Cyber Countermeasure Specialist

The Newberry Group

Waipahu (HI)

On-site

USD 140,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Sign-on bonus
Relocation assistance

Job summary

Newberry Group seeks a Cyber Countermeasure Specialist to help defend the Joint Fires Network in a TS/SCI environment on Ford Island, HI. You will bridge detection analytics with active threat containment, tuning sensors like Corelight and Elastic Defend, and developing custom rules to block intrusions.

Role requires SCIF work, DoD baseline certifications, and close collaboration with DISA, NOC, and threat-hunting teams.

Qualifications

  • Bachelor’s degree in a technical field with related cyber defense experience or equivalent military experience.
  • 2+ years in intrusion detection/prevention engineering or network defense operations.
  • Experience with signature development, rules, and threat containment workflows.
  • Must be able to operate in TS/SCI environments and SCIF settings.

Responsibilities

  • Configure and tune security sensors to maximize high-fidelity detection while reducing noise.
  • Develop and maintain custom intrusion detection signatures and scripts (Zeek, YARA, etc.).
  • Validate and maintain log ingestion pipelines (Logstash) and sensor event logic for containment.
  • Track countermeasures and actions in JIRA; coordinate with DISA and field leadership during incidents.
  • Support rapid rollback testing and operational stability of sensor configurations.

Skills

Sensor tuning
Custom signatures
Threat containment
JIRA tracking
SCIF operations
Networking fundamentals
Incident response

Education

Bachelor’s degree in Cybersecurity/CS/CE/IT
2+ years in intrusion detection/prevention

Tools

Corelight
Elastic Defend
Zeek
YARA
ELK stack
Palo Alto equipment
Logstash

Job description

Job Summary - $10,000 sign-on bonus included (subject to a 12-month commitment)

Newberry Group is seeking an experienced, technically agile Cyber Countermeasure Specialist to support our customer’s defensive cyber operations team supporting the Joint Fires Network (JFN). Stationed inside secure SCIF environments at DISA Pacific (Ford Island, HI), this position plays a critical role in bridging detection analytics and active threat containment for the JFN Impact Level 7 (IL-7) environment and associated multi-domain operational enclaves.

Location

This is a full-time onsite role in Ford Island, HI. Telework is not permitted.

Relocation expenses may be eligible for reimbursement.

Responsibilities and Duties
1. Countermeasure Engineering, Sensor Tuning & Active Defense
  • Sensor Tuning & Management: Configure, tune, and operationalize advanced boundary and enroute security sensors—including Corelight (Zeek-based telemetry) and Elastic Defend to maximize high-fidelity detection while suppressing noise across JFN nodes.
  • Custom Signature & Rule Development: Design, test, validate, and maintain custom intrusion detection rules, Zeek scripts, YARA rules, and Elastic SIEM detection logic targeting emerging exploit patterns, living-off-the-land techniques, and lateral movement attempts.
  • Palo Alto ATP & Pipeline Ingestion: Collaborate with NIWC data engineers to validate log ingestion pipelines (Logstash) from Palo Alto Advanced Threat Prevention (ATP), Prometheus, and endpoint monitors, ensuring sensor event logic triggers actionable containment mechanisms.
  • Countermeasure Tracking & De-confliction: Track all deployed signatures and mitigation actions within JIRA; execute deliberate de-confliction procedures with DISA and operational network authorities to prevent unintended disruption to operational fires data streams.
  • Rapid Rollback & Operational Stability: Establish, document, and test rapid rollback mechanisms to immediately revert sensor configurations and containment rules if mission communications are impacted during crisis execution.
2. Playbook Engineering & Incident Response Automation
  • Containment Playbook Development: Leverage Atlassian JIRA to design, automate, document, and maintain end-to-end standard operating procedures (SOPs) and execution runbooks for routine threat containment, node isolation and sensor re-baselining.
  • Incident Response Plan Operationalization: Support the drafting, maintenance, and technical execution of the JFN Incident Response Plan, ensuring rapid transition from alert triage to active containment.
  • CSSP Defense Service Integration: Drive the technical countermeasure delivery for four of the seven DoD Cybersecurity Service Provider (CSSP) core functions during Phase I standup, expanding to full CSSP operational countermeasure capability during Phase II sustainment.
  • Traffic Pattern & Behavioral Countermeasures: Translate behavioral anomaly findings and traffic pattern analyses developed by threat hunters into actionable, rule-based containment triggers across SD-WAN interfaces and out-of-band management channels.
3. Classified Spill Containment & SCIF Operations
  • Spill & Breach Containment: Implement and enforce rigorous Defense Intelligence Agency (DIA) protocols for containment and technical quarantine of classified data spills, unauthorized cross-domain transfers, or credential compromise within TS/SCI and IL-6 domains.
  • Audit Readiness & Compliance: Verify that all active countermeasures, alerting mechanisms, and log capture configurations strictly adhere to formal TS/SCI Information Systems Security Program audit criteria and JFN Security Classification Guidance.
  • Cross-Functional Team Collaboration: Partner daily with JFN 24/7 Real-Time Analysts, Tier II NOC administrators managing SolarWinds and Jira, and DISA Field Command leadership to coordinate high-priority containment actions during active network events.
  • SCIF Operational Assurance: Conduct all defensive engineering within designated Sensitive Compartmented Information Facilities (SCIF), maintaining operational integrity across classified enclaves.
Clearance & Citizenship
  • Citizenship: Must be a U.S. Citizen
  • Security Clearance: Must possess an active Top Secret clearance with current SCI eligibility (adjudicated Tier 5 / SSBI) prior to start date, with the ability to maintain clearance while working in a secure SCIF environment.
Education & Experience Requirements
  • Level II (Intermediate): Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or related discipline with 2+ years of direct experience in intrusion detection/prevention engineering, custom signature creation, or network defense operations; OR an Associate degree with 4+ years; OR 6+ years of relevant experience/military cyber service in lieu of degree.
  • Level III (Senior): Bachelor’s degree in a technical discipline with 4+ years of relevant experience; OR an Associate degree with 6+ years; OR 8+ years of relevant experience/military cyber service in lieu of degree.
Required DoD 8140 / 8570 Baseline Certification
  • Must hold a valid certification or degree meeting DoD 8140.03 / DCWF Work Role Code 521: Cyber Defense Infrastructure Support Specialist at the Basic Proficiency Level prior to start.
  • Accepted Certifications include: CySA+, CCNA-Security, GICSP, GSEC, Security+ CE, CND, CEH, or higher (e.g., CASP+ CE, CISSP, GCIA, GCIH).
Technical Core Competencies
  • Proven experience authoring, testing, and deploying custom network intrusion signatures and parsing logic (e.g., Snort/Suricata rules, Zeek scripts, YARA, or Elastic KQL/EQL query rules).
  • Hands-on operational experience with enterprise sensor platforms such as Corelight, Elastic Defend / ELK Stack, or next-generation firewalls (e.g., Palo Alto Networks).
  • Demonstrated experience developing, documenting, and executing threat containment workflows and tracking procedures using Atlassian JIRA.
  • Solid understanding of core networking protocols (TCP/IP, BGP, IPsec, DNS, TLS), network perimeter architectures, and packet analysis tools (Wireshark, tcpdump).
  • Ability to support standard operational day shifts (8x5) with on-call flexibility for emergency after-hours containment surges or critical network defense events.
Preferred Qualifications
  • Direct experience deploying and managing countermeasures across Impact Level 6/7 (IL-6/7), SIPRNet, or Top Secret / SCI enclaves.
  • Familiarity with Software-Defined WAN (SD-WAN) technologies, Out-of-Band network management, and SolarWinds monitoring integrations.
  • Experience with automated containment scripting using Python, PowerShell, Bash, or REST APIs.
  • Understanding of Darktrace Managed Detection & Response (MDR) and Prometheus pipeline data flows.
  • Prior experience supporting C4ISR systems or joint tactical enclaves.
Who We Are…

Newberry Group is a performance-driven government services and solutions firm that provides security compliance, program governance, consulting, and customized solutions for public sector clients nationwide.

The strength of our company is a direct reflection of our highly skilled and talented workforce.

Benefits and Perks

In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more.

The Newberry Group, Inc. is an Equal Opportunity Employer – EEO/AA/Disability/Veterans.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Analyst
Cyber Threat Analyst

The Newberry Group • Waipahu (HI)

On-site
USD 120,000 - 160,000
Medical coverage
Relocation reimbursement
Tuition and training reimbursement
+1
Cyber Real Time Analyst
Cyber Real Time Analyst

The Newberry Group • Waipahu (HI)

On-site
USD 110,000 - 150,000
Sign-on bonus
Relocation assistance
Cybersecurity Analyst
Cybersecurity Analyst

thenewberrygroup • O'Fallon (IL)

On-site
USD 95,000 - 125,000
Medical coverage
Paid time off
Retirement plan
Junior Security Control Assessor
Junior Security Control Assessor

thenewberrygroup • Fort Meade (MD)

Hybrid
USD 50,000 - 60,000
Medical, dental, vision coverage
Paid time off
Paid holidays
+6
Network Based Systems Analyst II
Network Based Systems Analyst II

DigiFlight, Inc. • Arlington (VA)

On-site
USD 90,000 - 120,000
Health, Dental, Vision Insurance
Paid Time Off
Tuition Education Assistance
+1
JCDC Cyber Triage Analyst - 3-5 years of experience
JCDC Cyber Triage Analyst - 3-5 years of experience

BCMC • Arlington (VA)

On-site
USD 90,000 - 130,000
Competitive salary
Employer-paid health benefits
401(k) with company match
+2
Malware Analyst
Malware Analyst

Indigo IT LLC • Fort Bragg (NC)

On-site
USD 110,000 - 150,000
Medical, Dental, Vision coverage
401(k) with company match
Group life and disability
+5
Incident Manager (Midlevel)
Incident Manager (Midlevel)

Node.Digital LLC • Arlington (VA)

On-site
USD 100,000 - 130,000
Medical
Dental
Vision
+3
Host Based Systems Analyst II
Host Based Systems Analyst II

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 140,000
Network Based System Analyst
Network Based System Analyst

Node.Digital LLC • Arlington (VA)

On-site
USD 90,000 - 120,000
Medical
Dental
Vision
+3