Advisory Consultant, Incident Response (Remote)
Herndon, VA  / Atlanta, GA  / Austin, TX  / Baltimore, MD  / Boston, MA  / Charlotte, NC  / Chicago, IL  / Dallas, TX  / Denver, CO  / Troy, MI  / Houston, TX  / Minneapolis, MN  / Philadelphia, PA  / Raleigh, NC  / Kansas City, MO  / St. Louis, MO  / Tampa, FL  / New York, NY  / Orlando, FL  / Indianapolis, IN ...View All
View Less
Posted 1 day ago
Job Description

GuidePointSecurity provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems,GuidePointenables some of the nation's top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

As an Advisory Consultant, you will be a technical resource that leverages your knowledge, skills, and experience to help deliver results to clients in various sectors.

Underneath GuidePoint Security's Digital Forensics & Incident Response Practice (DFIR) and GuidePoint Research & Intelligence Team (GRIT) umbrella the Advisory Practice performs the following:

  • Purple Team Exercises (as Blue Team in collaboration with GuidePoint Red Team)
  • Tabletop Exercises
  • Playbook and Runbook Development
  • Work alongside GuidePoint Incident Responders with reactive incidents and proactive threat discovery
Role Requirements

Your primary responsibilities include development of challenging scenarios for GuidePoint clientele through Purple Team and Tabletop exercises, as well as helping clients navigate the creation of operational documentation for responding to incidents (Playbooks & Runbooks). This role will require an experienced individual that can view attacks from a holistic level, inclusive of both offensive and defensive mindsets, to create meaningful impacts for clients, while managing a consulting engagement.

GuidePoint Security's DFIR service offerings are perpetually evolving in response to emerging threats and diverse client needs. Your creativity and expertise will assist the DFIR Practice with adapting to this rapidly changing environment. Primary duties will include:

  • Planning, facilitation, documentation, development, and coordination of follow-up activities for the cyber exercise program including Purple Team engagements, Tabletop exercises, and Playbook & Runbook development.
  • Review of client documentation including incident response plans, Playbooks, Runbooks, information security policies, network maps, architecture diagrams, etc.
  • Coordinate exercise planning teams comprised of internal resources and GuidePoint clients with various technical, non-technical, and executive staff to plan and execute cybersecurity exercises.
  • Work with internal teams to identify cyber risks, design threat scenarios, identify key stakeholders and participants, as well as execute the exercise against the planned scenarios and objectives.
  • Assess observations and findings during exercises, communicate findings to stakeholders, and escalate high risk findings to appropriate personnel for risk remediation efforts.
  • Assist in the development of programmatic documents, briefings, and reports tailored to a specific audience.
Education and Experience

Essential Qualifications

  • Four (4+) years of experience in an Information Security Role
  • Experience with creating and facilitating Tabletop exercises
  • Strong written documentation experience
  • Experience with common documentation tools including Microsoft Office, Confluence, and Diagraming Tools (Visio, LucidChart, etc.)
  • The ability to learn new technologies and concepts quickly
  • Ability to manage projects, milestones, and deliverables for business-related objectives

Preferred Qualifications

  • Prior experience in a Consulting Services role
  • Experience with Digital Forensics & Incident Response (DFIR) methodology and process
  • Experience with Immersive Labs
  • Experience with a variety of industry-related solutions including EDR, SIEM, NDR, FW, NGAV, Velociraptor, OSQuery, and others
  • Experience with common programming languages including PowerShell, Python, BASH, Go, or others

Why GuidePoint?

GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 500 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 1,000 clients.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company's success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity. This is a unique and rare opportunity to grow your career along with the one of the fastest growing companies in the nation.

Some added perks....

  • MacBook Air or Pro
  • Healthy mobile phone and home internet allowance
  • 100% employer-paid medical and dental with generous employer family contributions
  • Eligibility for retirement plan after 2 months at open enrollment

Equal Opportunity Employer

GuidePoint Security, LLC is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, marital status, sexual orientation, gender identity, genetic information, protected veteran status, or any other characteristic protected by law.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.


Job Summary
Start Date
As soon as possible
Employment Term and Type
Regular, Full Time
Required Experience
4 years
Email this Job to Yourself or a Friend
Indicates required fields