Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Countermeasure Specialist

Full-time

The Newberry Group

Job Summary - $10,000 sign-on bonus included (subject to a 12-month commitment)

Newberry Group is seeking an experienced, technically agile Cyber Countermeasure Specialist to support our customer’s defensive cyber operations team supporting the Joint Fires Network (JFN). Stationed inside secure SCIF environments at DISA Pacific (Ford Island, HI), this position plays a critical role in bridging detection analytics and active threat containment for the JFN Impact Level 7 (IL-7) environment and associated multi-domain operational enclaves.

In this role, you will be responsible for the engineering, operational validation, deployment, and lifecycle maintenance of defensive countermeasures, detection signatures, sensor tuning, and containment workflows. Operating across up to 30 active operational nodes (including SD-WAN transport fabrics and out-of-band management links), you will tune advanced network sensor grids (such as Corelight and Elastic Defend), author actionable threat containment playbooks within Atlassian JIRA, enforce strict Defense Intelligence Agency (DIA) TS/SCI spill and breach containment standards, and collaborate closely with Tier II NOC engineers (SolarWinds/Jira) and NIWC pipeline architects to neutralize adversarial activity across the JFN operational battlespace.

Location
This is a full-time onsite role in Ford Island, HI. Telework is not permitted.
Relocation expenses may be eligible for reimbursement.

Responsibilities and Duties
1. Countermeasure Engineering, Sensor Tuning & Active
Defense
  • Sensor Tuning & Management: Configure, tune, and operationalize advanced   boundary and enroute security sensors—including Corelight (Zeek-based telemetry) and Elastic Defend —to maximize high-fidelity detection while   suppressing noise across JFN nodes.
  • Custom Signature & Rule Development: Design, test, validate, and maintain   custom intrusion detection rules, Zeek scripts, YARA rules, and Elastic SIEM   detection logic targeting emerging exploit patterns, living-off-the-land   techniques, and lateral movement attempts.
  • Palo Alto ATP & Pipeline Ingestion: Collaborate with NIWC data engineers to   validate log ingestion pipelines (Logstash) from Palo Alto Advanced Threat   Prevention (ATP), Prometheus, and endpoint monitors, ensuring sensor event   logic triggers actionable containment mechanisms.
  • Countermeasure Tracking & De-confliction: Track all deployed signatures   and mitigation actions within JIRA; execute deliberate de-confliction procedures   with DISA and operational network authorities to prevent unintended   disruption to operational fires data streams.
  •   Rapid Rollback & Operational Stability: Establish, document, and test rapid   rollback mechanisms to immediately revert sensor configurations and   containment rules if mission communications are impacted during crisis  execution.
2. Playbook Engineering & Incident Response Automation
  • Containment Playbook Development: Leverage Atlassian JIRA to design,   automate, document, and maintain end-to-end standard operating procedures  (SOPs) and execution runbooks for routine threat containment, node isolation   and sensor re-baselining.
  • Incident Response Plan Operationalization: Support the drafting,   maintenance, and technical execution of the JFN Incident Response Plan,   ensuring rapid transition from alert triage to active containment.
  • CSSP Defense Service Integration: Drive the technical countermeasure   delivery for four of the seven DoD Cybersecurity Service Provider (CSSP) core   functions during Phase I standup, expanding to full CSSP operational   countermeasure capability during Phase II sustainment.
  • Traffic Pattern & Behavioral Countermeasures: Translate behavioral   anomaly findings and traffic pattern analyses developed by threat hunters into   actionable, rule-based containment triggers across SD-WAN interfaces and out-of- band management channels.
3. Classified Spill Containment & SCIF Operations
  • Spill & Breach Containment: Implement and enforce rigorous Defense   Intelligence Agency (DIA) protocols for containment and technical quarantine of   classified data spills, unauthorized cross-domain transfers, or credential   compromise within TS/SCI and IL-6 domains.
  • Audit Readiness & Compliance: Verify that all active countermeasures, alerting   mechanisms, and log capture configurations strictly adhere to formal TS/SCI   Information Systems Security Program audit criteria and JFN Security   Classification Guidance.
  • Cross-Functional Team Collaboration: Partner daily with JFN 24/7 Real-Time   Analysts, Tier II NOC administrators managing SolarWinds and Jira, and DISA   Field Command leadership to coordinate high-priority containment actions   during active network events.
  • SCIF Operational Assurance: Conduct all defensive engineering within   designated Sensitive Compartmented Information Facilities (SCIF), maintaining   operational integrity across classified enclaves.
Clearance & Citizenship
  • Citizenship: Must be a U.S. Citizen
  • Security Clearance: Must possess an active Top Secret clearance with current SCI eligibility (adjudicated Tier 5 / SSBI) prior to start date, with the ability to maintain clearance while working in a secure SCIF environment.
Education & Experience Requirements
  • Level II (Intermediate): Bachelor’s degree in Cybersecurity, Computer Science,   Computer Engineering, Information Technology, or related discipline with 2+   years of direct experience in intrusion detection/prevention engineering,   custom signature creation, or network defense operations; OR an Associate   degree with 4+ years ; OR 6+ years of relevant experience/military cyber   service in lieu of degree.
  • Level III (Senior): Bachelor’s degree in a technical discipline with 4+ years of   relevant experience; OR an Associate degree with 6+ years ; OR 8+ years of   relevant experience/military cyber service in lieu of degree.
Required DoD 8140 / 8570 Baseline Certification
  • Must hold a valid certification or degree meeting DoD 8140.03 / DCWF Work   Role Code 521: Cyber Defense Infrastructure Support Specialist at the Basic   Proficiency Level prior to start.
  • Accepted Certifications include: CySA+, CCNA-Security, GICSP, GSEC,   Security+ CE, CND, CEH, or higher (e.g., CASP+ CE, CISSP, GCIA, GCIH) .
Technical Core Competencies
  • Proven experience authoring, testing, and deploying custom network intrusion signatures and parsing logic (e.g., Snort/Suricata rules, Zeek scripts, YARA, or Elastic KQL/EQL query rules)
  • Hands-on operational experience with enterprise sensor platforms such as   Corelight , Elastic Defend / ELK Stack , or next-generation firewalls (e.g., Palo   Alto Networks).
  • Demonstrated experience developing, documenting, and executing threat   containment workflows and tracking procedures using Atlassian JIRA .
  • Solid understanding of core networking protocols (TCP/IP, BGP, IPsec, DNS,   TLS), network perimeter architectures, and packet analysis tools (Wireshark,   tcpdump).
  • Ability to support standard operational day shifts (8x5) with on-call flexibility   for emergency after-hours containment surges or critical network defense   events.
Preferred Qualifications
  • Direct experience deploying and managing countermeasures across Impact   Level 6/7 (IL-6/7) , SIPRNet, or Top Secret / SCI enclaves.
  • Familiarity with Software-Defined WAN (SD-WAN) technologies, Out-of-Band   network management, and SolarWinds monitoring integrations.
  • Experience with automated containment scripting using Python, PowerShell,   Bash, or REST APIs.
  • Understanding of Darktrace Managed Detection & Response (MDR) and   Prometheus pipeline data flows.
  • Prior experience supporting C4ISR systems or joint tactical enclaves.
Who We Are…
Newberry Group is a performance-driven government services and solutions firm that provides security compliance, program governance, consulting, and customized solutions for public sector clients nationwide. 

The strength of our company is a direct reflection of our highly skilled and talented workforce.

Benefits and Perks
In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more.

The Newberry Group, Inc. is an Equal Opportunity Employer – EEO/AA/Disability/Veterans.

 

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Countermeasure Specialist in Ford County, IL vacancy
  •  ...commitment) Newberry Group is seeking an analytical, mission-driven Cyber Threat Analyst to join our customer’s defensive cyber...  ...executing routine threat containment actions and defensive countermeasure coordination. MITRE ATT&CK Mapping: Map adversary tactics,... 
    Cyber
    Full time
    Temporary work
    Remote work
    Relocation
    Relocation package
    Flexible hours
    Shift work

    The Newberry Group

    Ford County, IL
    2 days ago
  •  ...commitment) Newberry Group is seeking proactive and mission-focused Cyber Real Time Analysts to join our customer's defensive cyber...  ...containment actions, remediation coordination, and defensive countermeasures. Cross-Functional Collaboration: Partner closely with JFN... 
    Cyber
    Full time
    Temporary work
    Remote work
    Relocation
    Relocation package
    Flexible hours
    Night shift
    Rotating shift

    The Newberry Group

    Ford County, IL
    2 days ago
  •  ...Job Responsibilities The Safety Specialist in Gibson City, IL supports specific project needs by ensuring best practices are implemented, safety compliance requirements are met, and enhance a culture of safety. # Oversee all aspects of a commercial construction project... 
    Suggested
    Full time

    HazTek Inc.

    Gibson City, IL
    2 days ago
  • Gibson Area Hospital & Health Services in Gibson City, IL is seeking a full-time Medical Billing Clerk to greet and assist patients, manage billing tasks, and support the practice team. You will verify patient data, balance payments, and process records using NextGen. The...
    Suggested
    Full time
    Work at office

    Gibson-Area-Hospital-

    Gibson City, IL
    3 days ago
  • $40 - $60 per hour

    Job Description Job Description Position Overview: We are looking for a skilled Custom Refacing Installer with experience in kitchen cabinet refacing, particularly in replacing cabinet doors and applying refacing materials to the fronts and sides of cabinets. ...
    Suggested
    Hourly pay
    Part time
    Flexible hours

    Art of Drawers North Florida

    Ford County, IL
    4 days ago
  • About Atos Group Atos Group is a global leader in digital transformation with c. 56,000 employees and annual revenue of c. 7.2 billion (at the go-forward perimeter), operating in 54 countries under two brands - Atos for services and Eviden for products and systems...
    Full time

    Atos

    Piper City, IL
    2 days ago
  • Job Description Job Description Description Ready to elevate your career? Animal Medical Clinic at St. Johns is excited to add you as an Associate Veterinarian! Our team located in St. Johns, Florida prides themselves on their collaborative culture that integrates...
    Relocation package
    Flexible hours

    Animal Medical Center at St. Johns

    Ford County, IL
    26 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Countermeasure Specialist. Be the first to apply!