ForgeApply
Try it free

ForgeApply · Job listing

Recovery & Restoration Consultant - Remote (Anywhere in the U.S.)

Guidepointsecurity

Remote · US

Apply in about a minute — without sacrificing quality.

ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.

About this role

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

General Description

The Recovery & Restoration Consultant is a foundational member of the Incident Management & Recovery team, responsible for supporting the rebuild and securing of infrastructure environments following ransomware or other destructive cyber incidents. This role combines developing on-premises infrastructure expertise (Active Directory, VMware/Hyper-V, networking, backups) with growing Microsoft 365 and Azure/Entra ID knowledge.

You will support hands-on rebuild efforts across identity, compute, storage, networking, and cloud layers — working directly with clients, the GuidePoint Security Incident Response team, and senior engineers to restore business operations quickly, securely, and safely. This position reports to senior engineers and the R&R Engineering Manager, with the expectation of rapid growth through mentorship and real-world engagement experience.

Roles and Responsibilities:

• Support IT recovery projects involving on-premises endpoint and network infrastructure, Entra ID (Azure AD), and Microsoft 365 under the guidance of senior engineers

• Assist in developing technical remediation and restoration plans tailored to the impact on a client's environment

• Implement network containment and isolation measures on common firewall platforms in preparation for recovery efforts

• Assist in rebuilding Active Directory domains, DNS/DHCP, and Group Policy structures to a clean baseline

• Support restoration and validation of virtualized workloads (VMware ESXi, Hyper-V) and critical file/application servers

• Assist in recovering and securing Entra ID identities, Conditional Access policies, and synchronization with on-prem AD via Entra Connect

• Support rebuilds of Exchange Online, SharePoint, OneDrive, and Teams configurations

• Validate and restore data from backups (Veeam, Rubrik, Datto, etc.), ensuring integrity and cleanliness — understanding the critical difference between snapshots and proper isolated backups

• Utilize common remote management tools and VPN connections to assist impacted clients remotely

• Apply industry-standard Microsoft hardening guidelines throughout recovery processes

• Assist in implementing compliance controls such as MFA, Defender for Office 365, and Purview

• Develop and maintain PowerShell scripts for recurring recovery workflows

• Maintain thorough documentation of rebuilt configurations, recovery timelines, and actions taken — supporting defensible, auditable records for insurance carriers and legal counsel

• Maintain chain of custody awareness when handling evidence, disk images, or log files

Required Experience:

Windows & Active Directory Fundamentals

• Solid understanding of Active Directory as a centralized directory service for authentication and authorization

• Knowledge of AD objects (users, computers, groups, OUs) and Domain Controller roles (NTDS.dit, replication)

• Clear understanding of the difference between local administrator accounts (SAM database) and domain administrator accounts (Domain Admins group), including the security implications of each

• Ability to identify which domain controller a machine is authenticating against (e.g., %LOGONSERVER%, nltest, Get-ADDomainController)

• Working knowledge of Group Policy — purpose, GPO linking (sites, domains, OUs), and common enforcement use cases (password policies, drive mappings, firewall rules, USB restrictions)

• Understanding of why network isolation is the first step in a ransomware recovery scenario (containment, forensic preservation, preventing reintroduction of threats)

Cloud & Identity Basics

• Understanding of the distinction between on-premises Active Directory and Entra ID (Azure AD) — their respective roles and how they coexist in hybrid identity environments

• Familiarity with Entra Connect and hybrid identity synchronization concepts

• Solid understanding of MFA — what it is, why it's critical during recovery, and awareness that attackers target MFA (disabling it, registering rogue devices)

• Basic awareness of Conditional Access policies and their role in identity security

PowerShell Fundamentals

• Understanding of PowerShell as an object-oriented shell/scripting language and how it differs from cmd.exe (structured objects vs. plain text)

• Familiarity with cmdlet naming conventions (Verb-Noun) and basic commands (Get-Process, Get-Service, piping, Where-Object, Sort-Object)

• Understanding of execution policies (Get-ExecutionPolicy, Set-ExecutionPolicy, RemoteSigned, Bypass) and their security purpose

• Willingness and ability to write and modify scripts for recovery tasks; experience with AzureAD, ExchangeOnline, or Graph API modules is a plus

Virtualization Basics

• Understanding of hypervisor concepts — what they do and the difference between Type 1 (bare-metal: ESXi, Hyper-V, Proxmox) and Type 2 (hosted: VMware Workstation, VirtualBox)

• Clear understanding of the difference between VM snapshots and proper backups — snapshots reside on the same storage and are not a substitute for offsite/isolated backups

• Awareness that threat actors specifically target and delete snapshots and VSS shadow copies to prevent rollback

Troubleshooting & Problem-Solving

• Demonstrated ability to apply a logical, layered troubleshooting approach (physical → network → service) rather than random guessing

• Instinct to start simple (power, ping, physical connectivity) and progressively narrow scope

• Ability to isolate whether an issue is service-specific or host-wide

• Awareness of w

Ready to apply to Guidepointsecurity?

Apply in about a minute

Similar jobs

More like this: More jobs at Guidepointsecurity · Browse all jobs