Threat Hunt Lead (CBP)
$165k - $200kAgile Defense
Job Description
Job Description
About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Title : Threat Hunt Lead (CBP)
Clearance : Active Top Secret with SCI eligibility, ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can begin processing for candidates who do not hold one.
Citizenship : U.S. Citizenship required
Location : Reston, VA - Hybrid
Salary Range : $165,000-200,000
Signing Bonus : $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply.
Required Certification(s) : GIAC, GCIH or CEH
The RoleU.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. The systems behind that mission are watched by automated detection around the clock, and automated detection only catches what it was built to catch. The gap between what a tool flags and what is actually happening in the environment is where a threat hunter works, and on a program supporting continuous federal law enforcement operations, that gap is not theoretical. You lead threat hunting for this program. You will form and test hypotheses about activity the SOC's existing detections might be missing, dig into the environment to confirm or rule them out, and turn what you find into detections other analysts can rely on going forward. You will work closely with the Security Operations Center Manager and hand confirmed findings to the incident response and digital forensics leads. One thing is worth knowing before you apply. Most hunts do not find anything, and that is not failure. A hunt that rules out a hypothesis honestly is doing its job. The people who do well here are comfortable being wrong most of the time in service of being right when it counts.
What Success Looks LikeObjective 1: Find what automated detection misses
- Hunts are grounded in a real hypothesis about adversary behavior, not a general look around for anything unusual.
- Confirmed findings represent activity that existing detections did not catch, which is the actual measure of whether hunting is adding value beyond the SOC's standing tools.
- You can explain why you ruled a hypothesis out, not just report that you did.
Objective 2: Turn what you find into detection that outlives the hunt
- Confirmed findings become new detection logic, so the next occurrence gets caught automatically instead of requiring another manual hunt.
- Detection you build gets tuned as conditions change, rather than left as originally written.
- Other analysts can use what you built without needing you to explain it every time.
Objective 3: Hand off findings clean enough to act on immediately
- When a hunt confirms real activity, incident response gets a finding they can act on without redoing your investigative work.
- Evidence and context are preserved well enough that digital forensics can pick up where you left off if a case needs that depth.
- You know when a finding needs to escalate now versus when it can go through standard reporting.
Objective 4: Keep the hunting program grounded in what actually threatens this environment
- Hunt hypotheses reflect the tactics that matter for a federal law enforcement environment, not a generic threat list.
- Threat intelligence gets translated into hunts that are specific enough to test, not left as a general awareness exercise.
- You can say what you have not hunted for yet and why, rather than presenting coverage as complete.
Minimum required experience
- One of the folowing certificatations: GCIA, GCIH or GFCA OR CEH
A minimum of five (5) years of experience as a Tier 3 senior cyber threat hunt analyst performing threat analysis, technical analysis, and network asset traversal.
A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes host and network-based security monitoring using cybersecurity capabilities.
Applicant will possess a strong cyber security background with experience in host and network-based forensics related to the identification of advanced cyber threat activities, intrusion detection, malware identification, and security content development (e.g., signatures, rules, queries etc.).
Shall have experience interpreting a variety of scripts or programming languages to support cyber threat hunts or malware analysis in a variety of formats, such as VB scripts, Python, PowerShell, JavaScript, and HTML, XML or other types needed for analysis.
Candidates will have experience in conducting cyber threat hunt analysis, utilizing cyber threat intelligence to identify and prioritize tactics, techniques, and procedures to hunt against.
Have a deep knowledge of capabilities and experience with security information and event management (SIEM) and networked-device management tools such as Splunk and EDR solutions.
Candidates will have experience in maintaining a comprehensive understanding of the cyber threat landscape, including identifying and analyzing cyber threats actors and activities to enhance cybersecurity posture of the organization’s IT operating environment.
Will work with the Cyber Threat Intelligence team to report significant findings of importance to leadership as well as coordinate with Pentest team and asset owners to deconflict findings.
Candidate will lead the Cyber Threat Hunt team to propose corrective actions and inform the necessary parties of security issues, reportable offenses, or cybersecurity best practices.
Candidate will have strong written and oral communication skills
Preferred Experience
- Additional certifications such as: GFCA, GREM, GFNA,OSCP, GPEN
- You have led or performed structured threat hunting, using a framework such as MITRE ATT&CK to form and test hypotheses, not only reviewed alerts as they arrived.
- You have turned a hunt finding into a production detection and can describe the process.
- You have worked in an environment defending against threats targeting government or law enforcement data, not only general commercial risk.
- You are comfortable working from incomplete or ambiguous signals and can describe how you decide when a hypothesis is worth pursuing.
- You hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance. Any of these shortens your start date.
- Certifications such as GCFA, GNFA, or equivalent are useful, but they are not a substitute for having found something real.
We are staffing this program now. If you already hold an active CBP BI and EOD, your start date is short and a $10,000 signing bonus comes with the role, payable after 90 days under standard terms. We would like to talk this week. If you do not, we can begin processing a CBP BI for you. That takes months rather than weeks, so applying now means joining a pipeline rather than starting immediately. We would rather tell you that up front than have you find out after you apply.
Employee BenefitsAgile's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections.
Our Core Values
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$155k - $180k
...Title : Incident Response Team Lead Clearance : Active Top... ...ability to obtain and maintain a CBP Background Investigation (CBP BI... ...security investigations for potential threat activity identified within the... ...security issues, incidents, hunts or digital forensics and...SuggestedWork experience placementRelocation package- ID.me is seeking a highly experienced SOC Lead to play a pivotal role in our advanced security operations. Based in McLean, VA, you... ...initiatives across cloud-native environments. You will lead threat hunting, forensic analysis, and incident response across GCP/Kubernetes...Suggested
$155k - $185k
...with SCI Eligibility, ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI... ...individual analysts. You will work closely with the leads who run insider threat monitoring, threat hunting, incident response, digital forensics, and...SuggestedTemporary workImmediate startRelocation packageShift work- Steampunk is seeking a Red-Team / Adversarial Security Lead to plan and execute threat-based assessments across enterprise environments. You will develop threat models, conduct adversarial testing, and evaluate security controls to support pass/fail safety gating. You will...Suggested
$175k - $225k
...strengthen and protect our nation’s vital interests. Title : Splunk Architect Lead Clearance : Active Top Secret Clearance with SCI eligibility, ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can...SuggestedRelocation package- Bank of America in McLean, VA seeks a Global Financial Crimes Threat Identification & Liaison Manager who is a subject matter expert in financial crime and will execute enterprise threat identification practices under applicable laws and guidance. You will research emerging...
- ...at We are seeking a Cybersecurity Incident and Application Lead to join our team and support our client. The ideal candidate is... ...network security, web application security, cloud technologies, and threat detection. This individual is motivated by protecting enterprise...Temporary workFor contractorsWork experience placementWork at officeRemote workFlexible hours2 days per week
- ...please visit us at We are seeking a Vulnerability Management Lead to join our team and support our client. The ideal candidate is... ...that account for exploitability, impact, asset criticality, and threat intelligence. Support automation, dashboarding, and process...Temporary workFor contractorsWork experience placementWork at officeRemote workFlexible hours2 days per week
$96.09k - $111.68k
...here.Role Overview:ID.me is seeking a highly experienced SOC Lead to play a pivotal role in our advanced security operations. As... ...ecosystem, bringing your deep expertise in incident response, threat hunting, and forensic analysis to the forefront. In this role, you will...Full timeTemporary workWork at officeRemote workFlexible hours- .... Make an impact by using your expertise to protect our country from threats. Job Description Ensure the safety and security of our nation as a Knowledge/Configuration Management (KM/CM) Lead at GDIT. You’ll apply the latest technology and provide operational support...
- ...Role Presidio has an exciting opportunity for a Security Practice Lead to join our Cybersecurity National Practice. The primary... ...DSS, etc. Broad experience and understanding of security trends, threat landscape, and frameworks like the cyber kill‑chain. Ability to...
- ...mission critical customer in Reston, VA. As the Incident Response Lead/Advisor, you will advise/mentor/coach a team of cyber security... ...~ Collaborating with IT and security teams to mitigate threats and prevent recurrence ~ Advising on security policies, risk...Full timeContract workTemporary workImmediate startShift work
$135k - $216k
...Capabilities Engineer (ACE) to serve as the primary technical proposal lead for National Geospatial-Intelligence Agency (NGA) opportunities.... ...at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The...Full timeContract workWork experience placementWork at officeImmediate startShift work$135k - $216k
...Capabilities Engineer (ACE) to serve as the primary technical proposal lead for National Reconnaissance Office (NRO) opportunities. This is... ...at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The...Full timeContract workFor contractorsWork experience placementWork at officeImmediate startShift work- Sprouts Farmers Market, Inc. is looking for an experienced Assistant Meat Manager to join their team in Herndon, Virginia. The role involves assisting in managing and merchandising for the Meat and Seafood department, ensuring excellent customer service and team leadership...
- ...Lead Security Systems Technician Active Security designs, develops, implements, and sustains advanced C5ISR and security solutions to enhance defense and mission capabilities, addressing threats across physical, electronic, cyber, and communications security for commercial...Night shift
- ...strategic initiatives. You will translate complex technical information for executive audiences through briefings and written products and lead staff and client relationships. Due to federal contracting, employees may handle Controlled Unclassified Information and must comply...
- ...is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role... .... Maintain currency in offensive tooling, TTPs, and emerging threat vectors Certifications: OSCP (minimum requirement) OSEP...Full time
$107.9k - $195.05k
...scale and repeatability. Leidos is seeking an Incident Response Lead to join our team on a highly visible cyber security single-award... ...to monitor, detect, analyze, mitigate, and respond to cyber threats and adversarial activity on the DHS Enterprise. The DHS SOC has...Local areaImmediate start$118.3k - $224.9k
...meet the needs of today’s mission and stay ahead of tomorrow’s threat. Our team solves tough, meaningful problems that create a safer,... ...Mission Applied Science & Technology (MAST) directorate is seeking a Lead Applied Imagery Scientist and Data Scientist with deep...Temporary workWork experience placementWork at officeLocal areaRemote workFlexible hours- ...Lead Structured Cabling Technician The Lead Structured Cabling Technician is responsible for overseeing the installation, maintenance, and testing of structured cabling systems for Wi-Fi Access Point (AP) installation projects. This role involves managing a team...For contractorsLocal area
$68.4k - $143.7k
...Quality Control Lead Join CACI as a Senior Quality/Continual Service Improvement (CSI) Lead in the Enterprise Communications Services 3 (ECS3) program, supporting our intel customer across various locations. Focus areas include design, transition, operations, and continual...Contract workWork experience placementFlexible hours$148.2k - $263k
...Forensics Lead Unlock the secrets of intelligence with MANTECH! Join a dynamic team at the forefront of national security, providing... ...to utilize a "kill chain" process to thwart Advanced Persistent Threats (APT). Key Responsibilities: Conduct remote imaging and...Hourly payContract workTemporary workWork experience placementWork at officeLocal areaRemote work- ...about our extraordinary teams building inspiring projects in our Impact Report . Job Summary: In this position, you will lead a Talent Acquisition team to ensure all staffing and recruitment targets are met. You will develop strong relationships with Senior...16 hoursPart timeWork experience placementWork at officeLocal areaRemote workRelocation
- ...national security missions worldwide. Job Description Overview SOSi is seeking a highly organized and detail-oriented Program Lead to join our team. As our Program Lead you will play a critical role in supporting our language service program for federal, state,...Permanent employmentContract workWork at officeLocal areaWorldwideNight shift
$21.27 - $27.18 per hour
...ratio of time spent on leadership duties and paraprofessional responsibilities will vary depending on the hospital situation; the Shift Lead must use good judgment in prioritizing their duties on any given day ,ensuring hospital productivity. On average, the ratio is...Hourly payMinimum wageFull timeTemporary workPart timeLocal areaFlexible hoursShift work$37.87 per hour
...A leading fitness coordination organization is seeking a Physical Fitness Coordinator in Reston, VA. This role involves leading on-site Physical Fitness Exams for the USPIS. Candidates should have a background in exercise science, hold a national fitness credential, and...Hourly payRelief- ...a friendly manner. You'll also ensure that the restaurant is a safe place for Team Members to work and customers to visit. Shift Lead behaviors include: Solving customer complaints quickly and with a smile. Providing feedback to Team Members in a positive manner...Shift work
- ...Talent Acquisition Lead ID 2026-3425 Category Human Resources Type Full Time Clearance TS/SCI w/ CI Poly Location US-VA- About GKG With a passion for excellence, Golden Key Group (GKG) helps clients solve their...Full timeContract work
$12.77 - $18.25 per hour
...Catering Lead At Panera At Panera, our people come first. If you're looking for a place where you can grow, feel supported, be yourself, enjoy great perks, and have a little fun along the way—you're in the right spot. We're here to help you succeed every day, in every...Full timeLocal areaFlexible hoursShift workNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Threat Hunt Lead (CBP). Be the first to apply!



