[Remote] Principal DFIR Consultant- Remote (Anywhere in the U.S.)

Remote Full-time
Note: The job is a remote job and is open to candidates in USA. GuidePoint Security is a rapidly growing cybersecurity firm that provides trusted expertise and solutions to help organizations minimize risk. They are seeking a Principal DFIR Consultant who will serve as the foremost technical authority within the DFIR Practice, leading complex investigations and mentoring junior staff while contributing to business development and practice improvement.ResponsibilitiesServe in the Oversight role on complex or high-severity engagements, reviewing findings before client calls, providing technical depth, anticipating client questions, and ensuring quality of analysis and deliverablesStep in as engagement Lead on the most complex or sensitive investigations (ransomware, APT, nation-state, insider threat), setting the standard for client communication and investigative rigorConduct advanced host forensics, network analysis, malware reverse engineering/triage, cloud forensics, threat actor attribution, and intelligence-driven investigationServe as a trusted surge resource for the team during high-volume periods, providing senior-level coverage across concurrent engagementsDesign, document, and maintain DFIR investigation methodologies, playbooks, and SOPs that raise the quality floor for the entire practiceActively mentor Senior Consultants and Analysts; provide guidance on technical challenges, client management, and professional development. Help develop the next generation of DFIR leadsLead internal training sessions, write technical blog posts and research, document lessons learned, and contribute to the team's collective knowledge baseIdentify gaps in current tooling and processes; design and build automation, scripts, or integrations that improve investigative efficiency across the teamParticipate in candidate screening, technical interviews, and skills assessment to help build a high-quality team pipelineBuild deep, trusted relationships with key clients and stakeholders; serve as a credible senior voice during high-stakes incidentsSupport pre-sales activities including technical scoping, proposal development, SOW review, and client presentations for DFIR, Compromise Assessment, and IR Advisory engagementsRepresent GuidePoint Security externally through conference presentations, webinars, publications, and engagement with the broader DFIR communityMaintaining consistent availability outside standard business hours for high-severity incident surges and team escalationsParticipating in on-call rotation as appropriate for seniorityProactively identifying and addressing gaps in team performance, processes, or client deliverySetting an example of professionalism, urgency, and ownership that the broader team can followSkills8+ years of hands-on DFIR experience, including complex incident response and forensic investigations10+ combined years of IT and information security experienceDemonstrated experience in a Lead or senior technical role on high-severity engagements (ransomware, APT, nation-state, or insider threat)Expert-level proficiency across multiple DFIR disciplines: host forensics, network forensics, log analysis, malware triage, cloud IR, and BEC investigationExceptional written and verbal communication skills; ability to present complex technical findings to executive and legal audiencesProven track record of mentoring and developing junior and mid-level technical staffExperience developing or contributing to DFIR methodologies, playbooks, or toolingPrior consulting or professional services experience at a leading DFIR or cybersecurity firmAdvanced proficiency with scripting and tooling: PowerShell, Python, Bash, Go, or similar; experience building custom investigative toolsDeep experience with EDR, NDR, XDR, SIEM, Velociraptor, and commercial/open-source forensic platformsCloud incident response expertise: AWS, Microsoft 365, Azure, Google Workspace; familiarity with cloud-native forensic techniquesExperience with threat actor attribution, CTI integration, and intelligence-driven investigationFamiliarity with ransomware negotiation considerations, threat actor communications, and recovery workflowsExternal thought leadership: conference talks, published research, blog posts, or community contributionsRelevant certifications: GREM, GCFA, GCFE, GDAT, GCIH, GCIA, CISSP, or equivalent; advanced or multiple certifications are a strong plusBenefitsRemote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans12 corporate holidays and a Flexible Time Off (FTO) programHealthy mobile phone and home internet allowanceEligibility for retirement plan after 2 months at open enrollmentPet Benefit OptionCompany OverviewGuidePoint Security provides trusted cybersecurity expertise, solutions, and services that help organizations minimize risk. It was founded in 2011, and is headquartered in Reston, Virginia, USA, with a workforce of 1001-5000 employees. Its website is https://www.guidepointsecurity.com/.

Apply Now →

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Business Development Representative, Informatics - Minnesota/Wisconsin/Michigan

Remote

Experienced IT Operations Manager – Remote Work Opportunity at careerzynith

Remote

Account Manager – US and Allied Defense and Intelligence

Remote

Gardening Social Media Manager and Content Creator

Remote

Need Substitute Teacher in Florham Park, NJ

Remote

Virtual Sitter/Patient Observer - Float Pool

Remote

Experienced Data Entry Specialist – Remote Opportunity with careerzynith

Remote

Marketing Insights Program Manager (Remote)

Remote

Manager, Global Accounts Receivable

Remote

Vice President, Business Analysis I

Remote
← Back