Security Operations Center Manager (CBP)
Summary
Oversee a 24/7 security operations center for U.S. Customs and Border Protection, triaging alerts, coordinating incident response, and translating technical risks into leadership-ready reports.
The Role
What Success Looks Like
- Alert volume gets triaged fast enough that a real incident does not sit in a queue behind noise.
- Analysts know what to escalate and what to close, and the standard for that decision is written down rather than tribal knowledge.
- Recurring false positives get tuned out at the source instead of re-triaged every shift.
- Insider threat, threat hunt, incident response, forensics, and vulnerability assessment hand work to each other cleanly, without a finding stalling because nobody owned the next step.
- You can tell which function is under strain before it becomes the SOC's bottleneck.
- Coverage holds across shifts and gaps in staffing, rather than depending on who happens to be on duty.
- Reporting to leadership tells them what changed and what it means, not just a count of tickets closed.
- Risk that needs a decision above your level reaches that decision maker while there is still time to act on it.
- An incident's real severity and impact get communicated accurately the first time, not revised upward after the fact.
- Lessons from real incidents change how the SOC operates, not just what gets written in an after-action report.
- Analysts get better at their craft under you, not just busier.
- Standards and playbooks exist for the SOC's recurring work, and they get followed because they hold up under real conditions.
What You Bring
- Candidates will have a minimum of fice (5) years of direct operational and program management experience in delivery of Cybersecurity program or related projects.
- Candidates will have a minimum of seven (7) years of professional experience with a solid understanding of incident response, insider threat investigations, digital forensics, and cyber threats.
- Candidates for this role possess minimum of five (5) years of cybersecurity experience, with at least 5 years in a SOC leadership capacity.
- In-depth technical expertise in areas such as SIEM, EDR, and incident response methodologies is essential, coupled with a thorough understanding of network architectures and security controls.
- The ability to create insider threat focused dashboards, reports and workflow diagrams. Experience collecting data, chain of custody and reporting results; handling and escalating security issues or emergency situations appropriately; providing incident response capabilities to isolate and mitigate threats to maintain confidentiality, integrity, and availability for protected data.
- Experience with mentoring junior members in an open collaborative environment.
- Bachelor’s degree in computer science, engineering, STEM or cybersecurity
- One of the following certifications: GCFA, GREM, GCIH, OSCP, GPEN, GFCE or equivalent preferred.
- You have run a security operations center or an equivalent detection and response function, not only worked inside one as an analyst.
- You have managed a team through a real incident and can describe what you would do differently.
- You have reported security posture and incidents to non-technical leadership and can describe what changed in how you communicate because of it.
- You have worked inside a federal or highly regulated security program and know what that adds to the job beyond the technical work.
- You hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance. Any of these shortens your start date.
- You are comfortable across the disciplines your team covers, insider threat, threat hunting, incident response, forensics, and vulnerability assessment, even where you are not the deepest technical expert in each.
- Certifications such as CISSP, GCIH, or CISM are useful, but they are not a substitute for having run the function.
A note on timing
Employee Benefits
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company
- Are you authorized to work in the US? choose one
- What is your full street address? (Street, City, State, Zip)
- Are you open to relocating for this position, or another position with Agile Defense? choose one
- What is your desired salary?
- Are you a current employee of Agile Defense or any of its subsidiaries, affiliates, or acquired companies? choose one
- Have you ever been employed by Agile Defense or any of its subsidiaries, affiliates, or acquired companies? choose one
- How did you hear about us? choose one
- Do you have a higher education degree? choose one
- What is your highest level of education? choose one
- Do you have any active industry related certifications? choose one
- What active industry related certifications do you have? written answer
- Please upload a copy of your certification(s) if applicable upload · optional
- Are you a current or former U.S. Government employee or U.S. armed forces? choose one
- Are you currently subject to any post-employment obligations from a current or former employer that could restrict your ability to perform this role if hired? choose one
- If yes, please briefly describe the type of obligation and its duration (you may exclude employer names and confidential terms). If no, please respond with "N/A". written answer
- If hired, would you have any ongoing outside employment, consulting, or business activities that could conflict with this role or the company’s interests? written answer
- If yes, please briefly describe. If no, please respond with "N/A". written answer
- I certify that the information provided is accurate to the best of my knowledge and understand that additional details may be requested later in the hiring process. choose one
- Have you ever been employed, directly or indirectly, by U.S. Customs and Border Protection? choose one · optional
- Have you ever held an active CBP Background Investigation? choose one · optional
- Have you ever worked, directly or indirectly, for any other component of DHS other than CBP (i.e. ICE, TSA, USCIS, USCG, USSS, CISA, FEMA, FLETC). Check all that apply: yes / no · optional
- Have you ever successfully completed a DHS Suitability Investigation for any non-CBP component of DHS? choose one · optional
- Do you have a Department of Defense (DOD) Recognized Security Clearance? choose one
- What level of DOD clearance do you have? choose one

