×
Register Here to Apply for Jobs or Post Jobs. X

Security Operations Center Manager (CBP

Job in Ashburn, Loudoun County, Virginia, 22011, USA
Listing for: Agile Defense
Full Time position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 120000 - 150000 USD Yearly USD 120000.00 150000.00 YEAR
Job Description & How to Apply Below

About Agile Defense

At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.

Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

Title:

Security Operations Center Manager

Clearance:
Active CBP Background Investigation (CBP BI) and EOD strongly preferred. We can begin processing for candidates who do not hold one.

Citizenship: U.S. Citizenship required

Location:

Ashburn, VA

Salary Range: [Pending]

Signing Bonus: $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply.

Travel:
As needed

The Role

U.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. Every system that keeps that mission running, biometric checks against watchlists, apprehension processing, surveillance feeds, is also a target. An intrusion that goes undetected does not just risk data. It risks the same operational capability an outage would take down, except an adversary chose the timing.

You run the security operations center that watches for that. You own its people, process, and performance: how alerts get triaged, how work gets prioritized when everything looks urgent at once, and how the center performs as a whole rather than as a collection of individual analysts. You will work closely with the leads who run insider threat monitoring, threat hunting, incident response, digital forensics, and vulnerability assessment, and you are accountable for how well those functions work together, not just how well each one works alone.

One thing is worth knowing before you apply. A SOC that catches everything but cannot tell leadership what happened in terms they can act on has not actually done its job. Managing up and out is as much a part of this role as managing the floor.

What Success Looks Like

Objective 1:
Run a SOC that catches what matters and does not drown in what does not

  • Alert volume gets triaged fast enough that a real incident does not sit in a queue behind noise.
  • Analysts know what to escalated and what to close, and the standard for that decision is written down rather than tribal knowledge.
  • Recurring false positives get tuned out at the source instead of re-triaged every shift.

Objective 2:
Make the SOC's specialist functions work as one operation

  • Insider threat, threat hunt, incident response, forensics, and vulnerability assessment hand work to each other cleanly, without a finding stalling because nobody owned the next step.
  • You can tell which function is under strain before it becomes the SOC's bottleneck.
  • Coverage holds across shifts and gaps in staffing, rather than depending on who happens to be on duty.

Objective 3:
Give leadership an accurate picture of the SOC's performance and the program's exposure

  • Reporting to leadership tells them what changed and what it means, not just a count of tickets closed.
  • Risk that needs a decision above your level reaches that decision maker while there is still time to act on it.
  • An incident's real severity and impact get communicated accurately the first time, not revised upward after the fact.

Objective 4:
Build a SOC that gets better at its job over time

  • Lessons from real incidents change how the SOC operates, not just what gets written in an after-action report.
  • Analysts get better at their craft under you, not just busier.
  • Standards and playbooks exist for the SOC's recurring work, and they get followed because they hold up under real conditions.
What You Bring

Preferred Experience

  • You have run a security operations center or an equivalent detection and response function, not only worked inside one as an analyst.
  • You have managed a team through a real incident and can describe what you would do differently.
  • You have reported security posture and incidents to non-technical leadership and can describe what changed in how you communicate because of it.
  • You have worked inside a federal or highly regulated security program and know what that adds to the job beyond the technical work.
  • You hold an active CBP BI, a fitness determination at another DHS…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary