Recovery & Restoration Consultant - Remote (Anywhere in the U.S.)
GuidePoint Security
| Company | GuidePoint Security |
| Category | Consulting & Strategy |
| Location | Remote |
| Remote | Remote |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 21 Jul 2026 |
| Last verified | 9 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk. General Description
The Recovery & Restoration Consultant is a foundational member of the Incident Management & Recovery team, responsible for supporting the rebuild and securing of infrastructure environments following ransomware or other destructive cyber incidents. This role combines developing on-premises infrastructure expertise (Active Directory, VMware/Hyper-V, networking, backups) with growing Microsoft 365 and Azure/Entra ID knowledge.
You will support hands-on rebuild efforts across identity, compute, storage, networking, and cloud layers — working directly with clients, the GuidePoint Security Incident Response team, and senior engineers to restore business operations quickly, securely, and safely. This position reports to senior engineers and the R&R Engineering Manager, with the expectation of rapid growth through mentorship and real-world engagement experience.
Roles and Responsibilities:
Support IT recovery projects involving on-premises endpoint and network infrastructure, Entra ID (Azure AD), and Microsoft 365 under the guidance of senior engineers
Assist in developing technical remediation and restoration plans tailored to the impact on a client's environment
Implement network containment and isolation measures on common firewall platforms in preparation for recovery efforts
Assist in rebuilding Active Directory domains, DNS/DHCP, and Group Policy structures to a clean baseline
Support restoration and validation of virtualized workloads (VMware ESXi, Hyper-V) and critical file/application servers
Assist in recovering and securing Entra ID identities, Conditional Access policies, and synchronization with on-prem AD via Entra Connect
Support rebuilds of Exchange Online, SharePoint, OneDrive, and Teams configurations
Validate and restore data from backups (Veeam, Rubrik, Datto, etc.), ensuring integrity and cleanliness — understanding the critical difference between snapshots and proper isolated backups
Utilize common remote management tools and VPN connections to assist impacted clients remotely
Apply industry-standard Microsoft hardening guidelines throughout recovery processes
Assist in implementing compliance controls such as MFA, Defender for Office 365, and Purview
Develop and maintain PowerShell scripts for recurring recovery workflows
Maintain thorough documentation of rebuilt configurations, recovery timelines, and actions taken — supporting defensible, auditable records for insurance carriers and legal counsel
Maintain chain of custody awareness when handling evidence, disk images, or log files
Required Experience:
Windows & Active Directory Fundamentals
Solid understanding of Active Directory as a centralized directory service for authentication and authorization
Knowledge of AD objects (users, computers, groups, OUs) and Domain Controller roles (NTDS.dit, replication)
Clear understanding of the difference between local administrator accounts (SAM database) and domain administrator accounts (Domain Admins group), including the security implications of each
Ability to identify which domain controller a machine is authenticating against (e.g., %LOGONSERVER%, nltest, Get-ADDomainController)
Working knowledge of Group Policy — purpose, GPO linking (sites, domains, OUs), and common enforcement use cases (password policies, drive mappings, firewall rules, USB restrictions)
Understanding of why network isolation is the first step in a ransomware