, is preferred.

• Relevant certifications such as GREM, GCFA, GCFE, GDAT, GCIH, GCIA, or CISSP are highly advantageous.

• Up to 10% travel may be required.

• Sedentary work environment.

• Significant movement of the wrists, hands, and/or fingers for at least 8 hours a day.

• Close visual acuity for computer terminal use and/or extensive reading for a minimum of 8 hours a day.

• U.S.-based work authorization/location requirement.


🏝️ Benefits

• Primarily remote workforce (U.S. based only).

• Group Medical Insurance options: Zero Deductible PPO Plan, with GuidePoint covering 90% of the employee premium and 70% of family premiums.

• High Deductible Health Plan with HSA, with GuidePoint paying 100% of the employee premium and 75% of family premiums.

• HSA contributions of $850 annually for employees or $1,750 annually for family plans.

• Group Dental Insurance, with GuidePoint paying 100% of the employee premium and 75% of family premiums.

• 12 corporate holidays.

• Flexible Time Off (FTO) program.

• Healthy mobile phone allowance.

• Home internet allowance.

• Eligibility for a retirement plan after 2 months during open enrollment.

• Pet Benefit Option.

• Some travel may be necessary for certain positions.

People also viewed

Palo Alto Networks20 hours ago

Staff Professional Services Consultant – Machine Identity

ES flagSpain, +3 more countriesFull-timeConsultant
ApplyView job
Devoteam20 hours ago

Atlassian Consultant

TN flagTunisia, +1 more countryFull-timeConsultant
ApplyView job
TecnoSpeed TI21 hours ago

Trainee Technical Consultant

BR flagBrazil OnlyFull-timeConsultant
ApplyView job
onefinestay23 hours ago

Property Acquisition Consultant

US flagColorado OnlyFreelanceConsultant
ApplyView job
Workiva1 day ago

SEC Reporting Consultant

US flagUnited States OnlyFull-timeConsultant$68k – $110k/year
ApplyView job
Vista Equity Partners1 day ago

Senior Consultant, Executive Talent

US flagIllinois, +1 more stateFull-timeConsultant$125k – $135k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers