Security Operations Center Manager (CBP)
Agile Defense - Reston, VA
Hiring: Security Operations Center Manager (CBP) Company: Agile Defense Location: Reston, VA Job Posted Time: 2026-09-09 18:06:44 Employment Type: Hybrid Target Skills & Keywords : Agile, Make, Objective-C, SOC, Sentry About the job Required Skills: •U.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. Every system that keeps that mission running, biometric checks against watchlists, apprehension processing, surveillance feeds, is also a target. An intrusion that goes undetected does not just risk data. It risks the same operational capability an outage would take down, except an adversary chose the timing. •You run the security operations center that watches for that. You own its people, process, and performance: how alerts get triaged, how work gets prioritized when everything looks urgent at once, and how the center performs as a whole rather than as a collection of individual analysts. You will work closely with the leads who run insider threat monitoring, threat hunting, incident response, digital forensics, and vulnerability assessment, and you are accountable for how well those functions work together, not just how well each one works alone. •One thing is worth knowing before you apply. A SOC that catches everything but cannot tell leadership what happened in terms they can act on has not actually done its job. Managing up and out is as much a part of this role as managing the floor. •What Success Looks Like •Objective 1: Run a SOC that catches what matters and does not drown in what does not •Alert volume gets triaged fast enough that a real incident does not sit in a queue behind noise •Analysts know what to escalate and what to close, and the standard for that decision is written down rather than tribal knowledge •Recurring false positives get tuned out at the source instead of re-triaged every shift •Objective 2: Make the SOC's specialist functions work as one operation •Insider threat, threat hunt, incident response, forensics, and vulnerability assessment hand work to each other cleanly, without a finding stalling because nobody owned the next step •You can tell which function is under strain before it becomes the SOC's bottleneck •Coverage holds across shifts and gaps in staffing, rather than depending on who happens to be on duty •Objective 3: Give leadership an accurate picture of the SOC's performance and the program's exposure •Reporting to leadership tells them what changed and what it means, no Compensation: •: $155,000-$185,000 •Signing Bonus •: $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply. •Required Certification(s) •: CISSP, and one of the following: GCFA, GREM, GCIH, OSCP, GPEN, GFCE or equivalent preferred. Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!