Recovery & Restoration Consultant - Remote (Anywhere in the U.S.)
GuidePoint SecurityRole Overview
GuidePoint Security is hiring a entry-level Recovery & Restoration Consultant - Remote (Anywhere in the U.S.). This is a full-time remote role, with the team based in Remote. posted today. applications are still in the early window, before most candidates have applied. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job description
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
General Description
The Recovery & Restoration Consultant is a foundational member of the Incident Management & Recovery team, responsible for supporting the rebuild and securing of infrastructure environments following ransomware or other destructive cyber incidents. This role combines developing on-premises infrastructure expertise (Active Directory, VMware/Hyper-V, networking, backups) with growing Microsoft 365 and Azure/Entra ID knowledge.
You will support hands-on rebuild efforts across identity, compute, storage, networking, and cloud layers — working directly with clients, the GuidePoint Security Incident Response team, and senior engineers to restore business operations quickly, securely, and safely. This position reports to senior engineers and the R&R Engineering Manager, with the expectation of rapid growth through mentorship and real-world engagement experience.
Roles and Responsibilities:
- Support IT recovery projects involving on-premises endpoint and network infrastructure, Entra ID (Azure AD), and Microsoft 365 under the guidance of senior engineers
- Assist in developing technical remediation and restoration plans tailored to the impact on a client's environment
- Implement network containment and isolation measures on common firewall platforms in preparation for recovery efforts
- Assist in rebuilding Active Directory domains, DNS/DHCP, and Group Policy structures to a clean baseline
- Support restoration and validation of virtualized workloads (VMware ESXi, Hyper-V) and critical file/application servers
- Assist in recovering and securing Entra ID identities, Conditional Access policies, and synchronization with on-prem AD via Entra Connect
- Support rebuilds of Exchange Online, SharePoint, OneDrive, and Teams configurations
- Validate and restore data from backups (Veeam, Rubrik, Datto, etc.), ensuring integrity and cleanliness — understanding the critical difference between snapshots and proper isolated backups
- Utilize common remote management tools and VPN connections to assist impacted clients remotely
- Apply industry-standard Microsoft hardening guidelines throughout recovery processes
- Assist in implementing compliance controls such as MFA, Defender for Office 365, and Purview
- Develop and maintain PowerShell scripts for recurring recovery workflows
- Maintain thorough documentation of rebuilt configurations, recovery timelines, and actions taken — supporting defensible, auditable records for insurance carriers and legal counsel
- Maintain chain of custody awareness when handling evidence, disk images, or log files
Required Experience:
Windows & Active Directory Fundamentals
- Solid understanding of Active Directory as a centralized directory service for authentication and authorization
- Knowledge of AD objects (users, computers, groups, OUs) and Domain Controller roles (NTDS.dit, replication)
- Clear understanding of the difference between local administrator accounts (SAM database) and domain administrator accounts (Domain Admins group), including the security implications of each
- Ability to identify which domain controller a machine is authenticating against (e.g., %LOGONSERVER%, nltest, Get-ADDomainController)
- Working knowledge of Group Policy — purpose, GPO linking (sites, domains, OUs), and common enforcement use cases (password policies, drive mappings, firewall rules, USB restrictions)
- Understanding of why network isolation is the first step in a ransomware recovery scenario (containment, forensic preservation, preventing reintroduction of threats)
Cloud & Identity Basics
- Understanding of the distinction between on-premises Active Directory and Entra ID (Azure AD) — their respective roles and how they coexist in hybrid identity environments
- Familiarity with Entra Connect and hybrid identity synchronization concepts
- Solid understanding of MFA — what it is, why it's critical during recovery, and awareness that attackers target MFA (disabling it, registering rogue devices)
- Basic awareness of Conditional Access policies and their role in identity security
PowerShell Fundamentals
- Understanding of PowerShell as an object-oriented shell/scripting language and how it differs from cmd.exe (structured objects vs. plain text)
- Familiarity with cmdlet naming conventions (Verb-Noun) and basic commands (Get-Process, Get-Service, piping, Where-Object, Sort-Object)
- Understanding of execution policies (Get-ExecutionPolicy, Set-ExecutionPolicy, RemoteSigned, Bypass) and their security purpose
- Willingness and ability to write and modify scripts for recovery tasks; experience with AzureAD, ExchangeOnline, or Graph API modules is a plus
Virtualization Basics
- Understanding of hypervisor concepts — what they do and the difference between Type 1 (bare-metal: ESXi, Hyper-V, Proxmox) and Type 2 (hosted: VMware Workstation, VirtualBox)
- Clear understanding of the difference between VM snapshots and proper backups — snapshots reside on the same storage and are not a substitute for offsite/isolated backups
- Awareness that threat actors specifically target and delete snapshots and VSS shadow copies to prevent rollback
Troubleshooting & Problem-Solving
- Demonstrated ability to apply a logical, layered troubleshooting approach (physical → network → service) rather than random guessing
- Instinct to start simple (power, ping, physical connectivity) and progressively narrow scope
- Ability to isolate whether an issue is service-specific or host-wide
- Awareness of when to escalate — knowing the limits of your knowledge is a strength, not a weakness
- Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.
Preferred Requirements
- 1–3 years of experience in infrastructure engineering, IT support, or systems administration roles
- Exposure to consulting, MSP, or IT environments with diverse client infrastructure
- Microsoft certifications (e.g., AZ-900, AZ-104, MS-900, SC-900) or equivalent hands-on experience
- Familiarity with at least one EDR or security platform (CrowdStrike, SentinelOne, Microsoft Defender)
- Any prior exposure to incident response, disaster recovery, or high-pressure IT scenarios
- Home lab experience or self-driven technical projects demonstrating curiosity and initiative
Networking Fundamentals
- Understanding of IP addressing and subnet masks (network vs. host portion, common private ranges)
- Knowledge of the difference between TCP (connection-oriented, reliable) and UDP (connectionless, low overhead) and common use cases for each
- Understanding of VPN concepts — encrypted tunnels over untrusted networks, their role in secure remote engagement access, and least-privilege/segmented access principles
- Basic familiarity with firewall platforms and network segmentation concepts
Incident Response & Documentation
- Understanding of why thorough documentation is critical during IR engagements — creating defensible, auditable records for insurance carriers, legal counsel, and forensic review
- Awareness that undocumented actions can be indistinguishable from attacker activity during later analysis
- Basic understanding of chain of custody — maintaining an unbroken, documented record of evidence handling (labeling, hashing, logging)
- Ability to support clean handoffs between team members or shifts on 24/7 engagements
Disaster Recovery Awareness
- Understanding of RTO (Recovery Time Objective) and RPO (Recovery Point Objective)
- Basic awareness of how these objectives shape recovery prioritization during an engagement
Additional Requirements:
- Travel up to 50% may be required to client sites as required to perform recovery activities and on-site validation.
- Participate in after-hours response rotations.
Physical Requirements:
- Sedentary work
- Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
- Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day
We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.
Why GuidePoint?
GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.
Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.
This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.
Some added perks….
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
About GuidePoint Security
GuidePoint Security
guidepointsecurity.com
60 other open roles at GuidePoint Security on TryApplyNow.
Frequently Asked Questions
How do I apply for the Recovery & Restoration Consultant - Remote (Anywhere in the U.S.) position at GuidePoint Security?
Use the Apply button above to submit your application directly to GuidePoint Security. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Is the Recovery & Restoration Consultant - Remote (Anywhere in the U.S.) role at GuidePoint Security remote?
Yes. This is a remote role. The team is based in Remote, but the position itself does not require relocating to that office.
What does a Recovery & Restoration Consultant - Remote (Anywhere in the U.S.) at GuidePoint Security earn?
GuidePoint Security has not disclosed a salary range in this posting. Many employers share specifics later in the interview process; you can also ask during a recruiter screen if compensation transparency is important to you.
When was the Recovery & Restoration Consultant - Remote (Anywhere in the U.S.) role at GuidePoint Security posted?
This role was posted on July 21, 2026 (today). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
Is the Recovery & Restoration Consultant - Remote (Anywhere in the U.S.) role at GuidePoint Security entry-level?
Yes. This is an entry-level position. Strong candidates typically have 0-2 years of relevant work experience, internships, or significant project work. Read the full description for any specific qualification requirements GuidePoint Security has listed.
More Jobs at GuidePoint Security
View all →Account Executive (Southeast / Florida)
GuidePoint Security
Director, Information Technology Project Management Office
GuidePoint Security
Enterprise Cloud Security Architect
GuidePoint Security
Exposure Management Engineer - Northeast region (Remote)
GuidePoint Security
Cloud Security Engineer
GuidePoint Security
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get started freeNo credit card to start