The Newberry Group

Cyber Countermeasure Specialist

Ford Island, Hawaii · Posted today

Opens thenewberrygroup.applytojob.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Full-time
Work mode
Not specified
Source
Jazzhr (employer's hiring system)

Skills mentioned

Jira, Incident Response, Prometheus, Cybersecurity, Python, Bash, REST, TCP/IP

About the role

Job Summary

Newberry Group is seeking an experienced, technically agile Cyber Countermeasure Specialist to support our customer’s defensive cyber operations team supporting the Joint Fires Network (JFN). Stationed inside secure SCIF environments at DISA Pacific (Ford Island, HI), this position plays a critical role in bridging detection analytics and active threat containment for the JFN Impact Level 7 (IL-7) environment and associated multi-domain operational enclaves.

In this role, you will be responsible for the engineering, operational validation, deployment, and lifecycle maintenance of defensive countermeasures, detection signatures, sensor tuning, and containment workflows. Operating across up to 30 active operational nodes (including SD-WAN transport fabrics and out-of-band management links), you will tune advanced network sensor grids (such as Corelight and Elastic Defend), author actionable threat containment playbooks within Atlassian JIRA, enforce strict Defense Intelligence Agency (DIA) TS/SCI spill and breach containment standards, and collaborate closely with Tier II NOC engineers (SolarWinds/Jira) and NIWC pipeline architects to neutralize adversarial activity across the JFN operational battlespace.

Location
This is a full-time onsite role in Ford Island, HI. Telework is not permitted.
Relocation expenses may be eligible for reimbursement.

Responsibilities and Duties
1. Countermeasure Engineering, Sensor Tuning & Active
Defense
  • Sensor Tuning & Management: Configure, tune, and operationalize advanced boundary and enroute security sensors—including Corelight (Zeek-basedtelemetry) and Elastic Defend—to maximize high-fidelity detection while suppressing noise across JFN nodes.
  • Custom Signature & Rule Development: Design, test, validate, and maintain custom intrusion detection rules, Zeek scripts, YARA rules, and Elastic SIEM detection logic targeting emerging exploit patterns, living-off-the-land techniques, and lateral movement attempts.
  • Palo Alto ATP & Pipeline Ingestion: Collaborate with NIWC data engineers to validate log ingestion pipelines (Logstash) from Palo Alto Advanced Threat Prevention (ATP), Prometheus, and endpoint monitors, ensuring sensor event logic triggers actionable containment mechanisms.
  • Countermeasure Tracking & De-confliction: Track all deployed signatures and mitigation actions within JIRA; execute deliberate de-confliction procedures with DISA and operational network authorities to prevent unintended disruption to operational fires data streams.
  •  Rapid Rollback & Operational Stability: Establish, document, and test rapid rollback mechanisms to immediately revert sensor configurations and containment rules if mission communications are impacted during crisis execution.
2. Playbook Engineering & Incident Response Automation
  • Containment Playbook Development: Leverage Atlassian JIRA to design, automate, document, and maintain end-to-end standard operating procedures (SOPs) and execution runbooks for routine threat containment, node isolation and sensor re-baselining.
  • Incident Response Plan Operationalization: Support the drafting, maintenance, and technical execution of the JFN Incident Response Plan, ensuring rapid transition from alert triage to active containment.
  • CSSP Defense Service Integration: Drive the technical countermeasure delivery for four of the seven DoD Cybersecurity Service Provider (CSSP) core functions during Phase I standup, expanding to full CSSP operational countermeasure capability during Phase II sustainment.
  • Traffic Pattern & Behavioral Countermeasures: Translate behavioral anomaly findings and traffic pattern analyses developed by threat hunters into actionable, rule-based containment triggers across SD-WAN interfaces and out-of-band management channels.
3. Classified Spill Containment & SCIF Operations
  • Spill & Breach Containment: Implement and enforce rigorous Defense Intelligence Agency (DIA) protocols for containment and technical quarantine of classified data spills, unauthorized cross-domain transfers, or credential compromise within TS/SCI and IL-6 domains.
  • Audit Readiness & Compliance: Verify that all active countermeasures, alerting mechanisms, and log capture configurations strictly adhere to formal TS/SCI Information Systems Security Program audit criteria and JFN Security Classification Guidance.
  • Cross-Functional Team Collaboration: Partner daily with JFN 24/7 Real-Time Analysts, Tier II NOC administrators managing SolarWinds and Jira, and DISA Field Command leadership to coordinate high-priority containment actions during active network events.
  • SCIF Operational Assurance: Conduct all defensive engineering within designated Sensitive Compartmented Information Facilities (SCIF), maintaining operational integrity across classified enclaves.
Clearance & Citizenship
  • Citizenship: Must be a U.S. Citizen
  • Security Clearance: Must possess an active Top Secret clearance with current SCI eligibility (adjudicated Tier 5 / SSBI) prior to start date, with the ability to maintain clearance while working in a secure SCIF environment.

Education & Experience Requirements
  • Level II (Intermediate): Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, Information Technology, or related discipline with 2+ years of direct experience in intrusion detection/prevention engineering, custom signature creation, or network defense operations; OR an Associate degree with 4+ years; OR 6+ years of relevant experience/military cyber service in lieu of degree.
  • Level III (Senior): Bachelor’s degree in a technical discipline with 4+ years of relevant experience; OR an Associate degree with 6+ years; OR 8+ years of relevant experience/military cyber service in lieu of degree.
Required DoD 8140 / 8570 Baseline Certification
  • Must hold a valid certification or degree meeting DoD 8140.03 / DCWF Work Role Code 521: Cyber Defense Infrastructure Support Specialist at the Basic Proficiency Level prior to start.
  • Accepted Certifications include: CySA+, CCNA-Security, GICSP, GSEC, Security+ CE, CND, CEH, or higher (e.g., CASP+ CE, CISSP, GCIA, GCIH).
Technical Core Competencies
  • Proven experience authoring, testing, and deploying custom network intrusionsignatures and parsing logic (e.g., Snort/Suricata rules, Zeek scripts, YARA, orElastic KQL/EQL query rules)
  • Hands-on operational experience with enterprise sensor platforms such as Corelight, Elastic Defend / ELK Stack, or next-generation firewalls (e.g., Palo Alto Networks).
  • Demonstrated experience developing, documenting, and executing threat containment workflows and tracking procedures using Atlassian JIRA.
  • Solid understanding of core networking protocols (TCP/IP, BGP, IPsec, DNS, TLS), network perimeter architectures, and packet analysis tools (Wireshark, tcpdump).
  • Ability to support standard operational day shifts (8x5) with on-call flexibility for emergency after-hours containment surges or critical network defense events.
Preferred Qualifications
  • Direct experience deploying and managing countermeasures across Impact Level 6/7 (IL-6/7), SIPRNet, or Top Secret / SCI enclaves.
  • Familiarity with Software-Defined WAN (SD-WAN) technologies, Out-of-Band network management, and SolarWinds monitoring integrations.
  • Experience with automated containment scripting using Python, PowerShell, Bash, or REST APIs.
  • Understanding of Darktrace Managed Detection & Response (MDR) and Prometheus pipeline data flows.
  • Prior experience supporting C4ISR systems or joint tactical enclaves.

Who We Are…
Newberry Group is a performance-driven government services and solutions firm that provides security compliance, program governance, consulting, and customized solutions for public sector clients nationwide. 


The strength of our company is a direct reflection of our highly skilled and talented workforce.


Benefits and Perks
In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more.

The Newberry Group, Inc. is an Equal Opportunity Employer – EEO/AA/Disability/Veterans.

 

Job ID jz-thenewberrygroup-20260930203443_o36jnmsxnqhz8vwa · Original posting ↗