Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Threat Analyst

Newberry Group

Cyber Threat Analyst

Newberry Group is seeking an analytical, mission-driven Cyber Threat Analyst to join our customer's defensive cyber operations team supporting the Joint Fires Network (JFN) Security Operations Center (SOC). Operating out of secure Sensitive Compartmented Information Facilities (SCIFs) at DISA Pacific (Ford Island, HI), this team provides specialized threat intelligence synthesis, behavioral anomaly detection, and advanced threat hunting to safeguard the JFN Impact Level 7 (IL-7) and multi-level classified enclaves supporting the Olympus Fires mission. In this role, you will analyze network telemetry, advanced sensor feeds (such as Corelight and Darktrace), and syslog audits across up to 30 active operational nodes (including SD-WAN transport fabrics tied to the DISN and GMS). You will develop novel behavioral threat hunting playbooks, formulate containment and response strategies in JIRA, support the JFN Incident Response Plan, ensure DIA-aligned TS/SCI incident escalation compliance, and translate adversary tradecraft into detection logic for the Elastic Search / Elastic Defend SIEM platform.

Location This is a full-time onsite role in Ford Island, HI. Telework is not permitted. Relocation expenses may be eligible for reimbursement.

Responsibilities and Duties
  • Novel Playbook Authoring: Design, test, and operationalize novel threat hunting playbooks focused on behavioral anomalies, abnormal command and control (C2), lateral movement, and traffic pattern deviations across JFN transport nodes.
  • Proactive Hypothesis Hunting: Formulate threat hypotheses based on all-source intelligence and observed indicators, interrogating the Elastic Search / Defend SIEM and raw network telemetry to uncover persistent, evasive adversary tradecraft.
  • Routine Threat Containment: Leverage Atlassian JIRA to author, refine, and maintain standardized processes and playbooks for executing routine threat containment actions and defensive countermeasure coordination.
  • MITRE ATT&CK Mapping: Map adversary tactics, techniques, and procedures (TTPs) targeting tactical fires and command-and-control networks to the MITRE ATT&CK® framework to identify visibility gaps and improve defensive posturing.
  • SIEM Detection Tuning: Recommend and refine custom detection queries (Elastic KQL/EQL) and alert correlations within Elastic Defend to optimize detection accuracy and reduce false positives for the 24/7 watch cell.

2. TS/SCI Incident Handling & Incident Response

  • Incident Response Architecture: Drive the technical threat intelligence and containment sections of the JFN Incident Response Plan in alignment with enterprise standards.
  • DIA-Aligned TS/SCI Incident Reporting: Strictly enforce Defense Intelligence Agency (DIA) requirements for TS/SCI incident handling, ensuring all spills, unauthorized access attempts, system compromises, and operational anomalies are reported through authorized channels within mandated reporting windows.
  • CSSP Alignment & Briefings: Support the delivery and maturity of four of the seven DoD Cybersecurity Service Provider (CSSP) core functions during Phase I standup, providing actionable threat summaries, warnings, and intelligence briefings to JFN leadership, DISA, and mission stakeholders.

Clearance & Citizenship

  • Citizenship: Must be a U.S. Citizen.
  • Security Clearance: Must possess an active Top Secret clearance with current SCI eligibility (adjudicated Tier 5 / SSBI) prior to start date, with the ability to maintain clearance while working in a secure SCIF environment.

Education & Experience Requirements

  • Level II (Intermediate): Bachelor's degree in Cybersecurity, Intelligence Studies, Computer Science, Information Technology, or related discipline and 2+ years of direct experience in cyber threat intelligence, all-source cyber analysis, threat hunting, or SOC tier-2/tier-3 operations; OR an Associate degree and 4+ years ; OR 6+ years of relevant professional/military cyber intelligence experience in lieu of a degree.
  • Level III (Senior): Bachelor's degree in a technical discipline and 4+ years of relevant experience; OR an Associate degree and 6+ years ; OR 8+ years of relevant experience/military service in lieu of degree.

Required DoD 8140 / 8570 Baseline Certification

  • Must hold a valid certification or degree meeting DoD 8140.03 / DCWF Work Role Code 531 Cyber Defense Incident Responder at the Intermediate Proficiency Level prior to hire.
  • Accepted Certifications include: CySA+, GIAC GCTI, EC-C CEH or CND, Security+ CE, GIAC GSEC, or higher (e.g., CASP+ CE, CISSP, GCIA, GCIH).

Technical Core Competencies

  • Strong experience in threat hunting, cyber threat intelligence, or advanced incident analysis within a DoD, military, or government SOC/DCO environment.
  • Proven ability to analyze and correlate network protocol telemetry, Netflow, proxy logs, and raw packet captures to reconstruct complex intrusion paths.
  • Hands-on proficiency querying SIEM platforms—specifically Elasticsearch, Logstash, Kibana (ELK) / Elastic Defend —using KQL or Lucene query syntax.
  • Deep knowledge of adversary TTPs, threat actor attribution, and operational mapping using the MITRE ATT&CK framework.
  • Direct experience writing incident documentation, standard operating procedures, and containment playbooks in JIRA.
  • Ability to work standard operational shifts with readiness for on-call surge or emergency incident escalation.

Preferred Qualifications

  • Prior experience supporting C4ISR systems or tactical operational enclaves (e.g., PMN).
  • Operational experience analyzing telemetry from Corelight (Zeek), Darktrace MDR, or Palo Alto Advanced Threat Prevention (ATP).
  • Experience utilizing AI prompting tools (Gemini, Grok, ChatGPT) to automate threat hunting data collection and indicator extraction.
  • Career Growth & Certification Support: Access Leidos cyber training pipelines, tuition assistance, and corporate sponsorships for premier technical credentials (SANS/GIAC, cloud security).
  • Long-Term Program Backing: Solidified role on a high-priority joint program supporting strategic defense requirements across DISA.

Who We Are… Newberry Group is a performance-driven government services and solutions firm that provides security compliance, program governance, consulting, and customized solutions for public sector clients nationwide. The strength of our company is a direct reflection of our highly skilled and talented workforce. Benefits and Perks In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more. The Newberry Group, Inc. is an Equal Opportunity Employer – EEO/AA/Disability/Veterans.

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Cyber Threat Analyst in Pearl, MS vacancy
  • $214.51k

     ...tasks to junior teammates and guide them. In tandem with security leadership, senior cloud architects will consistently assess the threat landscape and adapt quickly to protect the business from risk. The senior architect will mentor junior employees to help strengthen... 
    Suggested
    Work experience placement
    H1b
    Remote work

    CDM Smith

    Jackson, MS
    4 days ago
  • $112.5k - $202.5k

     ...everyone. Our focus is simple: Cloud and Edge: Running apps closer to users for instant performance. Security : Neutralizing threats before they ever reach your data. Content Delivery : Scaling the world's biggest moments without a glitch. AI : Enabling... 
    Suggested
    Work experience placement
    Work at office

    Akamai

    Jackson, MS
    5 days ago
  •  ...and authorization policy sets, and endpoint profiling.Integrate Cyber Vision intelligence into profiling, segmentation, and access control...  ...Cybersecurity Associate Foundational security, NGFW basics, threats, App-ID, and policy.PCNSA – Palo Alto Networks Certified Network... 
    Suggested
    For contractors
    Work at office

    Novalink Solutions

    Jackson, MS
    5 days ago
  • $150k - $225k

    Job Description Job Description Overview We are seeking a Senior Corporate Enterprise Network Engineer to join our team supporting the Defense Logistics Agency. This position is in support of Defense Logistics Agency (DLA). DLA is an agency of the Department ...
    Suggested
    Full time
    Contract work
    Temporary work
    Local area
    Remote work
    Monday to Friday
    Night shift
    Weekend work
    Day shift
    Afternoon shift

    TekSynap

    Pearl, MS
    a month ago
  • Required Qualifications ~ Expert knowledge of Oracle PL/SQL (procedures, functions, triggers, packages, views). ~ Strong SQL expertise including query optimization and performance tuning. ~ Experience with data migration, ETL workflows, and schema transformation...
    Suggested

    3B Staffing LLC

    Jackson, MS
    3 days ago
  •  ...Nexus, Catalyst, SDA, Cisco ISE, Palo Alto firewalls, ThousandEyes, Cyber Vision, DNA Spaces, network automation, and enterprise routing/...  ...·         Foundational understanding of network security threats and policies Key Responsibilities ·         Design, implement... 
    Work at office
    Local area
    Monday to Friday

    S R INTERNATIONAL INC

    Jackson, MS
    4 days ago
  • $250.6k - $362.6k

    The application window is expected to close on: 11/29/2026This is a fully remote opportunity open to candidates located anywhere in the United States.Meet the Team You will join Cisco’s Security and Policy Platform Group, a foundational organization responsible for transforming...
    Full time
    Temporary work
    Local area
    Remote work
    Flexible hours

    CISCO Systems

    Jackson, MS
    1 day ago
  • ERP Implementation Consultant Location: Jackson, Mississippi, USA (Hybrid) Job Type: Contract / Professional Services Industry: Government Consulting • Information Technology • Enterprise Resource Planning (ERP) About the Role Guru Consulting ...
    Contract work

    GuruSchools

    Jackson, MS
    23 days ago
  • $131.3k - $237.35k

     ...SRE) leadership to safeguard our network infrastructure against threats and ensure the highest levels of operational integrity. As a senior...  ...topics, including managing STIG vulnerabilities for Cyber Operational Readiness Assessment (CORA) inspections and leading... 
    Contract work
    Work experience placement
    Local area
    Immediate start
    Night shift

    Leidos

    Pearl, MS
    1 day ago
  • Hi, Greeting from Ageatia Global Solutions. We have a new job opening with my direct client. Please go through the Job Description, and if you are comfortable and available in the job market, then please reply to me. Position: Enterprise Solutions Architect...

    Ageatia Global Solutions

    Jackson, MS
    1 day ago
  •  ...Defined Access (SDA), Cisco Identity Services Engine (ISE), Cisco Catalyst platforms, and observability tools including ThousandEyes, Cyber Vision, and DNA Spaces. It also includes administration of Palo Alto firewalls supporting statewide systems.Major... 

    InstantServe

    Jackson, MS
    1 day ago
  • $144.9k - $265.8k

    Location: Anywhere in Country At EY, we’re all in to shape your future with confidence.  We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go.  Join EY and help to build a better working world...
    Summer holiday
    Flexible hours

    EY

    Jackson, MS
    3 days ago
  • $104.5k - $234.6k

     ...Experience working with internal customers and translating requests into prioritized work or features Expertise in applying threat modeling or other risk identification techniques to develop security solutions FedRAMP, PCI DSS, or similar compliance and auditing... 
    Temporary work
    Flexible hours
    Shift work

    Oracle

    Jackson, MS
    1 day ago
  • $85k - $100k

     ...85-$100k Must have an active DoD Top Secret security clearance PREFERRED QUALIFICATIONS: Tech control facility or cyber transport experience Circuit actions and vendor experience, IP/Transport architecture experience Solarwinds and JIRA experience... 
    Local area
    Immediate start
    Shift work
    Night shift

    Leidos

    Pearl, MS
    1 day ago
  • Senior Network EngineerJoint Base Pearl Harbor-Hickam, HICSCI is on the hunt for a dynamic Senior Network Engineer to join our client's Engineering Support Services program in Pearl Harbor, HI. This hybrid role offers the perfect blend of flexibility and adventure, with...
    Work at office
    Local area
    1 day per week

    Navstar

    Pearl, MS
    5 days ago
  • Healthy Careers Start Here The Network Engineer II is responsible for planning and leading the installation, configuration, documentation and maintenance of network infrastructure devices and software including network routers, switches, load balancers, and firewalls...
    Work at office

    Blue Cross and Blue Shield of Mississippi

    Flowood, MS
    4 days ago
  • $73.45k - $132.78k

     ...topologies. Must have an active DoD Top Secret security clearance PREFERRED QUALIFICATIONS: Tech control facility or cyber transport experience Circuit actions and vendor experience IP/Transport architecture experience Solarwinds and JIRA... 
    Local area
    Immediate start
    Shift work
    Night shift

    Leidos

    Pearl, MS
    1 day ago
  • $92.3k - $166.85k

    Description Network Engineer Location: Pearl Harbor, Hawaii Security Clearance: Active TS/SCI Required Leidos is seeking a Network Engineer to support forward deployed mission operations at the Office of Naval Intelligence (ONI) in Pearl Harbor, Hawaii...
    Work at office
    Local area
    Immediate start
    Remote work

    Leidos

    Pearl, MS
    5 days ago
  • $70 - $90 per hour

     ...to work in a 24×7 shift environment.Working knowledge of both IP and Transport network topologies.Preferred:Tech control facility or cyber transport experience.Experience with circuit actions, vendor coordination, and IP/Transport architecture.SolarWinds and Jira... 
    Shift work
    Night shift

    Cornerstone Defense

    Pearl, MS
    2 days ago
  • .NET Developer (Atlanta, GA and W2 candidates only) Job Id : A 8167 Posted Date : 10/02/2026 Experience : - Job Type : - Location : Atlanta Engagement Type Contract Required Qualifications Candidates must possess a bachelor’s degree. Prefer the degree be in the following...
    Contract work

    Oorwin AI

    Jackson, MS
    13 hours ago
  • Ergon has an opening at our corporate in Flowood, MS, for a Business Applications Analyst. The Business Applications Analyst position in the EHSS Systems area uses enterprise systems analysis skills and takes initiative to create value for Ergon's business units. Leads... 
    Flexible hours

    ergon

    Flowood, MS
    2 days ago
  • $114.6k - $234.6k

    Job Description Designs, implements, and operates resilient L3/L4 network services across data centers and cloud environments with broader influence beyond the immediate team. Leads moderately complex projects, drives automation and observability at scale, and contributes...
    Temporary work
    Immediate start
    Flexible hours
    Shift work

    Oracle

    Jackson, MS
    5 days ago
  • $61.11 per hour

     ...endpoint profiling, and network access control. Integrate Cisco Cyber Vision intelligence into endpoint profiling, segmentation, and...  ...Administrator). Knowledge of Palo Alto NGFW fundamentals, threat prevention, App-ID, policy configuration, security profiles, NAT... 
    Full time
    Work at office
    Local area
    Remote work

    Certec, Inc.

    Clinton, MS
    4 days ago
  •  ...administration, and endpoint profiling. ·         Integrate Cisco Cyber Vision intelligence into endpoint profiling, segmentation, asset...  ...equivalent knowledge of next-generation firewall fundamentals, threats, App-ID, and security policy. ·          PCNSA – Palo Alto... 
    Permanent employment
    Full time
    Contract work
    Temporary work
    Immediate start
    Work from home

    KēSTA I.T.

    Clinton, MS
    7 days ago
  •  ...Defined Access (SDA), Cisco Identity Services Engine (ISE), Cisco Catalyst platforms, and observability tools including ThousandEyes, Cyber Vision, and DNA Spaces. The role also includes the administration of Palo Alto firewalls supporting statewide systems. Major... 
    Local area

    Brilliant Infotech Inc

    Jackson, MS
    2 days ago
  •  ...Experience administering Cisco ISE including TACACS+ and policy-set based NAC. Required. ~ Strong understanding of ThousandEyes, Cyber Vision, and DNA Spaces or comparable tools. Required. ~ Solid command of core TCP/IP, routing, switching, QoS, and network... 
    Work at office
    Relocation

    HireITPeople

    Jackson, MS
    2 days ago
  • Founded in 1912 as an adoption agency, Canopy Children's Solutions is Mississippi’s most comprehensive nonprofit provider of children’s behavioral health, educational, and family support solutions. Canopy employs a diverse group of mission-driven individuals committed to...
    Full time
    For contractors
    Local area

    Canopy Standard

    Jackson, MS
    2 days ago
  • Descriptionofthejobfunctionsthecontractorwillbeexpectedtoperform. EngineertosupportandadvancetheState’senterprisenetworkingenvironment.Thispositionplaysacriticalrolein designing,deploying,andoperatingnewLDC(LiquorDistributionCenter)fabrics,networks,identity-drivenaccess...

    Skywalk Global

    Jackson, MS
    1 day ago
  • Delivery ManagerThe Delivery Manager holds program-level execution accountability for an assigned portfolio and is responsible for the financial performance, operational execution, and strategic success of an assigned portfolio within the Business Unit. This role owns ...
    Work at office
    Local area
    Remote work

    Neumo Group LLC.

    Jackson, MS
    1 day ago
  •  ...through identity-centric segmentation and policy integration.Deploy and manage network observability tools such as ThousandEyes, Cisco Cyber Vision, and DNA Spaces, analyzing data to provide actionable insights.Troubleshoot Layer 2 and Layer 3 network issues, including... 

    Delphi-US, LLC - Peacemakers in the Talent War

    Jackson, MS
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Threat Analyst. Be the first to apply!