Logo for GuidePoint Security

Recovery & Restoration Consultant - Remote (Anywhere in the U.S.)

Role overview

Qualifications

  • Windows Active Directory Fundamentals
  • Cloud Identity Basics
  • PowerShell Fundamentals
  • Virtualization Basics

Responsibilities

  • Support IT recovery projects involving on-premises endpoint and network infrastructure, Entra ID (Azure AD), and Microsoft 365
  • Assist in developing technical remediation and restoration plans tailored to the impact on a client's environment
  • Implement network containment and isolation measures on common firewall platforms in preparation for recovery efforts
  • Support restoration and validation of virtualized workloads (VMware ESXi, Hyper-V) and critical file/application servers

About the company

GuidePoint Security logo

GuidePoint Security

Cybersecurity

GuidePoint Security is an elite team of highly trained, top certified experts who cut through cyber chaos and confusion to put control back in your hands. We help you make the smartest, most informed decisions, choose and integrate products and services that are the best fit, and build the most effective cybersecurity posture. We provide organizations with holistic perspective on their cyber ecosystem to minimize gaps, vulnerabilities, and optimize resources, including: 1. Understanding the changing threat landscape, vulnerabilities, and gaps 2. New insights of how product decisions align with resource capacity 3. Insightful product comparisons and integration to save time, money, and mistakes

Company details

Company typeSME
IndustryCybersecurity
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

General Description

The Recovery & Restoration Consultant is a foundational member of the Incident Management & Recovery team, responsible for supporting the rebuild and securing of infrastructure environments following ransomware or other destructive cyber incidents. This role combines developing on-premises infrastructure expertise (Active Directory, VMware/Hyper-V, networking, backups) with growing Microsoft 365 and Azure/Entra ID knowledge.

You will support hands-on rebuild efforts across identity, compute, storage, networking, and cloud layers — working directly with clients, the GuidePoint Security Incident Response team, and senior engineers to restore business operations quickly, securely, and safely. This position reports to senior engineers and the R&R Engineering Manager, with the expectation of rapid growth through mentorship and real-world engagement experience.

Roles and Responsibilities:  

  • Support IT recovery projects involving on-premises endpoint and network infrastructure, Entra ID (Azure AD), and Microsoft 365 under the guidance of senior engineers
  • Assist in developing technical remediation and restoration plans tailored to the impact on a client's environment
  • Implement network containment and isolation measures on common firewall platforms in preparation for recovery efforts
  • Assist in rebuilding Active Directory domains, DNS/DHCP, and Group Policy structures to a clean baseline
  • Support restoration and validation of virtualized workloads (VMware ESXi, Hyper-V) and critical file/application servers
  • Assist in recovering and securing Entra ID identities, Conditional Access policies, and synchronization with on-prem AD via Entra Connect
  • Support rebuilds of Exchange Online, SharePoint, OneDrive, and Teams configurations
  • Validate and restore data from backups (Veeam, Rubrik, Datto, etc.), ensuring integrity and cleanliness — understanding the critical difference between snapshots and proper isolated backups
  • Utilize common remote management tools and VPN connections to assist impacted clients remotely
  • Apply industry-standard Microsoft hardening guidelines throughout recovery processes
  • Assist in implementing compliance controls such as MFA, Defender for Office 365, and Purview
  • Develop and maintain PowerShell scripts for recurring recovery workflows
  • Maintain thorough documentation of rebuilt configurations, recovery timelines, and actions taken — supporting defensible, auditable records for insurance carriers and legal counsel
  • Maintain chain of custody awareness when handling evidence, disk images, or log files

Required Experience: 

Windows & Active Directory Fundamentals

  • Solid understanding of Active Directory as a centralized directory service for authentication and authorization
  • Knowledge of AD objects (users, computers, groups, OUs) and Domain Controller roles (NTDS.dit, replication)
  • Clear understanding of the difference between local administrator accounts (SAM database) and domain administrator accounts (Domain Admins group), including the security implications of each
  • Ability to identify which domain controller a machine is authenticating against (e.g., %LOGONSERVER%, nltest, Get-ADDomainController)
  • Working knowledge of Group Policy — purpose, GPO linking (sites, domains, OUs), and common enforcement use cases (password policies, drive mappings, firewall rules, USB restrictions)
  • Understanding of why network isolation is the first step in a ransomware recovery scenario (containment, forensic preservation, preventing reintroduction of threats)

Cloud & Identity Basics

  • Understanding of the distinction between on-premises Active Directory and Entra ID (Azure AD) — their respective roles and how they coexist in hybrid identity environments
  • Familiarity with Entra Connect and hybrid identity synchronization concepts
  • Solid understanding of MFA — what it is, why it's critical during recovery, and awareness that attackers target MFA (disabling it, registering rogue devices)
  • Basic awareness of Conditional Access policies and their role in identity security

PowerShell Fundamentals

  • Understanding of PowerShell as an object-oriented shell/scripting language and how it differs from cmd.exe (structured objects vs. plain text)
  • Familiarity with cmdlet naming conventions (Verb-Noun) and basic commands (Get-Process, Get-Service, piping, Where-Object, Sort-Object)
  • Understanding of execution policies (Get-ExecutionPolicy, Set-ExecutionPolicy, RemoteSigned, Bypass) and their security purpose
  • Willingness and ability to write and modify scripts for recovery tasks; experience with AzureAD, ExchangeOnline, or Graph API modules is a plus

Virtualization Basics

  • Understanding of hypervisor concepts — what they do and the difference between Type 1 (bare-metal: ESXi, Hyper-V, Proxmox) and Type 2 (hosted: VMware Workstation, VirtualBox)
  • Clear understanding of the difference between VM snapshots and proper backups — snapshots reside on the same storage and are not a substitute for offsite/isolated backups
  • Awareness that threat actors specifically target and delete snapshots and VSS shadow copies to prevent rollback

Troubleshooting & Problem-Solving

  • Demonstrated ability to apply a logical, layered troubleshooting approach (physical → network → service) rather than random guessing
  • Instinct to start simple (power, ping, physical connectivity) and progressively narrow scope
  • Ability to isolate whether an issue is service-specific or host-wide
  • Awareness of when to escalate — knowing the limits of your knowledge is a strength, not a weakness
  • Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.

Preferred Requirements

  • 1–3 years of experience in infrastructure engineering, IT support, or systems administration roles
  • Exposure to consulting, MSP, or IT environments with diverse client infrastructure
  • Microsoft certifications (e.g., AZ-900, AZ-104, MS-900, SC-900) or equivalent hands-on experience
  • Familiarity with at least one EDR or security platform (CrowdStrike, SentinelOne, Microsoft Defender)
  • Any prior exposure to incident response, disaster recovery, or high-pressure IT scenarios
  • Home lab experience or self-driven technical projects demonstrating curiosity and initiative

Networking Fundamentals

  • Understanding of IP addressing and subnet masks (network vs. host portion, common private ranges)
  • Knowledge of the difference between TCP (connection-oriented, reliable) and UDP (connectionless, low overhead) and common use cases for each
  • Understanding of VPN concepts — encrypted tunnels over untrusted networks, their role in secure remote engagement access, and least-privilege/segmented access principles
  • Basic familiarity with firewall platforms and network segmentation concepts

Incident Response & Documentation

  • Understanding of why thorough documentation is critical during IR engagements — creating defensible, auditable records for insurance carriers, legal counsel, and forensic review
  • Awareness that undocumented actions can be indistinguishable from attacker activity during later analysis
  • Basic understanding of chain of custody — maintaining an unbroken, documented record of evidence handling (labeling, hashing, logging)
  • Ability to support clean handoffs between team members or shifts on 24/7 engagements

Disaster Recovery Awareness

  • Understanding of RTO (Recovery Time Objective) and RPO (Recovery Point Objective)
  • Basic awareness of how these objectives shape recovery prioritization during an engagement

Additional Requirements:

  • Travel up to 50% may be required to client sites as required to perform recovery activities and on-site validation.
  • Participate in after-hours response rotations.

Physical Requirements:

  • Sedentary work
  • Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
  • Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.


Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.  

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks….

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Consultant Related jobs

Other jobs at GuidePoint Security

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.