Recovery & Restoration Consultant - Remote (Anywhere in the U.S.)
About the role
General Description
The Recovery & Restoration Consultant is a foundational member of the Incident Management & Recovery team, responsible for supporting the rebuild and securing of infrastructure environments following ransomware or other destructive cyber incidents. This role combines developing on-premises infrastructure expertise (Active Directory, VMware/Hyper-V, networking, backups) with growing Microsoft 365 and Azure/Entra ID knowledge.
You will support hands-on rebuild efforts across identity, compute, storage, networking, and cloud layers — working directly with clients, the GuidePoint Security Incident Response team, and senior engineers to restore business operations quickly, securely, and safely. This position reports to senior engineers and the R&R Engineering Manager, with the expectation of rapid growth through mentorship and real-world engagement experience.
Roles and Responsibilities
- Support IT recovery projects involving on-premises endpoint and network infrastructure, Entra ID (Azure AD), and Microsoft 365 under the guidance of senior engineers
- Assist in developing technical remediation and restoration plans tailored to the impact on a client's environment
- Implement network containment and isolation measures on common firewall platforms in preparation for recovery efforts
- Assist in rebuilding Active Directory domains, DNS/DHCP, and Group Policy structures to a clean baseline
- Support restoration and validation of virtualized workloads (VMware ESXi, Hyper-V) and critical file/application servers
- Assist in recovering and securing Entra ID identities, Conditional Access policies, and synchronization with on-prem AD via Entra Connect
- Support rebuilds of Exchange Online, SharePoint, OneDrive, and Teams configurations
- Validate and restore data from backups (Veeam, Rubrik, Datto, etc.), ensuring integrity and cleanliness — understanding the critical difference between snapshots and proper isolated backups
- Utilize common remote management tools and VPN connections to assist impacted clients remotely
- Apply industry-standard Microsoft hardening guidelines throughout recovery processes
- Assist in implementing compliance controls such as MFA, Defender for Office 365, and Purview
- Develop and maintain PowerShell scripts for recurring recovery workflows
- Maintain thorough documentation of rebuilt configurations, recovery timelines, and actions taken — supporting defensible, auditable records for insurance carriers and legal counsel
- Maintain chain of custody awareness when handling evidence, disk images, or log files
Required Experience
Windows & Active Directory Fundamentals
- Solid understanding of Active Directory as a centralized directory service for authentication and authorization
- Knowledge of AD objects (users, computers, groups, OUs) and Domain Controller roles (NTDS.dit, replication)
- Clear understanding of the difference between local administrator accounts (SAM database) and domain administrator accounts (Domain Admins group), including the security implications of each
- Ability to identify which domain controller a machine is authenticating against (e.g., %LOGONSERVER%, nltest, Get