Recovery & Restoration Consultant - Remote (Anywhere in the U.S.)
GuidePoint Security · United States · 4 days ago
RemoteRemoteConsultingFull-time
About the role
The Recovery & Restoration Consultant supports the rebuild and securing of infrastructure environments following ransomware or other destructive cyber incidents. This role combines developing on-premises infrastructure expertise with growing Microsoft 365 and Azure/Entra ID knowledge.
Responsibilities
- Support IT recovery projects involving on-premises endpoint and network infrastructure, Entra ID (Azure AD), and Microsoft 365 under the guidance of senior engineers
- Aid in developing technical remediation and restoration plans tailored to the impact on a client's environment
- Implement network containment and isolation measures on common firewall platforms in preparation for recovery efforts
- Rebuild Active Directory domains, DNS/DHCP, and Group Policy structures to a clean baseline
- Support restoration and validation of virtualized workloads (VMware ESXi, Hyper-V) and critical file/application servers
- Assist in recovering and securing Entra ID identities, Conditional Access policies, and synchronization with on-prem AD via Entra Connect
- Validate and restore data from backups (Veeam, Rubrik, Datto, etc.), ensuring integrity and cleanliness — understanding the critical difference between snapshots and proper isolated backups
- Utilize common remote management tools and VPN connections to assist impacted clients remotely
- Apply industry-standard Microsoft hardening guidelines throughout recovery processes
- Develop and maintain PowerShell scripts for recurring recovery workflows
- Maintain thorough documentation of rebuilt configurations, recovery timelines, and actions taken — supporting defensible, auditable records for insurance carriers and legal counsel
- Maintain chain of custody awareness when handling evidence, disk images, or log files
Requirements
- Solid understanding of Active Directory as a centralized directory service for authentication and authorization
- Clear understanding of the difference between local administrator accounts (SAM database) and domain administrator accounts (Domain Admins group), including the security implications of each
- Ability to identify which domain controller a machine is authenticating against (e.g., %LOGONSERVER%, nltest, Get-ADDomainController)
- Working knowledge of Group Policy — purpose, GPO linking (sites, domains, OUs), and common enforcement use cases (password policies, drive mappings, firewall rules, USB restrictions)
- Understanding of why network isolation is the first step in a ransomware recovery scenario (containment, forensic preservation, preventing reintroduction of threats)
- Solid understanding of MFA — what it is, why it's critical during recovery, and awareness that attackers target MFA (disabling it, registering rogue devices)
- Basic awareness of Conditional Access policies and their role in identity security
- Understanding of why network isolation is the first step in a ransomware recovery scenario (containment, forensic preservation, preventing reintroduction of threats)
- Understanding of the difference between VM snapshots and proper backups — snapshots reside on the same storage and are not a substitute for offsite/isolated backups
- Willingness and ability to write and modify scripts for recovery tasks; experience with AzureAD, ExchangeOnline, or Graph API modules is a plus
- Understanding of the difference between Type 1 (bare-metal: ESXi, Hyper-V, Proxmox) and Type 2 (hosted: VMware Workstation, VirtualBox) hypervisors
- Understanding of troubleshooting and problem-solving techniques, including a logical, layered troubleshooting approach (physical → network → service)
- Experience with EDR or security platforms (CrowdStrike, SentinelOne, Microsoft Defender) is a plus
- Exposure to incident response, disaster recovery, or high-pressure IT scenarios
- Exposure to consulting, MSP, or IT environments with diverse client infrastructure
- Exposure to Microsoft certifications (e.g., AZ-900, AZ-104, MS-900, SC-900) or equivalent hands-on experience
Qualifications
- 1–3 years of experience in infrastructure engineering, IT support, or systems administration roles
- Exposure to consulting, MSP, or IT environments with diverse client infrastructure
- Exposure to Microsoft certifications (e.g., AZ-900, AZ-104, MS-900, SC-900) or equivalent hands-on experience
- Familiarity with at least one EDR or security platform (CrowdStrike, SentinelOne, Microsoft Defender)
- Any prior exposure to incident response, disaster recovery, or high-pressure IT scenarios
- Home lab experience or self-driven technical projects demonstrating curiosity and initiative
- Understanding of IP addressing and subnet masks (network vs. host portion, common private ranges)
- Knowledge of the difference between TCP (connection-oriented, reliable) and UDP (connectionless, low overhead) and common use cases for each
- Basic familiarity with firewall platforms and network segmentation concepts
- Understanding of incident response and disaster recovery concepts
- Understanding of RTO (Recovery Time Objective) and RPO (Recovery Point Objective)
Skills
- PowerShell fundamentals
- Virtualization basics
- Network fundamentals
- Cloud & identity basics
- Incident response & documentation
- Disaster recovery awareness
Benefits
At GuidePoint, we offer:
- Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family)) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family).
- If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Pet Benefit Option
Pay
Competitive salary commensurate with experience
Schedule
Flexible schedule with occasional evening and weekend work as needed