Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Threat Analyst

Full-time

The Newberry Group

Job Summary

Newberry Group is seeking an analytical, mission-driven Cyber Threat Analyst to join our customer’s defensive cyber operations team supporting the Joint Fires Network (JFN) Security Operations Center (SOC). Operating out of secure Sensitive Compartmented Information Facilities (SCIFs) at DISA Pacific (Ford Island, HI), this team provides specialized threat intelligence synthesis, behavioral anomaly detection, and advanced threat hunting to safeguard the JFN Impact Level 7 (IL-7) and multi-level classified enclaves supporting the Olympus Fires mission.
In this role, you will analyze network telemetry, advanced sensor feeds (such as Corelight and Darktrace), and syslog audits across up to 30 active operational nodes (including SD-WAN transport fabrics tied to the DISN and GMS). You will develop novel behavioral threat hunting playbooks, formulate containment and response strategies in JIRA, support the JFN Incident Response Plan, ensure DIA-aligned TS/SCI incident escalation compliance, and translate adversary tradecraft into detection logic for the Elastic Search / Elastic Defend SIEM platform.

Location
This is a full-time onsite role in Ford Island, HI. Telework is not permitted.
Relocation expenses may be eligible for reimbursement.

Responsibilities and Duties
1. Advanced Threat Hunting & Novel Playbook Development
  • Novel Playbook Authoring: Design, test, and operationalize novel threat hunting playbooks focused on behavioral anomalies, abnormal command and control (C2), lateral movement, and traffic pattern deviations across JFN transport nodes.
  • Proactive Hypothesis Hunting: Formulate threat hypotheses based on all-source intelligence and observed indicators, interrogating the Elastic Search / Defend SIEM and raw network telemetry to uncover persistent, evasive adversary tradecraft.
  • Routine Threat Containment: Leverage Atlassian JIRA to author, refine, and maintain standardized processes and playbooks for executing routine threat containment actions and defensive countermeasure coordination.
  • MITRE ATT&CK Mapping: Map adversary tactics, techniques, and procedures (TTPs) targeting tactical fires and command-and-control networks to the MITRE ATT&CK® framework to identify visibility gaps and improve defensive posturing.
  • SIEM Detection Tuning: Recommend and refine custom detection queries (Elastic KQL/EQL) and alert correlations within Elastic Defend to optimize detection accuracy and reduce false positives for the 24/7 watch cell.
2. TS/SCI Incident Handling & Incident Response
  • Incident Response Architecture: Drive the technical threat intelligence and containment sections of the JFN Incident Response Plan in alignment with enterprise standards.
  • DIA-Aligned TS/SCI Incident Reporting: Strictly enforce Defense Intelligence Agency (DIA) requirements for TS/SCI incident handling, ensuring all spills, unauthorized access attempts, system compromises, and operational anomalies are reported through authorized channels within mandated reporting windows.
  • CSSP Alignment & Briefings: Support the delivery and maturity of four of the seven DoD Cybersecurity Service Provider (CSSP) core functions during Phase I standup, providing actionable threat summaries, warnings, and intelligence briefings to JFN leadership, DISA, and mission stakeholders.
Clearance & Citizenship
  • Citizenship: Must be a U.S. Citizen.
  • Security Clearance: Must possess an active Top Secret clearance with current SCI eligibility (adjudicated Tier 5 / SSBI) prior to start date, with the ability to maintain clearance while working in a secure SCIF environment.
Education & Experience Requirements
  • Level II (Intermediate): Bachelor’s degree in Cybersecurity, Intelligence Studies, Computer Science, Information Technology, or related discipline and 2+ years of direct experience in cyber threat intelligence, all-source cyber analysis, threat hunting, or SOC tier-2/tier-3 operations; OR an Associate degree and 4+ years ; OR 6+ years of relevant professional/military cyber intelligence experience in lieu of a degree.
  • Level III (Senior): Bachelor’s degree in a technical discipline and 4+ years of relevant experience; OR an Associate degree and 6+ years ; OR 8+ years of relevant experience/military service in lieu of degree.
Required DoD 8140 / 8570 Baseline Certification
  • Must hold a valid certification or degree meeting DoD 8140.03 / DCWF Work Role Code 531 Cyber Defense Incident Responder at the Intermediate Proficiency Level prior to hire.
  •   Accepted Certifications include: CySA+, GIAC GCTI, EC-C CEH or CND, Security+ CE, GIAC GSEC, or higher (e.g., CASP+ CE, CISSP, GCIA, GCIH) .
Technical Core Competencies
  • Strong experience in threat hunting, cyber threat intelligence, or advanced incident analysis within a DoD, military, or government SOC/DCO environment.
  • Proven ability to analyze and correlate network protocol telemetry, Netflow, proxy logs, and raw packet captures to reconstruct complex intrusion paths.
  • Hands-on proficiency querying SIEM platforms—specifically Elasticsearch, Logstash, Kibana (ELK) / Elastic Defend —using KQL or Lucene query syntax.
  • Deep knowledge of adversary TTPs, threat actor attribution, and operational mapping using the MITRE ATT&CK framework.
  • Direct experience writing incident documentation, standard operating procedures, and containment playbooks in JIRA.
  • Ability to work standard operational shifts with readiness for on-call surge or emergency incident escalation.
Preferred Qualifications
  • Prior experience supporting C4ISR systems or tactical operational enclaves (e.g., PMN).
  • Operational experience analyzing telemetry from Corelight (Zeek), Darktrace MDR, or Palo Alto Advanced Threat Prevention (ATP).
  • Experience utilizing AI prompting tools (Gemini, Grok, ChatGPT) to automate threat hunting data collection and indicator extraction.
  • Career Growth & Certification Support: Access Leidos cyber training pipelines, tuition assistance, and corporate sponsorships for premier technical credentials (SANS/GIAC, cloud security).
  • Long-Term Program Backing: Solidified role on a high-priority joint program supporting strategic defense requirements across DISA.
Who We Are…
Newberry Group is a performance-driven government services and solutions firm that provides security compliance, program governance, consulting, and customized solutions for public sector clients nationwide. 

The strength of our company is a direct reflection of our highly skilled and talented workforce.

Benefits and Perks
In addition to competitive wages, Newberry Group offers an outstanding benefit package. This includes medical coverage with three plan options, dental and vision coverage, personal time off, paid holidays, paid parental leave, telecommuting if available, retirement savings accounts (Pre-Tax and Roth), flexible and dependent care savings accounts, life insurance, long and short-term disability coverage, tuition and training reimbursement, employee assistance program, and more.
The Newberry Group, Inc. is an Equal Opportunity Employer – EEO/AA/Disability/Veterans.



 

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Cyber Threat Analyst in Washington DC vacancy
  •  ...MANTECH seeks a motivated, career and customer-oriented Cyber Network Threat Analyst to join our team in Springfield, VA The Counterintelligence Threat Technical Analyst will leverage their strong technical background and knowledge to support the Sponsor's mission... 
    Suggested
    Work at office

    MANTECH

    Springfield, VA
    6 hours ago
  •  ...Leidos is seeking a Tier 3 Cyber Threat Intelligence Analyst to join our team supporting DHS NOSC services. You will identify and investigate high-priority threat campaigns, track adversaries and TTPs, and deliver actionable intelligence to improve cyber resiliency across... 
    Suggested

    Leidos

    Washington DC
    2 days ago
  •  ...Allyon is seeking a Cyber Threat Intelligence Analyst in Arlington, VA to support DHS mission-critical CTI by analyzing and identifying threats. The role requires an active TS/SCI clearance and U.S. citizenship, with 5+ years of relevant experience. The position is full... 
    Suggested
    Full time

    Allyon

    Arlington, VA
    4 days ago
  •  ...Manager to proactively gather and analyze CTI for vulnerability management and operational decision support. You will identify emerging threats, coordinate with stakeholders, and produce comprehensive CTI reports. The role requires TS/SCI clearance, DHS suitability, and the... 
    Suggested
    2 days per week
    3 days per week

    Business Computers Management Consulting Group

    Arlington, VA
    4 days ago
  •  ...BCMC is seeking a seasoned Incident Manager to support cyber threat intelligence efforts for a critical VM program. The role focuses on gathering and analyzing CTI to guide operational decisions, identify emerging threats and collaborate with stakeholders to implement... 
    Suggested

    BCMC, LLC

    Arlington, VA
    5 days ago
  •  ...~10 years' experience in conducting in-depth analysis of cyber threats, including malware, phishing campaigns, and other attack vectors...  ...Public Trust Position Senior Cyber Threat Intelligence Analyst Number of Openings 1 Exempt/Non-Exempt Non-Exempt... 
    Full time
    Part time
    Work at office

    Avening Management and Technical Services LLC

    Washington DC
    3 days ago
  •  ...our employees are our number one resource. If you are a problem-solving people-person, apply today! Position Title: Lead Cyber Threat Analyst Location: Washington, DC Position Summary The Lead Cyber Threat Analyst serves as the technical and operational lead... 
    For contractors
    Local area

    DirectViz Solutions, LLC

    Washington DC
    18 days ago
  •  ...Job Description Job Description Evolver Federal is seeking a Lead Cyber Threat Analyst to fulfil a requirement for a potential government client. The Lead Cyber Threat Analyst is responsible for identifying, analyzing, and mitigating advanced cyber threats targeting... 
    Flexible hours

    Evolver Federal

    Washington DC
    18 days ago
  •  ...Job Description Job Description Job Title:   Senior Cyber Analyst City: Alexandria State: Virginia Position Requirements...  ...Familiarity with intelligence tools including Defense Intelligence Threat Library, Validated Online Lifecycle Threat reports, Community... 
    Work experience placement
    Work at office
    Local area

    Noetic Strategies Inc.

    Alexandria, VA
    a month ago
  •  ...Required Qualifications: Eastern Europe-focused geopolitical and cyber threat intelligence experience  Experience with cyber threat intelligence analysis principles in a government or commercial environment  Knowledge of current and emerging Eastern Europe-related... 
    Full time

    Maania Consultancy Services

    Arlington, VA
    a month ago
  • $100k - $124k

     ...produce meaningful results. This is a contingent position based upon customer approval. SkyePoint Decisions is seeking a Cyber Threat Analyst to support the Diplomatic Security Cyber Mission (DSCM) program providing leading cyber and technology security experience... 
    Contract work
    Remote work
    Overseas

    SkyePoint Decisions

    Arlington, VA
    a month ago
  • Nightwing seeks a Cyber Threat Analyst to support a U.S. Government customer in Arlington, VA. The role focuses on incident response, analysis of threats, and coordination across teams to mitigate cyber breaches. The ideal candidate has 2+ years in cyber incident management... 

    Nightwing

    Arlington, VA
    4 days ago
  • Makoa in Arlington, VA is seeking a cybersecurity engineer to implement and manage Splunk infrastructure, monitor threats and ensure compliance in a federal context. The role includes patching servers, maintaining Linux environments, and enforcing security policies while... 

    Makoa

    Arlington, VA
    4 days ago
  • $142.79k - $172.5k

    Job Overview Cyber Security Analyst at GDIT. Build and protect classified and unclassified systems for a major Intelligence Community Agency, ensuring threat mitigation and compliance with policies. Responsibilities Gather and handle forensic evidence in accordance with... 
    Temporary work
    Monday to Friday
    Shift work

    3M HEALTHCARE

    Riverdale Park, MD
    3 days ago
  • Nightwing is seeking a JCDC Cyber Triage Analyst to perform initial triage and analysis of cyber threat reports, IOCs, and incident tickets. You will correlate evidence, determine severity, and provide actionable recommendations for escalation to government and interagency... 

    Nightwing

    Arlington, VA
    4 days ago
  • $160k - $220k

     ...our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect,...  ...newsworthy findings. About the Job Wiz is looking for a Cyber Threat Analyst to join the Threat Research team and spread the power of Wiz... 
    Full time

    Wiz, Inc.

    Washington DC
    3 days ago
  • $154.2k - $190.3k

     ...more. Join us to drive positive, lasting change that moves missions and the government forward! We are seeking a Cyber Threat Hunt Analyst to provide subject-matter expertise on a federal agency's proactive threat hunting mission. You will lead complex hunt missions... 
    Full time
    Live in
    Work at office
    Local area
    Remote work

    Accenture Federal Services

    Washington DC
    3 days ago
  • $130k - $180k

     ...delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy. Lead Cyber Threat Intelligence Analyst Location: Onsite – Government-controlled secure facility Terms: Full-time Salary: $130-$180k DOE Clearance... 
    Full time
    Work experience placement
    Flexible hours
    Shift work

    Revolutional, LLC

    Suitland, MD
    a month ago
  •  ...through proactively identifying, analyzing, and responding to cyber threats to inform the customer’s vulnerability management (VM) efforts...  ...Hacker (CEH) • CompTIA’s Security Plus (SEC+) • Intelligence Analyst Certified (IAC) • Certified Threat Intelligence Analyst (C|... 
    Full time
    Local area
    Flexible hours

    BCMC

    Arlington, VA
    a month ago
  •  ...Required Qualifications: Experience with intelligence analysis principles or cyber threat intelligence (CTI) principles, including the ability to collect, analyze, and assess threat information. Specific experience conducting CTI analysis focused on China cyber... 

    Maania Consultancy Services

    Arlington, VA
    a month ago
  •  ...Job Description Job Description Synertex is seeking an All-Source Cyber Threat Intelligence Analyst to support a national cybersecurity organization client in Arlington, VA. This organization focuses on reducing risk to national infrastructure and growing resilience... 
    Work at office

    Synertex LLC

    Arlington, VA
    15 days ago
  •  ...flexibility, and ingenuity to strengthen and protect our nation’s vital interests. Requisition #: 1617 Job Title: Cyber Threat Intelligence Analyst Location: On-Site, Arlington, VA Clearance Level: Top Secret, Must Have Clearance to Start Job Description... 

    Agile Defense

    Arlington, VA
    a month ago
  •  ...Job Description Job Description Synertex is seeking a Senior Cyber Threat & Adversary Intelligence Analyst to support a national cybersecurity organization client in Arlington, VA. This organization focuses on reducing risk to national infrastructure and growing resilience... 

    Synertex LLC

    Arlington, VA
    15 days ago
  •  ...Job Description Job Description Cyber Threat intelligence Analyst II Location: Onsite (CONUS) / Shift Work Clearance: Active TS/SCI (DHS EOD Suitability required) Company: Argo Cyber Systems, LLC – Service-Disabled Veteran-Owned Small Business (SDVOSB) About... 
    Shift work

    Argo Cyber Systems

    Arlington, VA
    18 days ago
  •  ...skilled digital forensics and incident response professional to join our security operations. The role focuses on investigations, threat hunting, malware analysis, and proactive defense to strengthen enterprise security across enterprise infrastructure. The candidate... 

    Gunnison

    Alexandria, VA
    2 days ago
  • Peraton in the United States seeks a Senior Cyber Threat Analyst - GTA to join the Global Threat Analysis program on-site in Rosslyn, VA. The role focuses on analyzing threats from state and non-state actors, producing intelligence-rich briefings for senior leadership,... 

    Peraton

    Arlington, VA
    4 days ago
  • $100k - $110k

    Cyber Threat Intelligence Analyst Job Number : 32285 Location : Arlington, VA Job Description : Cyber Threat Intelligence Analyst Arlington, VA Support mission-critical cyber threat intelligence for the Department of Homeland Security by analyzing and identifying... 
    Full time
    Flexible hours

    Allyon, Inc.

    Arlington, VA
    4 days ago
  • SOSI is seeking a Cyber Intelligence Analyst III to lead cyber threat intelligence activities in support of mission-critical defense and government services. The role focuses on producing intelligence, supporting detection and response, and delivering actionable reports... 
    Work at office
    Remote work

    SmartRecruiters, Inc.

    Washington DC
    2 days ago
  • $70k - $85k

     ...cybersecurity support provider is seeking motivated individuals to deliver intelligence support by analyzing and responding to cyber threats. The position requires U.S. citizenship, an active TS/SCI clearance, and 5+ years of experience in relevant fields. Responsibilities... 

    ARGO Cyber Systems

    Arlington, VA
    1 day ago
  • $106.92k - $242.82k

     ...team that develops products and services with action-based outcomes to reduce and identify risk to TikTok USDS JV. As a Cyber Threat Intelligence Analyst, the candidate will be responsible for managing the triage, escalation, and reporting of threats against our US... 
    Temporary work
    Shift work

    TikTok USDS Joint Venture LLC

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Threat Analyst. Be the first to apply!