Threat Hunt Lead (CBP)
$165k - $200kAgile Defense
Job Description
Job Description
About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Title : Threat Hunt Lead (CBP)
Clearance : Active Top Secret with SCI eligibility, ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can begin processing for candidates who do not hold one.
Citizenship : U.S. Citizenship required
Location : Reston, VA - Hybrid
Salary Range : $165,000-200,000
Signing Bonus : $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply.
Required Certification(s) : GIAC, GCIH or CEH
The RoleU.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. The systems behind that mission are watched by automated detection around the clock, and automated detection only catches what it was built to catch. The gap between what a tool flags and what is actually happening in the environment is where a threat hunter works, and on a program supporting continuous federal law enforcement operations, that gap is not theoretical. You lead threat hunting for this program. You will form and test hypotheses about activity the SOC's existing detections might be missing, dig into the environment to confirm or rule them out, and turn what you find into detections other analysts can rely on going forward. You will work closely with the Security Operations Center Manager and hand confirmed findings to the incident response and digital forensics leads. One thing is worth knowing before you apply. Most hunts do not find anything, and that is not failure. A hunt that rules out a hypothesis honestly is doing its job. The people who do well here are comfortable being wrong most of the time in service of being right when it counts.
What Success Looks LikeObjective 1: Find what automated detection misses
- Hunts are grounded in a real hypothesis about adversary behavior, not a general look around for anything unusual.
- Confirmed findings represent activity that existing detections did not catch, which is the actual measure of whether hunting is adding value beyond the SOC's standing tools.
- You can explain why you ruled a hypothesis out, not just report that you did.
Objective 2: Turn what you find into detection that outlives the hunt
- Confirmed findings become new detection logic, so the next occurrence gets caught automatically instead of requiring another manual hunt.
- Detection you build gets tuned as conditions change, rather than left as originally written.
- Other analysts can use what you built without needing you to explain it every time.
Objective 3: Hand off findings clean enough to act on immediately
- When a hunt confirms real activity, incident response gets a finding they can act on without redoing your investigative work.
- Evidence and context are preserved well enough that digital forensics can pick up where you left off if a case needs that depth.
- You know when a finding needs to escalate now versus when it can go through standard reporting.
Objective 4: Keep the hunting program grounded in what actually threatens this environment
- Hunt hypotheses reflect the tactics that matter for a federal law enforcement environment, not a generic threat list.
- Threat intelligence gets translated into hunts that are specific enough to test, not left as a general awareness exercise.
- You can say what you have not hunted for yet and why, rather than presenting coverage as complete.
Minimum required experience
- One of the folowing certificatations: GCIA, GCIH or GFCA OR CEH
A minimum of five (5) years of experience as a Tier 3 senior cyber threat hunt analyst performing threat analysis, technical analysis, and network asset traversal.
A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes host and network-based security monitoring using cybersecurity capabilities.
Applicant will possess a strong cyber security background with experience in host and network-based forensics related to the identification of advanced cyber threat activities, intrusion detection, malware identification, and security content development (e.g., signatures, rules, queries etc.).
Shall have experience interpreting a variety of scripts or programming languages to support cyber threat hunts or malware analysis in a variety of formats, such as VB scripts, Python, PowerShell, JavaScript, and HTML, XML or other types needed for analysis.
Candidates will have experience in conducting cyber threat hunt analysis, utilizing cyber threat intelligence to identify and prioritize tactics, techniques, and procedures to hunt against.
Have a deep knowledge of capabilities and experience with security information and event management (SIEM) and networked-device management tools such as Splunk and EDR solutions.
Candidates will have experience in maintaining a comprehensive understanding of the cyber threat landscape, including identifying and analyzing cyber threats actors and activities to enhance cybersecurity posture of the organization’s IT operating environment.
Will work with the Cyber Threat Intelligence team to report significant findings of importance to leadership as well as coordinate with Pentest team and asset owners to deconflict findings.
Candidate will lead the Cyber Threat Hunt team to propose corrective actions and inform the necessary parties of security issues, reportable offenses, or cybersecurity best practices.
Candidate will have strong written and oral communication skills
Preferred Experience
- Additional certifications such as: GFCA, GREM, GFNA,OSCP, GPEN
- You have led or performed structured threat hunting, using a framework such as MITRE ATT&CK to form and test hypotheses, not only reviewed alerts as they arrived.
- You have turned a hunt finding into a production detection and can describe the process.
- You have worked in an environment defending against threats targeting government or law enforcement data, not only general commercial risk.
- You are comfortable working from incomplete or ambiguous signals and can describe how you decide when a hypothesis is worth pursuing.
- You hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance. Any of these shortens your start date.
- Certifications such as GCFA, GNFA, or equivalent are useful, but they are not a substitute for having found something real.
We are staffing this program now. If you already hold an active CBP BI and EOD, your start date is short and a $10,000 signing bonus comes with the role, payable after 90 days under standard terms. We would like to talk this week. If you do not, we can begin processing a CBP BI for you. That takes months rather than weeks, so applying now means joining a pipeline rather than starting immediately. We would rather tell you that up front than have you find out after you apply.
Employee BenefitsAgile's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections.
Our Core Values
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$160k - $185k
...foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests. Title : Insider Threat Monitoring Lead (CBP) Clearance : Active Top Secret with SCI Eligibility, and ability to obtain CBP Background Investigation (CBP BI) and...SuggestedTemporary workImmediate startRelocation package$155k - $175k
...vital interests. Title : Vulnerability Assessment (VA) Team Lead (CBP) Clearance : Active Top Secret Clearance with SCI... ...what you find, and hand confirmed exploitable findings to the threat hunt and incident response leads when they need that context. One thing...SuggestedTemporary workImmediate startRelocation package$155k - $180k
...Title : Incident Response Team Lead Clearance : Active Top... ...ability to obtain and maintain a CBP Background Investigation (CBP BI... ...security investigations for potential threat activity identified within the... ...security issues, incidents, hunts or digital forensics and...SuggestedWork experience placementRelocation package- ...Strategic Non‑Kinetic Effects Mission Division is seeking a Cyber Threat Intelligence Analyst with deep, cross-disciplinary expertise in... ...engineering.Experience in all-source intelligence, threat hunting, vulnerability analysis, network reverse engineering and network...SuggestedWork experience placementLocal area
$155k - $180k
...#: 1435 Job Title: Incident Response Team Lead Location: Reston, VA Clearance Level: TS (... ...conducts security investigations for potential threat activity identified within the... ...emphasis in cyber security issues, incidents, hunts or digital forensics and operations, and computer...SuggestedWork experience placement$155k - $185k
...with SCI Eligibility, ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI... ...individual analysts. You will work closely with the leads who run insider threat monitoring, threat hunting, incident response, digital forensics, and...Temporary workImmediate startRelocation packageShift work$198k - $202k
Hire, mentor, and lead a geographically dispersed team of multi-disciplinary security professionals, insider threat analysts, technical investigators, and developers.Own the end-to-end strategy for Google’s global insider threat detection, personnel security vetting, and...For contractorsLocal area$112k - $179k
...experienced Systems Engineer to serve as our Secure Virtual Desktops, Lead to join our national intelligence program that delivers... ...operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The...Contract workWork experience placementWork at officeShift work- ...services (Consulting, Advanced Security Product Services, MDR) and leading Security Platforms (market leading OEM’s/ISV’s) revenue,... ...DSS, etc. Broad experience and understanding of security trends, threat landscape and frameworks like the cyber kill-chain. Ability to...Full time
$112k - $179k
...warfighter. Responsibilities: This Senior Collection Operations Manager Lead is responsible for analyzing how intelligence is collected and... ...at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The...Contract workWork experience placementWork at officeShift work$86k - $138k
ResponsibilitiesWe are seeking a Strategic Partnerships Lead Associate to support Peraton’s relationships with leading cloud and emerging... ...at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The...Contract workShift work$135k - $216k
...Capabilities Engineer (ACE) to serve as the primary technical proposal lead for National Reconnaissance Office (NRO) opportunities. This is... ...at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The...Full timeContract workFor contractorsWork experience placementWork at officeImmediate startShift work$135k - $216k
...Capabilities Engineer (ACE) to serve as the primary technical proposal lead for National Geospatial-Intelligence Agency (NGA) opportunities.... ...at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The...Full timeContract workWork experience placementWork at officeImmediate startShift work$146k - $234k
ResponsibilitiesPeraton Labs is seeking a Lead Data Architect - Aviation Analytics to support FAA BNATCS CTO in identifying, acquiring... ...at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company...Contract workLocal areaShift work- .... Make an impact by using your expertise to protect our country from threats. Job Description Ensure the safety and security of our nation as a Knowledge/Configuration Management (KM/CM) Lead at GDIT. You’ll apply the latest technology and provide operational support...
- Sprouts Farmers Market, Inc. is looking for an experienced Assistant Meat Manager to join their team in Herndon, Virginia. The role involves assisting in managing and merchandising for the Meat and Seafood department, ensuring excellent customer service and team leadership...
- ...mission critical customer in Reston, VA. As the Incident Response Lead/Advisor, you will advise/mentor/coach a team of cyber security... ...~ Collaborating with IT and security teams to mitigate threats and prevent recurrence ~ Advising on security policies, risk...Full timeContract workTemporary workImmediate startShift work
$175k - $225k
...strengthen and protect our nation’s vital interests. Title : Splunk Architect Lead Clearance : Active Top Secret Clearance with SCI eligibility, ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can...Relocation package- DescriptionWe are seeking a new Supervisory Team Lead - Recruiting! This position is responsible for leading a team of recruiters while implementing talent acquisition programs that drive recruiting effectiveness across Tyler. This role leverages industry expertise, operating...
$110k - $160k
Ashburn, VAComputer World Services - CWS /Full-time /HybridCWS seeks a NOC Tier 1 Shift Lead to supervise the U.S. Customs and Border Protection’s (CBP) Network Operations Center (NOC) contract Tier 1 NOC technicians. The NOC Tier 1 Shift Lead supervises the Tier 1 NOC...Full timeContract workLocal areaShift workNight shift$150k - $180k
OverviewAs an Integration Lead, you will work with our growing DevSecOps practice developing APIs and integration capabilities to connect... ...Ensure that systems are safe and secure against cybersecurity threats Identify technical problems, perform root cause analysis, and...- ...to enable national security missions worldwide.Job DescriptionOverviewSOSi is seeking a highly organized and detail-oriented Program Lead to join our team. As our Program Lead you will play a critical role in supporting our language service program for federal, state,...Permanent employmentContract workWork at officeLocal areaWorldwideNight shift
$125k - $175k
OverviewWe are seeking a Vulnerability Management Lead responsible for planning, executing, and continuously maturing the enterprise... ...risk-based prioritization methodologies utilizing exploitability, threat intelligence, asset criticality, and business impact to mature...$154.3k - $274.1k
...’re obsessed with making hard work pay off, for our people, our customers, and the world around us. As a Fortune 500 company and a leading AI platform for managing people, money, and agents, we’re shaping the future of work so teams can reach their potential and focus on...Full timeWork at officeRemote workHome officeFlexible hours- Celestar Corporation is seeking a Lead Ontologist to support the Defense Intelligence Agency (DIA) under the Object Based Intelligence and Quality Assurance (OBIQUA) task order. The primary place of performance will be at DIA Facilities across the National Capital Region...Local area
$120.8k - $265.8k
...knowledge transfer to junior network engineers and technicians.Stay updated on emerging network technologies, trends, and security threats to continuously improve network infrastructure.Provide afterhours call in support for CAN/LAN services.Support deployable networks...Contract workWork experience placementLocal areaFlexible hours$85k - $170k
OverviewWe are seeking a Red-Team / Adversarial Security Lead responsible for planning and executing adversarial security assessments across complex enterprise environments. This role develops threat models, identifies potential attack paths and vulnerabilities, develops...$90k - $110k
ICF’s Disaster Management Division is looking for an experienced CDBG-DR Housing Grant Administration Lead. This position is 100% Remote in the United States. Non-managerial. As a CDBG-DR Housing Grant Administration Lead, you will have in-depth experience with the Department...Full timeContract workFor contractorsWork experience placementFor subcontractorWork at officeLocal areaRemote workRelocation$167k - $251k
...model governance, and data-driven oversight while developing and leading talent in a fast-paced, mission-critical environment.Our Impact... ...and using best practices to protect Freddie Mac from potential threats and risk. Employees exercise this responsibility by executing...Local area$116.35k - $210.33k
The Digital Modernization Sector at Leidos has an opening for a Tier II Site Lead to support the customer’s computer data communications systems, in providing design specifications, testing and inspections for computer networks; plan and implementing upgrades; as well...Full time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Threat Hunt Lead (CBP). Be the first to apply!


