Skip to main content
GuidePoint Security

Senior DFIR Consultant

RemoteUnited States only
Published
Role
Fullstack
Experience
Senior
Employment
Full-time
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

The Senior DFIR Consultant is a seasoned technical contributor within GuidePoint Security’s Digital Forensics & Incident Response (DFIR) Practice, leading and executing complex investigations across a range of engagement types, delivering high-quality analysis and client communication, and helping the practice continuously evolve its methodologies and tooling in response to emerging threats.

Core skills

EDRNDRXDR

Required skills

host forensicsnetwork traffic analysismalware handling/triagelog reviewBEC analysis

Optional skills

SIEMFWNGAVVelociraptorPowerShellPythonBashGo

Required languages

English professional

What you'll do

  • Operate as a core technical resource within the Practice and actively lead and perform DFIR investigations, including host forensics, network traffic analysis, malware handling/triage, log review, and BEC analysis.
  • Drive effective engagement communication, time management, and coordination throughout the investigative lifecycle.
  • Author comprehensive engagement deliverables tailored to both technical and managerial audiences that fully detail technical findings, recommendations, business impact, and realistic remediation strategies.
  • Apply creativity and adaptability to perform advanced, mission-critical assessments across reactive and proactive engagement types.
  • Collaborate effectively with peers across concurrent engagements, sharing findings and coordinating to deliver consistent, high-quality results.
  • Utilize automation, orchestration, and scripting to reduce manual processes, improve overall efficiency, and enable new capabilities that meet the rapidly changing needs of clients.
  • Contribute to the integration of existing and future open-source and commercial tools to improve DFIR processes and procedures.
  • Perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry.
  • Foster client relationships by providing support, information, and guidance during engagements, serving as a credible technical voice.
  • Help the DFIR Practice adapt to a perpetually evolving service portfolio driven by emerging threats and diverse client needs.
  • Maintain a strong desire to learn, adapt, and improve alongside a rapidly growing company; perform other duties as assigned.

What they require

  • 7 years of experience, including four (4+) years of hands-on experience performing incident response investigations and six (6+) combined years of IT and information security experience.
  • Demonstrated proficiency across core DFIR disciplines: host forensics, network traffic analysis, malware handling/triage, log review, and BEC analysis.
  • Strong written and verbal communication skills, with the ability to present technical findings to both technical and managerial audiences.
  • Creativity and adaptability to solve challenging and complex problems in a rapidly changing environment.
  • Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better outcomes.
  • Prior experience in a consulting or professional services role.
  • Experience with established DFIR methodology and process.
  • Experience with the technology stack listed in 'nice_to_have'.
  • Proficiency with common programming and scripting languages including PowerShell, Python, Bash, Go, or other.
  • Experience with enterprise cloud technologies such as Amazon Web Services, Google Workspace, Microsoft 365, and Azure.
  • Awareness of attacker techniques, advanced threat groups, and integration of threat intelligence into an investigation.
  • Relevant industry certifications such as GCFA, GCFE, GCIH, GCIA, GDAT, GREM, or CISSP.

Benefits

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (spouse/children/family)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Perks and cultural benefits, as weekly perks and travel opportunities listed
CybersecurityMid-size
Salary not disclosed