Cybersecurity Analyst
Listed on 2026-07-17
-
IT/Tech
Cybersecurity, Network Security
Job Summary
Newberry Group's Public Sector Division is seeking Cybersecurity Analysts to support a 24/7 Cyber Network Defense (CND) Operation for Department of Defense networks at Scott Air Force Base in Illinois. The role requires analyzing real‑time cyber threat intelligence, correlating security events to identify and prioritize potential incidents, conducting network traffic analysis using raw packet data to uncover malicious activity, and collaborating with incident response teams to contain and eradicate threats.
Candidates must hold an active DoD Secret clearance;
Top Secret clearance is preferred.
Work is on site at Scott AFB, IL, and requires willingness and ability to perform shift work. Available shifts are 7am‑3pm, 3pm‑11pm, and 11pm‑7am.
Compensation$95,000 to $125,000 per year.
Primary Responsibilities- Investigate alerts generated from endpoints, IDS/IPS, Net Flow data, and custom sensors to detect compromises on customer networks.
- Analyze extensive log files, pivot between diverse datasets, and correlate evidence to support incident investigations, creating detailed technical reports outlining your findings.
- Triage security alerts to rapidly identify malicious actors targeting customer networks.
- Monitor and analyze DoD and open‑source intelligence feeds to identify Indicators of Compromise (IOCs) and integrate them into security sensors and SIEMs.
- Report security incidents to customers and USCYBERCOM, ensuring timely communication and coordinated response.
- Active DoD Secret clearance or above.
- Current DoD 8570 IAT Level II certification (or higher), such as CompTIA Security+ CE, ISC‑2 SSCP, or SANS GSEC (or equivalent).
- Ability to obtain DoD 8570 CSSP‑A Level Certification (e.g., CEH, CySA+, GCIA, or equivalent) within 180 days of hire.
- Strong foundation in networking, including packet analysis, common ports and protocols, traffic flow, OSI model, defense‑in‑depth security principles, and common security elements for effective threat detection, analysis, and mitigation as a SOC Security Analyst.
- Education and experience requirements:
- Level I:
Bachelor’s degree and 1+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree. - Level II:
Bachelor’s degree and 3+ years of relevant experience; equivalent work experience and/or military service may be considered in lieu of a degree.
- Level I:
- Proven ability to work effectively both independently and as a collaborative team member, demonstrating initiative and a strong work ethic in both settings.
- Committed to continuous learning and self‑improvement in the cybersecurity domain, evidenced by ongoing pursuit of certifications, active participation in industry forums, and dedication to staying ahead of emerging threats and technologies.
- Excellent problem‑solving skills, including the ability to collaborate effectively with cross‑functional teams to address complex security challenges in real‑world scenarios, communicate technical information clearly and concisely, build consensus, and drive solutions to completion.
- Reliable and flexible, with a demonstrated willingness to work assigned shifts to support operational requirements and team objectives.
- Located within a commutable distance to Scott AFB, IL.
- Hands‑on experience analyzing large volumes of logs, network data (e.g., Net Flow, Full Packet Capture), and other attack artifacts during incident investigations.
- In‑depth experience using a SIEM/SOAR platform to analyze multiple log types and events across various data points, applying techniques such as behavioral analysis, statistical analysis, and machine learning to detect and respond to advanced threats.
- Comprehensive understanding of the network threat lifecycle, attack vectors, and methods of exploitation, including intrusion set tactics, techniques, and procedures (TTPs).
- Experience with Anti‑Virus, HIPS/HBSS, IDS/IPS, Full Packet Capture, and Network Forensics tools.
- Experience or knowledge in monitoring, defending, or administering cloud networks (e.g., AWS, Azure, GCP), including cloud‑native security tools and strategies for protecting data…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).