
Real job — pulled straight from Agile Defense’s careers page · Verified August 30, 2026 · No reposts.
Job description
Agile Defense is hiring a Digital Forensics Lead — a full-time, based in Reston, VA role ($155k–$175k). Apply directly on Agile Defense's careers page below.
Digital Forensics Lead (CBP)
Team: Cybersecurity
Location: Reston, VA
Commitment: Regular
Workplace Type: hybrid
The Role
What Success Looks Like
- Evidence handling follows chain of custody every time, not only when a case looks like it will matter.
- Your process would survive being challenged by someone whose job is to find the flaw in it.
- Nothing you needed for an analysis is missing because it was not preserved in time.
- Your analysis answers the question that was actually asked, not the version of it that was easiest to investigate.
- Where evidence is ambiguous, you say so rather than rounding up to a conclusion the evidence does not fully support.
- Timelines you build reconcile activity across systems rather than describing one system in isolation.
- Incident response, threat hunt, and insider threat monitoring get findings framed for what they need to act, not a raw technical dump.
- Findings that support disciplinary, legal, or law enforcement action are documented to the standard those processes require.
- You can explain a technical finding to a non-technical decision maker without losing what matters about it.
- Case types that recur get a faster, more consistent process each time, not reinvestigated from scratch.
- Tooling and technique choices get reviewed against what actually worked in real cases.
- Lessons from a case change the program's practice, not just that one investigation.
What You Bring
- Candidates will have a minimum of seven (7) years of professional experience with a solid understanding of incident response, insider threat investigations, digital forensics, and cyber threats.
- A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes bare metal, cloud or virtual system-based and network-based security monitoring, identifying and analyzing anomalous activities with familiarity in insider threat monitoring software, endpoint forensic tools, intrusion detection systems, intrusion analysis functions, security information event management (SIEM) platforms, endpoint detection and response tools, security operations ticket management.
- The ability to create insider threat focused dashboards, reports and workflow diagrams.
- Experience collecting data, chain of custody and reporting results; handling and escalating security issues or emergency situations appropriately; providing incident response capabilities to isolate and mitigate threats to maintain confidentiality, integrity, and availability for protected data.
- Applicant will have excellent written and oral communication skills, be able to work independently and as part of a team. Willingness and experience with mentoring junior members in an open collaborative environment.
- Bachelor’s degree in computer science, Engineering, STEM, Information Technology, or Cybersecurity
-
GCFA, GREM, GFCE, GNFA, GIME, GASF, GX-FA, Encase, Cellebrite or equivalent preferred.
-
Mobile Forensics
- You have led digital forensic investigations that produced findings used for disciplinary, legal, or law enforcement action, not only internal analysis.
- You can describe how you maintain chain of custody and why it matters for a finding to hold up.
- You have worked forensics in a federal or highly regulated environment and know what that adds to evidentiary standards.
- You have delivered a forensic finding to a non-technical audience, legal, HR, or leadership, and can describe how you framed it.
- You hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance. Any of these shortens your start date.
- Certifications such as GCFE, GCFA, or EnCE are useful, but they are not a substitute for having produced findings that held up.
A note on timing
Employee Benefits
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Get Digital Forensics Lead jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs
Frequently asked questions
What is the salary for Digital Forensics Lead at Agile Defense?
The estimated salary range for Digital Forensics Lead at Agile Defense is $155,000 - $175,000 USD per year.
What skills are required for Digital Forensics Lead at Agile Defense?
The required skills for Digital Forensics Lead at Agile Defense include: Cybersecurity, SIEM.
What is the seniority level for Digital Forensics Lead at Agile Defense?
Digital Forensics Lead at Agile Defense is a Senior / Manager level position.
How do I apply for Digital Forensics Lead at Agile Defense?
You can view the full description and apply for Digital Forensics Lead at Agile Defense on EchoJobs: https://echojobs.io/job/agile-defense-digital-forensics-lead-cbp-f7g0h.

