远程工作雷达

高级DFIR顾问 - 远程(美国任何地方)

Senior DFIR Consultant - Remote (Anywhere in the U.S.)

其他全球可投
公司guidepointsecurity
薪资未公开
工作地点Remote
地域资格全球可投
时区要求无特别要求
用工类型未标注
发布时间2026-08-12
数据来源Greenhouse
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

GuidePoint Security 提供值得信赖的网络安全专业知识、解决方案和服务,帮助组织做出更好的决策并降低风险。通过采用三层、全面的方法来评估安全态势和生态系统,GuidePoint 使一些国内顶尖组织,如财富 500 强公司和美国政府机构,能够识别威胁、优化资源并整合最适合的解决方案以降低风险。

职位概述

高级 DFIR 顾问是 GuidePoint Security 数字取证与事件响应(DFIR)业务中的资深技术贡献者。该职位具有高度自主性,负责领导并执行各种类型的调查,提供高质量的分析和客户沟通,并帮助业务持续改进其方法和工具以应对新兴威胁。

DFIR 业务进行反应式事件响应调查、取证调查、主动威胁发现和威胁狩猎,以及紫队演练(作为蓝队与 GuidePoint 红队合作)。在该职位上,您将作为技术资源,利用深厚的知识、技能和经验为多个行业的客户提供成果,运用创造力和适应性进行关键任务评估。

职责与要求:

技术执行与项目交付

  • 调查执行:作为业务的核心技术资源,积极领导并执行 DFIR 调查,包括主机取证、网络流量分析、恶意软件处理/初步评估、日志审查和 BEC 分析。
  • 项目沟通:在整个调查生命周期中推动有效的项目沟通、时间管理和协调工作。
  • 交付成果:撰写针对技术和管理层的综合性项目交付物,完整详细地说明技术发现、建议、业务影响和实际的修复策略。
  • 关键任务评估:运用创造力和适应性,对反应式和主动型项目类型进行高级的关键任务评估。

协作与持续改进

  • 同事协作:在多个同时进行的项目中与同事有效协作,分享发现并协调以交付一致且高质量的结果。
  • 自动化与效率:利用自动化工具提高工作效率,优化工作流程。
查看英文原文

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

General Description

The Senior DFIR Consultant is a seasoned technical contributor within GuidePoint Security’s Digital Forensics & Incident Response (DFIR) Practice. Operating with a high degree of autonomy, the Senior Consultant leads and executes complex investigations across a range of engagement types, delivers high-quality analysis and client communication, and helps the practice continuously evolve its methodologies and tooling in response to emerging threats.

The DFIR Practice performs reactive incident response investigations, forensic investigations, proactive threat discovery and threat hunting, and Purple Team exercises (as Blue Team in collaboration with the GuidePoint Red Team). In this role you will be a technical resource who leverages deep knowledge, skills, and experience to deliver results to clients across a variety of sectors, applying creativity and adaptability to mission-critical assessments.

Roles and Responsibilities:

Technical Execution & Engagement Delivery

  • Investigation Execution: Operate as a core technical resource within the Practice and actively lead and perform DFIR investigations, including host forensics, network traffic analysis, malware handling/triage, log review, and BEC analysis.
  • Engagement Communication: Drive effective engagement communication, time management, and coordination throughout the investigative lifecycle.
  • Deliverables: Author comprehensive engagement deliverables tailored to both technical and managerial audiences that fully detail technical findings, recommendations, business impact, and realistic remediation strategies.
  • Mission-Critical Assessments: Apply creativity and adaptability to perform advanced, mission-critical assessments across reactive and proactive engagement types.

Collaboration & Continuous Improvement

  • Peer Collaboration: Collaborate effectively with peers across concurrent engagements, sharing findings and coordinating to deliver consistent, high-quality results.
  • Automation & Efficiency: Utilize automation, orchestration, and scripting to reduce manual processes, improve overall efficiency, and enable new capabilities that meet the rapidly changing needs of clients.
  • Tooling Contribution: Contribute to the integration of existing and future open-source and commercial tools to improve DFIR processes and procedures.
  • Skills Development: Perpetually strengthen relevant skills, knowledge, and abilities to stay at the forefront of the information security industry.

Client & Practice Contribution

  • Client Relationships: Foster client relationships by providing support, information, and guidance during engagements, serving as a credible technical voice.
  • Practice Evolution: Help the DFIR Practice adapt to a perpetually evolving service portfolio driven by emerging threats and diverse client needs.
  • Growth Mindset: Maintain a strong desire to learn, adapt, and improve alongside a rapidly growing company; perform other duties as assigned.

Engagement & Availability Expectations

The Senior Consultant is held to a high standard for availability, initiative, and ownership commensurate with a senior technical role. This includes:

  • Maintaining availability outside standard business hours during high-severity incident surges.
  • Participating in on-call rotation as appropriate for the role.
  • Proactively identifying and addressing gaps in engagement delivery, processes, or client communication.
  • Setting an example of professionalism, urgency, and ownership on every engagement.

Required Experience and Education:

  • 7 years of experience, including:
  • Four (4+) years of hands-on experience performing incident response investigations.
  • Six (6+) combined years of IT and information security experience.
  • Demonstrated proficiency across core DFIR disciplines: host forensics, network traffic analysis, malware handling/triage, log review, and BEC analysis.
  • Strong written and verbal communication skills, with the ability to present technical findings to both technical and managerial audiences.
  • Creativity and adaptability to solve challenging and complex problems in a rapidly changing environment.
  • Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.

Preferred Experience and Education

  • Prior experience in a consulting or professional services role.
  • Experience with established DFIR methodology and process.
  • Experience with a variety of industry-related solutions including EDR, NDR, XDR, SIEM, FW, NGAV, Velociraptor, and others.
  • Proficiency with common programming and scripting languages including PowerShell, Python, Bash, Go, or similar.
  • Experience with enterprise cloud technologies such as Amazon Web Services, Google Workspace, Microsoft 365, and Azure.
  • Awareness of attacker techniques, advanced threat groups, and integration of threat intelligence into an investigation.
  • Relevant industry certifications such as, but not limited to, GCFA, GCFE, GCIH, GCIA, GDAT, GREM, or CISSP.

What Success Looks Like

  • You independently lead investigations end to end and deliver rigorous, high-quality analysis under pressure.
  • Your engagement deliverables are clear, accurate, and trusted by both technical and executive audiences.
  • You have improved at least one process, tool, or automation that makes DFIR engagements more efficient.
  • Clients recognize you as a credible, dependable technical resource during high-stakes incidents.
  • You operate with ownership and initiative—identifying problems, proposing solutions, and executing without being asked.

Travel Requirements:

  • Up to 20% travel

Physical Requirements:

  • Sedentary work
  • Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
  • Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.

Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,300 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option
本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位