Senior/Principal DFIR Consultant-Remote
Anywhere in the U.S
Updated on 10/2/2023
GuidePoint Security

501-1,000 employees

Information security solutions
Locations
Remote
Experience Level
Entry
Junior
Mid
Senior
Expert
Desired Skills
AWS
Bash
PowerShell
Linux/Unix
Microsoft Azure
Python
Communications
CategoriesNew
Consulting
IT & Security
Software Engineering
Requirements
  • Four (4+) years of experience performing incident response investigations
  • Six (6+) combined years of IT and information security experience
Responsibilities
  • Operate as a technical resource within the Practice and actively participate in DFIR investigations
  • Core understanding of Windows, Linux, and/or MacOS forensics
  • Effective engagement communication, time management, and collaboration with peers
  • Author comprehensive engagement deliverables that are tailored to both technical and managerial audiences as well as fully detail the technical findings, recommendations, business impact, and realistic remediation strategies
  • Foster client relationships by providing support, information, and guidance
  • Utilize automation, orchestration, and scripting to reduce manual processes, improving overall efficiency while also enabling new capabilities to meet the rapidly changing needs of our clients
  • Contribute to integration of existing and future open-source and commercial tools to help improve DFIR processes and procedures
  • Perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry
  • Maintain a strong desire to learn, adapt, and improve along with a rapidly-growing company
  • Perform other duties as assigned
Desired Qualifications
  • Prior experience in a Consulting Services role
  • Experience with Digital Forensics & Incident Response (DFIR) methodology and process
  • Core capabilities include:
  • Network traffic analysis
  • Host forensics
  • Malware handling / triage
  • Log review
  • Experience with a variety of industry-related solutions including EDR, NDR, XDR, SIEM, FW, NGAV, Velociraptor, OSQuery, and others
  • Experience with common programming languages including PowerShell, Python, BASH, Go, C, C++, C#, or others
  • Experience with cloud technologies for the enterprise, such as Amazon Web Services, G Suite, Office 365, and Azure.
  • Awareness of attacker techniques, advanced threat groups, and integration of intelligence into an investigation
  • Other relevant industry certifications, such as but not limited to CISSP, GCIA, GCIH, GDAT, GCFE, and GFCA