Security Operations Center Manager; CBP
Listed on 2026-09-12
-
IT/Tech
Cybersecurity
About Agile Defense
At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.
Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.
Title
:
Security Operations Center Manager
Clearance
:
Active Top Secret with SCI Eligibility, ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can begin processing for candidates who do not hold one.
Citizenship
: U.S. Citizenship required
Location
:
Reston, VA
- Hybrid 3 to 5 days
Salary Range
: $155,000-$185,000
Signing Bonus
: $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply.
Required Certification(s): CISSP, and one of the following: GCFA, GREM, GCIH, OSCP, GPEN, GFCE or equivalent preferred.
The RoleU.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. Every system that keeps that mission running, biometric checks against watchlists, apprehension processing, surveillance feeds, is also a target. An intrusion that goes undetected does not just risk data. It risks the same operational capability an outage would take down, except an adversary chose the timing.
You run the security operations center that watches for that. You own its people, process, and performance: how alerts get triaged, how work gets prioritized when everything looks urgent at once, and how the center performs as a whole rather than as a collection of individual analysts. You will work closely with the leads who run insider threat monitoring, threat hunting, incident response, digital forensics, and vulnerability assessment, and you are accountable for how well those functions work together, not just how well each one works alone.
One thing is worth knowing before you apply. A SOC that catches everything but cannot tell leadership what happened in terms they can act on has not actually done its job. Managing up and out is as much a part of this role as managing the floor.
What Success Looks LikeObjective 1:
Run a SOC that catches what matters and does not drown in what does not
- Alert volume gets triaged fast enough that a real incident does not sit in a queue behind noise.
- Analysts know what to elevate and what to close, and the standard for that decision is written down rather than tribal knowledge.
- Recurring false positives get tuned out at the source instead of re-triaged every shift.
Objective 2:
Make the SOC's specialist functions work as one operation
- Insider threat, threat hunt, incident response, forensics, and vulnerability assessment hand work to each other cleanly, without a finding stalling because nobody owned the next step.
- You can tell which function is under strain before it becomes the SOC's bottleneck.
- Coverage holds across shifts and gaps in staffing, rather than depending on who happens to be on duty.
Objective 3:
Give leadership an accurate picture of the SOC's performance and the program's exposure
- Reporting to leadership tells them what changed and what it means, not just a count of tickets closed.
- Risk that needs a decision above your level reaches that decision maker while there is still time to act on it.
- An incident's real severity and impact get communicated accurately the first time, not revised upward after the fact.
⠀Objective 4:
B…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).