Cyber Threat Analyst

The Newberry Group

Waipahu (HI)

On-site

USD 120,000 - 160,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical coverage
Relocation reimbursement
Tuition and training reimbursement
Paid time off

Job summary

Newberry Group seeks a Cyber Threat Analyst to support the Joint Fires Network SOC, analyzing network telemetry and advanced sensor feeds to hunt threats and develop novel playbooks. You will map adversary TTPs to MITRE ATT&CK, tune detections in Elastic Defend, and draft incident responses within secure SCIF environments.

The role requires TS/SCI-level eligibility, DoD 8140 baseline certification, and experience with Corelight or Darktrace.

Qualifications

  • Bachelor’s degree in a technical field plus 2+ years in cyber threat intelligence, threat hunting, or SOC operations, or equivalent experience.
  • DoD 8140/ DCWF-based certification required prior to hire.
  • Experience with SIEMs and network telemetry analysis required.

Responsibilities

  • Develop novel threat hunting playbooks focused on behavioral anomalies and C2 patterns.
  • Analyze network telemetry and logs to detect and contain threats across multiple nodes.
  • Tune SIEM queries (ELK) and correlate alerts to reduce false positives.
  • Prepare threat intelligence summaries and brief leadership on incidents and adversary activity.

Skills

Threat hunting
Threat intelligence
Incident response coordination
MITRE ATT&CK mapping
SIEM tuning

Education

Bachelor’s degree in Cybersecurity/Intelligence/CS/IT
DoD 8140/8570 baseline certification

Tools

Elasticsearch/ELK
Logstash
Kibana
Elastic Defend
Corelight
Darktrace MDR
JIRA

Job description

Job Summary -$10,000 sign-on bonus included (subject to a 12-month commitment)

Newberry Group is seeking an analytical, mission-driven Cyber Threat Analyst to join our customer’s defensive cyber operations team supporting the Joint Fires Network (JFN) Security Operations Center (SOC). Operating out of secure Sensitive Compartmented Information Facilities (SCIFs) at DISA Pacific (Ford Island, HI), this team provides specialized threat intelligence synthesis, behavioral anomaly detection, and advanced threat hunting to safeguard the JFN Impact Level 7 (IL-7) and multi-level classified enclaves supporting the Olympus Fires mission.

In this role, you will analyze network telemetry, advanced sensor feeds (such as Corelight and Darktrace), and syslog audits across up to 30 active operational nodes (including SD-WAN transport fabrics tied to the DISN and GMS). You will develop novel behavioral threat hunting playbooks, formulate containment and response strategies in JIRA, support the JFN Incident Response Plan, ensure DIA-aligned TS/SCI incident escalation compliance, and translate adversary tradecraft into detection logic for the Elastic Search / Elastic Defend SIEM platform.

Location

This is a full-time onsite role in Ford Island, HI. Telework is not permitted.

Relocation expenses may be eligible for reimbursement.

Responsibilities and Duties
1. Advanced Threat Hunting & Novel Playbook Development
  • Novel Playbook Authoring: Design, test, and operationalize novel threat hunting playbooks focused on behavioral anomalies, abnormal command and control (C2), lateral movement, and traffic pattern deviations across JFN transport nodes.
  • Proactive Hypothesis Hunting: Formulate threat hypotheses based on all-source intelligence and observed indicators, interrogating the Elastic Search / Defend SIEM and raw network telemetry to uncover persistent, evasive adversary tradecraft.
  • Routine Threat Containment: Leverage Atlassian JIRA to author, refine, and maintain standardized processes and playbooks for executing routine threat containment actions and defensive countermeasure coordination.
  • MITRE ATT&CK Mapping: Map adversary tactics, techniques, and procedures (TTPs) targeting tactical fires and command-and-control networks to the MITRE ATT&CK® framework to identify visibility gaps and improve defensive posturing.
  • SIEM Detection Tuning: Recommend and refine custom detection queries (Elastic KQL/EQL) and alert correlations within Elastic Defend to optimize detection accuracy and reduce false positives for the 24/7 watch cell.
2. TS/SCI Incident Handling & Incident Response
  • Incident Response Architecture: Drive the technical threat intelligence and containment sections of the JFN Incident Response Plan in alignment with enterprise standards.
  • DIA-Aligned TS/SCI Incident Reporting: Strictly enforce Defense Intelligence Agency (DIA) requirements for TS/SCI incident handling, ensuring all spills, unauthorized access attempts, system compromises, and operational anomalies are reported through authorized channels within mandated reporting windows.
  • CSSP Alignment & Briefings: Support the delivery and maturity of four of the seven DoD Cybersecurity Service Provider (CSSP) core functions during Phase I standup, providing actionable threat summaries, warnings, and intelligence briefings to JFN leadership, DISA, and mission stakeholders.
Clearance & Citizenship
  • Citizenship: Must be a U.S. Citizen.
  • Security Clearance: Must possess an active Top Secret clearance with current SCI eligibility (adjudicated Tier 5 / SSBI) prior to start date, with the ability to maintain clearance while working in a secure SCIF environment.
Education & Experience Requirements
  • Level II (Intermediate): Bachelor’s degree in Cybersecurity, Intelligence Studies, Computer Science, Information Technology, or related discipline and 2+ years of direct experience in cyber threat intelligence, all-source cyber analysis, threat hunting, or SOC tier-2/tier-3 operations; OR an Associate degree and 4+ years; OR 6+ years of relevant professional/military cyber intelligence experience in lieu of a degree.
  • Level III (Senior): Bachelor’s degree in a technical discipline and 4+ years of relevant experience; OR an Associate degree and 6+ years; OR 8+ years of relevant experience/military service in lieu of degree.
Required DoD 8140 / 8570 Baseline Certification
  • Must hold a valid certification or degree meeting DoD 8140.03 / DCWF Work Role Code 531 Cyber Defense Incident Responder at the Intermediate Proficiency Level prior to hire.
  • Accepted Certifications include: CySA+, GIAC GCTI, EC-C CEH or CND, Security+ CE, GIAC GSEC, or higher (e.g., CASP+ CE, CISSP, GCIA, GCIH).
Technical Core Competencies
  • Strong experience in threat hunting, cyber threat intelligence, or advanced incident analysis within a DoD, military, or government SOC/DCO environment.
  • Proven ability to analyze and correlate network protocol telemetry, Netflow, proxy logs, and raw packet captures to reconstruct complex intrusion paths.
  • Hands‑on proficiency querying SIEM platforms—specifically Elasticsearch, Logstash, Kibana (ELK) / Elastic Defend—using KQL or Lucene query syntax.
  • Deep knowledge of adversary TTPs, threat actor attribution, and operational mapping using the MITRE ATT&CK framework.
  • Direct experience writing incident documentation, standard operating procedures, and containment playbooks in JIRA.
  • Ability to work standard operational shifts with readiness for on‑call surge or emergency incident escalation.
Preferred Qualifications
  • Prior experience supporting C4ISR systems or tactical operational enclaves (e.g., PMN).
  • Operational experience analyzing telemetry from Corelight (Zeek), Darktrace MDR, or Palo Alto Advanced Threat Prevention (ATP).
  • Experience utilizing AI prompting tools (Gemini, Grok, ChatGPT) to automate threat hunting data collection and indicator extraction.
  • Career Growth & Certification Support: Access Leidos cyber training pipelines, tuition assistance, and corporate sponsorships for premier technical credentials (SANS/GIAC, cloud security).
  • Long‑Term Program Backing: Solidified role on a high‑priority joint program supporting strategic defense requirements across DISA.
Who We Are…

Newberry Group is a performance‑driven government services and solutions firm that provides security compliance, program governance, consulting, and customized solutions for public sector clients nationwide.

The strength of our company is a direct reflection of our highly skilled and talented workforce.

Benefits and Perks

In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre‑Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short‑term disability coverage, tuition and training reimbursement, employee assistance program, and more.
The Newberry Group, Inc. is an Equal Opportunity Employer – EEO/AA/Disability/Veterans.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Real Time Analyst
Cyber Real Time Analyst

The Newberry Group • Waipahu (HI)

On-site
USD 110,000 - 150,000
Sign-on bonus
Relocation assistance
Cyber Countermeasure Specialist
Cyber Countermeasure Specialist

The Newberry Group • Waipahu (HI)

On-site
USD 140,000 - 170,000
Sign-on bonus
Relocation assistance
Cybersecurity Analyst
Cybersecurity Analyst

thenewberrygroup • O'Fallon (IL)

On-site
USD 95,000 - 125,000
Medical coverage
Paid time off
Retirement plan
Junior Security Control Assessor
Junior Security Control Assessor

thenewberrygroup • Fort Meade (MD)

Hybrid
USD 50,000 - 60,000
Medical, dental, vision coverage
Paid time off
Paid holidays
+6
Cyber Threat Hunter — TS/SCI, Onsite in Hawaii
Cyber Threat Hunter — TS/SCI, Onsite in Hawaii

The Newberry Group • Waipahu (HI)

On-site
USD 120,000 - 160,000
Medical coverage
Relocation reimbursement
Tuition and training reimbursement
+1
Advanced Cyber Security Analytics Engineer
Advanced Cyber Security Analytics Engineer

D2 Technical Services • St. Louis (MO)

On-site
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Advanced Cyber Security Analytics Engineer
Advanced Cyber Security Analytics Engineer

D2 Consulting • St. Louis (MO)

On-site
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Cyber Intelligence Fusion Analyst
Cyber Intelligence Fusion Analyst

Leidos • Alexandria (VA)

On-site
USD 108,000 - 195,000
Network Based Systems Analyst II
Network Based Systems Analyst II

DigiFlight, Inc. • Columbia (MD), Northern (KY)

On-site
USD 110,000 - 150,000
Health, Dental, Vision
Paid Time Off
11 paid holidays
+6
Incident Manager (Midlevel)
Incident Manager (Midlevel)

Node • United States

On-site
USD 120,000 - 180,000
Medical
Dental
Vision
+6