
Real job — pulled straight from Agile Defense’s careers page · Verified August 30, 2026 · No reposts.
Job description
Agile Defense is hiring a Threat Hunt Lead — a full-time, based in Reston, VA role ($165k–$200k). Apply directly on Agile Defense's careers page below.
Threat Hunt Lead (CBP)
Team: Cybersecurity
Location: Reston, VA
Commitment: Regular
Workplace Type: hybrid
The Role
U.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. The systems behind that mission are watched by automated detection around the clock, and automated detection only catches what it was built to catch. The gap between what a tool flags and what is actually happening in the environment is where a threat hunter works, and on a program supporting continuous federal law enforcement operations, that gap is not theoretical. You lead threat hunting for this program. You will form and test hypotheses about activity the SOC's existing detections might be missing, dig into the environment to confirm or rule them out, and turn what you find into detections other analysts can rely on going forward. You will work closely with the Security Operations Center Manager and hand confirmed findings to the incident response and digital forensics leads. One thing is worth knowing before you apply. Most hunts do not find anything, and that is not failure. A hunt that rules out a hypothesis honestly is doing its job. The people who do well here are comfortable being wrong most of the time in service of being right when it counts.
What Success Looks Like
Objective 1: Find what automated detection misses
- Hunts are grounded in a real hypothesis about adversary behavior, not a general look around for anything unusual.
- Confirmed findings represent activity that existing detections did not catch, which is the actual measure of whether hunting is adding value beyond the SOC's standing tools.
- You can explain why you ruled a hypothesis out, not just report that you did.
Objective 2: Turn what you find into detection that outlives the hunt
- Confirmed findings become new detection logic, so the next occurrence gets caught automatically instead of requiring another manual hunt.
- Detection you build gets tuned as conditions change, rather than left as originally written.
- Other analysts can use what you built without needing you to explain it every time.
Objective 3: Hand off findings clean enough to act on immediately
- When a hunt confirms real activity, incident response gets a finding they can act on without redoing your investigative work.
- Evidence and context are preserved well enough that digital forensics can pick up where you left off if a case needs that depth.
- You know when a finding needs to escalate now versus when it can go through standard reporting.
Objective 4: Keep the hunting program grounded in what actually threatens this environment
- Hunt hypotheses reflect the tactics that matter for a federal law enforcement environment, not a generic threat list.
- Threat intelligence gets translated into hunts that are specific enough to test, not left as a general awareness exercise.
- You can say what you have not hunted for yet and why, rather than presenting coverage as complete.
What You Bring
Minimum required experience
- One of the folowing certificatations: GCIA, GCIH or GFCA OR CEH
-
A minimum of five (5) years of experience as a Tier 3 senior cyber threat hunt analyst performing threat analysis, technical analysis, and network asset traversal.
-
A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes host and network-based security monitoring using cybersecurity capabilities.
-
Applicant will possess a strong cyber security background with experience in host and network-based forensics related to the identification of advanced cyber threat activities, intrusion detection, malware identification, and security content development (e.g., signatures, rules, queries etc.).
-
Shall have experience interpreting a variety of scripts or programming languages to support cyber threat hunts or malware analysis in a variety of formats, such as VB scripts, Python, PowerShell, JavaScript, and HTML, XML or other types needed for analysis.
-
Candidates will have experience in conducting cyber threat hunt analysis, utilizing cyber threat intelligence to identify and prioritize tactics, techniques, and procedures to hunt against.
-
Have a deep knowledge of capabilities and experience with security information and event management (SIEM) and networked-device management tools such as Splunk and EDR solutions.
-
Candidates will have experience in maintaining a comprehensive understanding of the cyber threat landscape, including identifying and analyzing cyber threats actors and activities to enhance cybersecurity posture of the organization’s IT operating environment.
-
Will work with the Cyber Threat Intelligence team to report significant findings of importance to leadership as well as coordinate with Pentest team and asset owners to deconflict findings.
-
Candidate will lead the Cyber Threat Hunt team to propose corrective actions and inform the necessary parties of security issues, reportable offenses, or cybersecurity best practices.
-
Candidate will have strong written and oral communication skills
Preferred Experience
- Additional certifications such as: GFCA, GREM, GFNA,OSCP, GPEN
- You have led or performed structured threat hunting, using a framework such as MITRE ATT&CK to form and test hypotheses, not only reviewed alerts as they arrived.
- You have turned a hunt finding into a production detection and can describe the process.
- You have worked in an environment defending against threats targeting government or law enforcement data, not only general commercial risk.
- You are comfortable working from incomplete or ambiguous signals and can describe how you decide when a hypothesis is worth pursuing.
- You hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance. Any of these shortens your start date.
- Certifications such as GCFA, GNFA, or equivalent are useful, but they are not a substitute for having found something real.
A note on timing
We are staffing this program now. If you already hold an active CBP BI and EOD, your start date is short and a $10,000 signing bonus comes with the role, payable after 90 days under standard terms. We would like to talk this week. If you do not, we can begin processing a CBP BI for you. That takes months rather than weeks, so applying now means joining a pipeline rather than starting immediately. We would rather tell you that up front than have you find out after you apply.
Employee Benefits
Agile's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections.
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
Get Threat Hunt Lead jobs like this→
New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.
Email me new jobsSimilar jobs

Software Engineer, Tooling and Development Infrastructure



Senior Engineer - Cloud Operations (Remote)
Frequently asked questions
What is the salary for Threat Hunt Lead at Agile Defense?
The estimated salary range for Threat Hunt Lead at Agile Defense is $165,000 - $200,000 USD per year.
What skills are required for Threat Hunt Lead at Agile Defense?
The required skills for Threat Hunt Lead at Agile Defense include: Splunk, Python, PowerShell, JavaScript, HTML, XML.
What is the seniority level for Threat Hunt Lead at Agile Defense?
Threat Hunt Lead at Agile Defense is a Senior / Manager level position.
How do I apply for Threat Hunt Lead at Agile Defense?
You can view the full description and apply for Threat Hunt Lead at Agile Defense on EchoJobs: https://echojobs.io/job/agile-defense-threat-hunt-lead-cbp-m7e2w.