Job Description
About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Title : Threat Hunt Lead (CBP)
Clearance : Active Top Secret with SCI eligibility, ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can begin processing for candidates who do not hold one.
Citizenship : U.S. Citizenship required
Location : Reston, VA - Hybrid
Salary Range : $165,000-200,000
Signing Bonus : $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply.
Required Certification(s) : GIAC, GCIH or CEH
The RoleU.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. The systems behind that mission are watched by automated detection around the clock, and automated detection only catches what it was built to catch. The gap between what a tool flags and what is actually happening in the environment is where a threat hunter works, and on a program supporting continuous federal law enforcement operations, that gap is not theoretical. You lead threat hunting for this program. You will form and test hypotheses about activity the SOC's existing detections might be missing, dig into the environment to confirm or rule them out, and turn what you find into detections other analysts can rely on going forward. You will work closely with the Security Operations Center Manager and hand confirmed findings to the incident response and digital forensics leads. One thing is worth knowing before you apply. Most hunts do not find anything, and that is not failure. A hunt that rules out a hypothesis honestly is doing its job. The people who do well here are comfortable being wrong most of the time in service of being right when it counts.
What Success Looks LikeObjective 1: Find what automated detection misses
Objective 2: Turn what you find into detection that outlives the hunt
Objective 3: Hand off findings clean enough to act on immediately
Objective 4: Keep the hunting program grounded in what actually threatens this environment
Minimum required experience
A minimum of five (5) years of experience as a Tier 3 senior cyber threat hunt analyst performing threat analysis, technical analysis, and network asset traversal.
A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes host and network-based security monitoring using cybersecurity capabilities.
Applicant will possess a strong cyber security background with experience in host and network-based forensics related to the identification of advanced cyber threat activities, intrusion detection, malware identification, and security content development (e.g., signatures, rules, queries etc.).
Shall have experience interpreting a variety of scripts or programming languages to support cyber threat hunts or malware analysis in a variety of formats, such as VB scripts, Python, PowerShell, JavaScript, and HTML, XML or other types needed for analysis.
Candidates will have experience in conducting cyber threat hunt analysis, utilizing cyber threat intelligence to identify and prioritize tactics, techniques, and procedures to hunt against.
Have a deep knowledge of capabilities and experience with security information and event management (SIEM) and networked-device management tools such as Splunk and EDR solutions.
Candidates will have experience in maintaining a comprehensive understanding of the cyber threat landscape, including identifying and analyzing cyber threats actors and activities to enhance cybersecurity posture of the organization’s IT operating environment.
Will work with the Cyber Threat Intelligence team to report significant findings of importance to leadership as well as coordinate with Pentest team and asset owners to deconflict findings.
Candidate will lead the Cyber Threat Hunt team to propose corrective actions and inform the necessary parties of security issues, reportable offenses, or cybersecurity best practices.
Candidate will have strong written and oral communication skills
Preferred Experience
We are staffing this program now. If you already hold an active CBP BI and EOD, your start date is short and a $10,000 signing bonus comes with the role, payable after 90 days under standard terms. We would like to talk this week. If you do not, we can begin processing a CBP BI for you. That takes months rather than weeks, so applying now means joining a pipeline rather than starting immediately. We would rather tell you that up front than have you find out after you apply.
Employee BenefitsAgile's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections.
Our Core Values
Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.
What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
...Reading Specialist (6-8) Employment Status: Full-time; 10-Month - FLSA Status: Salary The management services offered to our family of charter schools, allows us to collectively become a change agent and national leader in urban education as evidenced by student...
...Pre-Owned Vehicle Sales Manager Become a Rusnak! Join Rusnak Auto Group, a leading automotive organization with over 60 years of... ...~ Competitive Pay ~ Comprehensive Health Coverage (Medical, Dental, Vision, Life, LTD) ~ Employee Assistance Program ~401(k) Retirement...
...The Economic Studies Program at the Brookings Institution is conducting our fall Research Assistant recruitment, for positions starting in summer 2027. We are recruiting for approximately ten research assistants for two-year appointments, preferably beginning between June...
...Risus Talent Partners is partnering with an established medical device manufacturer to hire a Sales Representative for its Elizabeth, New Jersey territory .The Sales Representative will sell products directly to hospitals and manage sales activity across an assigned...
...Caregiver Memory Care Location Served: Wauwatosa and surrounding areas Pay: $15$17/hr | Flexible Schedules | Bi-Weekly Pay... ...Aide (HHA) for a part-time position supporting a client with dementia in a one-on-one home setting. Why Caring Senior Service Caring...