Cyber Countermeasure Specialist

The Newberry Group
  • Ford Island, HI
  • Full-time
8 days ago

Job Description

Job Summary - $10,000 sign-on bonus included (subject to a 12-month commitment)

Newberry Group is seeking an experienced, technically agile Cyber Countermeasure Specialist to support our customer’s defensive cyber operations team supporting the Joint Fires Network (JFN). Stationed inside secure SCIF environments at DISA Pacific (Ford Island, HI), this position plays a critical role in bridging detection analytics and active threat containment for the JFN Impact Level 7 (IL-7) environment and associated multi-domain operational enclaves.

In this role, you will be responsible for the engineering, operational validation, deployment, and lifecycle maintenance of defensive countermeasures, detection signatures, sensor tuning, and containment workflows. Operating across up to 30 active operational nodes (including SD-WAN transport fabrics and out-of-band management links), you will tune advanced network sensor grids (such as Corelight and Elastic Defend), author actionable threat containment playbooks within Atlassian JIRA, enforce strict Defense Intelligence Agency (DIA) TS/SCI spill and breach containment standards, and collaborate closely with Tier II NOC engineers (SolarWinds/Jira) and NIWC pipeline architects to neutralize adversarial activity across the JFN operational battlespace.

Location
This is a full-time onsite role in Ford Island, HI. Telework is not permitted.
Relocation expenses may be eligible for up to $10,000 reimbursement in addition to the sign-on bonus.

Salary 
$115,000 to $150,000 annually - depending on level of experience

Responsibilities and Duties
1. Countermeasure Engineering, Sensor Tuning & Active
Defense
  • Sensor Tuning & Management: Configure, tune, and operationalize advanced boundary and enroute security sensors—including Corelight (Zeek-basedtelemetry) and Elastic Defend—to maximize high-fidelity detection while suppressing noise across JFN nodes.
  • Custom Signature & Rule Development: Design, test, validate, and maintain custom intrusion detection rules, Zeek scripts, YARA rules, and Elastic SIEM detection logic targeting emerging exploit patterns, living-off-the-land techniques, and lateral movement attempts.
  • Palo Alto ATP & Pipeline Ingestion: Collaborate with NIWC data engineers to validate log ingestion pipelines (Logstash) from Palo Alto Advanced Threat Prevention (ATP), Prometheus, and endpoint monitors, ensuring sensor event logic triggers actionable containment mechanisms.
  • Countermeasure Tracking & De-confliction: Track all deployed signatures and mitigation actions within JIRA; execute deliberate de-confliction procedures with DISA and operational network authorities to prevent unintended disruption to operational fires data streams.
  •  Rapid Rollback & Operational Stability: Establish, document, and test rapid rollback mechanisms to immediately revert sensor configurations and containment rules if mission communications are impacted during crisis execution.
2. Playbook Engineering & Incident Response Automation
  • Containment Playbook Development: Leverage Atlassian JIRA to design, automate, document, and maintain end-to-end standard operating procedures (SOPs) and execution runbooks for routine threat containment, node isolation and sensor re-baselining.
  • Incident Response Plan Operationalization: Support the drafting, maintenance, and technical execution of the JFN Incident Response Plan, ensuring rapid transition from alert triage to active containment.
  • CSSP Defense Service Integration: Drive the technical countermeasure delivery for four of the seven DoD Cybersecurity Service Provider (CSSP) core functions during Phase I standup, expanding to full CSSP operational countermeasure capability during Phase II sustainment.
  • Traffic Pattern & Behavioral Countermeasures: Translate behavioral anomaly findings and traffic pattern analyses developed by threat hunters into actionable, rule-based containment triggers across SD-WAN interfaces and out-of-band management channels.
3. Classified Spill Containment & SCIF Operations
  • Spill & Breach Containment: Implement and enforce rigorous Defense Intelligence Agency (DIA) protocols for containment and technical quarantine of classified data spills, unauthorized cross-domain transfers, or credential compromise within TS/SCI and IL-6 domains.
  • Audit Readiness & Compliance: Verify that all active countermeasures, alerting mechanisms, and log capture configurations strictly adhere to formal TS/SCI Information Systems Security Program audit criteria and JFN Security Classification Guidance.
  • Cross-Functional Team Collaboration: Partner daily with JFN 24/7 Real-Time Analysts, Tier II NOC administrators managing SolarWinds and Jira, and DISA Field Command leadership to coordinate high-priority containment actions during active network events.
  • SCIF Operational Assurance: Conduct all defensive engineering within designated Sensitive Compartmented Information Facilities (SCIF), maintaining operational integrity across classified enclaves.
Clearance & Citizenship
  • Citizenship: Must be a U.S. Citizen
  • Security Clearance: Must possess an active Top Secret clearance with current SCI eligibility (adjudicated Tier 5 / SSBI) prior to start date, with the ability to maintain clearance while working in a secure SCIF environment.

Education & Experience Requirements
  • Level II (Intermediate): Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or related discipline with 2+ years of direct experience in intrusion detection/prevention engineering, custom signature creation, or network defense operations; OR an Associate degree with 4+ years; OR 6+ years of relevant experience/military cyber service in lieu of degree.
  • Level III (Senior): Bachelor’s degree in a technical discipline with 4+ years of relevant experience; OR an Associate degree with 6+ years; OR 8+ years of relevant experience/military cyber service in lieu of degree.
Required DoD 8140 / 8570 Baseline Certification
  • Must hold a valid certification or degree meeting DoD 8140.03 / DCWF Work Role Code 521: Cyber Defense Infrastructure Support Specialist at the Basic Proficiency Level prior to start.
  • Accepted Certifications include: CySA+, CCNA-Security, GICSP, GSEC, Security+ CE, CND, CEH, or higher (e.g., CASP+ CE, CISSP, GCIA, GCIH).
Technical Core Competencies
  • Proven experience authoring, testing, and deploying custom network intrusionsignatures and parsing logic (e.g., Snort/Suricata rules, Zeek scripts, YARA, orElastic KQL/EQL query rules)
  • Hands-on operational experience with enterprise sensor platforms such as Corelight, Elastic Defend / ELK Stack, or next-generation firewalls (e.g., Palo Alto Networks).
  • Demonstrated experience developing, documenting, and executing threat containment workflows and tracking procedures using Atlassian JIRA.
  • Solid understanding of core networking protocols (TCP/IP, BGP, IPsec, DNS, TLS), network perimeter architectures, and packet analysis tools (Wireshark, tcpdump).
  • Ability to support standard operational day shifts (8x5) with on-call flexibility for emergency after-hours containment surges or critical network defense events.
Preferred Qualifications
  • Direct experience deploying and managing countermeasures across Impact Level 6/7 (IL-6/7), SIPRNet, or Top Secret / SCI enclaves.
  • Familiarity with Software-Defined WAN (SD-WAN) technologies, Out-of-Band network management, and SolarWinds monitoring integrations.
  • Experience with automated containment scripting using Python, PowerShell, Bash, or REST APIs.
  • Understanding of Darktrace Managed Detection & Response (MDR) and Prometheus pipeline data flows.
  • Prior experience supporting C4ISR systems or joint tactical enclaves.

Who We Are…
Newberry Group is a performance-driven government services and solutions firm that provides security compliance, program governance, consulting, and customized solutions for public sector clients nationwide. 

The strength of our company is a direct reflection of our highly skilled and talented workforce.


Benefits and Perks
In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more.

The Newberry Group, Inc. is an Equal Opportunity Employer – EEO/AA/Disability/Veterans.
 

Powered by JazzHR

Numbers & Facts

LocationFord Island, HI
Job TypeFull-time
Websitehttp://www.newberry-gs.com

Skills

  • Application Programming Interface (API)unmatched
  • Architectural Analysisunmatched
  • Atlassian JIRAunmatched
  • BGPunmatched
  • Bash Scriptingunmatched
  • Computer Engineeringunmatched
  • Computer Network Defense (CND)unmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Consultingunmatched
  • Cross-Functionalunmatched
  • Customer Support/Serviceunmatched
  • DNS (Domain Name System)unmatched
  • Defense Information Systems Agency (DISA)unmatched
  • Defense Intelligence Agency (DIA)unmatched
  • Documentationunmatched
  • Firewallsunmatched
  • Governmentunmatched
  • IPsec (IP Security)unmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information Technology/Systems Auditunmatched
  • Internet Securityunmatched
  • Intrusion Detection Systemsunmatched
  • Intrusion Detection and Prevention (IDP)unmatched
  • Leadershipunmatched
  • Militaryunmatched
  • Network Administration/Managementunmatched
  • Network Architecture/Engineeringunmatched
  • Network Operations Centerunmatched
  • Network Protocolsunmatched
  • Network Securityunmatched
  • Network Traffic Analysisunmatched
  • On Callunmatched
  • Operational Supportunmatched
  • Pattern Analysisunmatched
  • Python Programming/Scripting Languageunmatched
  • REST (Representational State Transfer)unmatched
  • SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
  • Scripting (Scripting Languages)unmatched
  • Security Complianceunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Sensitive Compartmented Information (SCI)unmatched
  • Sensitive Compartmented Information Facility (SCIF)unmatched
  • Snortunmatched
  • Standard Operating Procedures (SOP)unmatched
  • TCP/IP (Transmission Control Protocol/Internet Protocol)unmatched
  • Technical Deliveryunmatched
  • Test Designunmatched
  • Test Plan/Scheduleunmatched
  • Testingunmatched
  • Top Secret Clearanceunmatched
  • United States Citizenunmatched
  • United States Department of Defense (DoD)unmatched
  • Web Infrastructureunmatched
  • Wide Area Network (WAN)unmatched
  • Windows PowerShellunmatched
  • Wireshark (Ethereal)unmatched
  • Writing Skillsunmatched
  • tcpdumpunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder