Cyber Countermeasure Specialist

Newberry GroupHawaii, United StatesOn-siteFull-timeStaff, 8–12 yearsListed 9 hours ago

Apply now

About this role

Job Summary

Newberry Group is seeking an experienced, technically agile Cyber Countermeasure Specialist to support our customer’s defensive cyber operations team supporting the Joint Fires Network (JFN). Stationed inside secure SCIF environments at DISA Pacific (Ford Island, HI), this position plays a critical role in bridging detection analytics and active threat containment for the JFN Impact Level 7 (IL-7) environment and associated multi-domain operational enclaves.

In this role, you will be responsible for the engineering, operational validation, deployment, and lifecycle maintenance of defensive countermeasures, detection signatures, sensor tuning, and containment workflows. Operating across up to 30 active operational nodes (including SD-WAN transport fabrics and out-of-band management links), you will tune advanced network sensor grids (such as Corelight and Elastic Defend), author actionable threat containment playbooks within Atlassian JIRA, enforce strict Defense Intelligence Agency (DIA) TS/SCI spill and breach containment standards, and collaborate closely with Tier II NOC engineers (SolarWinds/Jira) and NIWC pipeline architects to neutralize adversarial activity across the JFN operational battlespace.

Location
This is a full-time onsite role in Ford Island, HI. Telework is not permitted.
Relocation expenses may be eligible for reimbursement.

Responsibilities and Duties
1. Countermeasure Engineering, Sensor Tuning & Active
Defense
- Sensor Tuning & Management: Configure, tune, and operationalize advanced   boundary and enroute security sensors—including Corelight (Zeek-based telemetry) and Elastic Defend —to maximize high-fidelity detection while   suppressing noise across JFN nodes.
- Custom Signature & Rule Development: Design, test, validate, and maintain   custom intrusion detection rules, Zeek scripts, YARA rules, and Elastic SIEM   detection logic targeting emerging exploit patterns, living-off-the-land   techniques, and lateral movement attempts.
- Palo Alto ATP & Pipeline Ingestion: Collaborate with NIWC data engineers to   validate log ingestion pipelines (Logstash) from Palo Alto Advanced Threat   Prevention (ATP), Prometheus, and endpoint monitors, ensuring sensor event   logic triggers actionable containment mechanisms.
- Countermeasure Tracking & De-confliction: Track all deployed signatures   and mitigation actions within JIRA; execute deliberate de-confliction procedures   with DISA and operational network authorities to prevent unintended   disruption to operational fires data streams.
-   Rapid Rollback & Operational Stability: Establish, document, and test rapid   rollback mechanisms to immediately revert sensor configurations and   containment rules if mission communications are impacted during crisis  execution.
2. Playbook Engineering & Incident Response Automation
- Containment Playbook Development: Leverage Atlassian JIRA to design,   automate, document, and maintain end-to-end standard operating procedures   (SOPs) and execution runbooks for routine threat containment, node isolation   and sensor re-baselining.
- Incident Response Plan Operationalization: Support the drafting,   maintenance, and technical execution of the JFN Incident Response Plan,   ensuring rapid transition from alert triage to active containment.
- CSSP Defense Service Integration: Drive the technical countermeasure   delivery for four of the seven DoD Cybersecurity Service Provider (CSSP) core   functions during Phase I standup, expanding to full CSSP operational   countermeasure capability during Phase II sustainment.
- Traffic Pattern & Behavioral Countermeasures: Translate behavioral   anomaly findings and traffic pattern analyses developed by threat hunters into   actionable, rule-based containment triggers across SD-WAN interfaces and out-of- band management channels.
3. Classified Spill Containment & SCIF Operations
- Spill & Breach Containment: Implement and enforce rigorous Defense   Intelligence Agency (DIA) protocols for containment and technical quarantine of   classified data spills, unauthorized cross-domain transfers, or credential   compromise within TS/SCI and IL-6 domains.
- Audit Readiness & Compliance: Verify that all active countermeasures, alerting   mechanisms, and log capture configurations strictly adhere to formal TS/SCI   Information Systems Security Program audit criteria and JFN Security   Classification Guidance.
- Cross-Functional Team Collaboration: Partner daily with JFN 24/7 Real-Time   Analysts, Tier II NOC administrators managing SolarWinds and Jira, and DISA   Field Command leadership to coordinate high-priority containment actions   during active network events.
- SCIF Operational Assurance: Conduct all defensive engineering within   designated Sensitive Compartmented Information Facilities (SCIF), maintaining   operational integrity across classified enclaves.
Clearance & Citizenship
- Citizenship: Must be a U.S. Citizen
- Security Clearance: Must possess an active Top Secret clearance with current SCI eligibility (adjudicated Tier 5 / SSBI) prior to start date, with the ability to maintain clearance while working in a secure SCIF environment.

Education & Experience Requirements
- Level II (Intermediate): Bachelor’s degree in Cybersecurity, Computer Science,   Computer Engineering, Information Technology, or related discipline with 2+   years of direct experience in intrusion detection/prevention engineering,   custom signature creation, or network defense operations; OR an Associate   degree with 4+ years ; OR 6+ years of relevant experience/military cyber   service in lieu of degree.
- Level III (Senior): Bachelor’s degree in a technical discipline with 4+ years of   relevant experience; OR an Associate degree with 6+ years ; OR 8+ years of   relevant experience/military cyber service in lieu of degree.
Required DoD 8140 / 8570 Baseline Certification
- Must hold a valid certification or degree meeting DoD 8140.03 / DCWF Work   Role Code 521: Cyber Defense Infrastructure Support Specialist at the Basic   Proficiency Level prior to start.
- Accepted Certifications include: CySA+, CCNA-Security, GICSP, GSEC,   Security+ CE, CND, CEH, or higher (e.g., CASP+ CE, CISSP, GCIA, GCIH) .
Technical Core Competencies
- Proven experience authoring, testing, and deploying custom network intrusion signatures and parsing logic (e.g., Snort/Suricata rules, Zeek scripts, YARA, or Elastic KQL/EQL query rules)
- Hands-on operational experience with enterprise sensor platforms such as   Corelight , Elastic Defend / ELK Stack , or next-generation firewalls (e.g., Palo   Alto Networks).
- Demonstrated experience developing, documenting, and executing threat   containment workflows and tracking procedures using Atlassian JIRA .
- Solid understanding of core networking protocols (TCP/IP, BGP, IPsec, DNS,   TLS), network perimeter architectures, and packet analysis tools (Wireshark,   tcpdump).
- Ability to support standard operational day shifts (8x5) with on-call flexibility   for emergency after-hours containment surges or critical network defense   events.
Preferred Qualifications
- Direct experience deploying and managing countermeasures across Impact   Level 6/7 (IL-6/7) , SIPRNet, or Top Secret / SCI enclaves.
- Familiarity with Software-Defined WAN (SD-WAN) technologies, Out-of-Band   network management, and SolarWinds monitoring integrations.
- Experience with automated containment scripting using Python, PowerShell,   Bash, or REST APIs.
- Understanding of Darktrace Managed Detection & Response (MDR) and   Prometheus pipeline data flows.
- Prior experience supporting C4ISR systems or joint tactical enclaves.

Who We Are…
Newberry Group is a performance-driven government services and solutions firm that provides security compliance, program governance, consulting, and customized solutions for public sector clients nationwide.

The strength of our company is a direct reflection of our highly skilled and talented workforce.

Benefits and Perks
In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more.

The Newberry Group, Inc. is an Equal Opportunity Employer – EEO/AA/Disability/Veterans.