Incident Response Team Lead (CBP) Job at Agile Defense, Reston, VA

  • Agile Defense
  • Reston, VA

Job Description

Job Description

Job Description

About Agile Defense

At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next.

Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.

Title : Incident Response Team Lead

Clearance : Active Top Secret with SCI eligibility, ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can begin processing for candidates who do not hold one.

Citizenship : U.S. Citizenship required

Location : Reston, VA - Hybrid 3 to 5 days

Salary Range : $155,000-180,000

Signing Bonus : $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply.

SUMMARY

Agile Defense is seeking experienced Cyber Incident Response Team Lead to support an enterprise cybersecurity program that delivers 24/7/365 Cybersecurity Operations Center (SOC) services. The IR team conducts security investigations for potential threat activity identified within the organization, conducts deep-dive forensic investigations (host-based, cloud and network), identify and implement countermeasures, as well as track and report on incident activity to USG customers. To support this vital mission, Agile Defense staff are on the forefront of providing Advanced CSOC Operations to include the development of advanced analytics and countermeasures to protect critical assets from various cyber threats. To ensure the integrity, security and resiliency of critical operations, we are seeking candidates with diverse backgrounds in cyber security systems operations, technical analysis and incident response lifecycle. A strong work ethic, diligent time and attendance, written and verbal communications skills are a must. The ideal candidate will have a solid understanding of cyber threats and information security in the domains of TTP’s, Threat Actors, Campaigns, and Observables. Additionally, the ideal candidate would be familiar with intrusion detection systems, intrusion analysis, security information event management platforms, endpoint threat detection tools, and security operations ticket management.

JOB DUTIES AND RESPONSIBILITIES

Drive the incident response lifecycle to include incident detection, analysis, escalation, and coordinated response across all CSOC functions. Develop and standardize incident response runbooks, playbooks, and communication protocols; ensure proper evidence handling and thorough documentation. Monitor and improve key performance metrics (MTTA/MTTR); capture lessons learned and implement corrective actions to strengthen future response efforts.

QUALIFICATIONS

Minimum required experience

  • Five (5) years of progressive professional experience in incident response role, SOC analyst role with emphasis in cyber security issues, incidents, hunts or digital forensics and operations, and computer incident response lifecycle.
  • Candidates must also exhibit proficient use of cyber tools, including but not limited to:
    • Security Information and Event Management (SIEM)
    • Network analysis
    • Live response
    • Endpoint detection and response tools
    • Intrusion Prevention / Detections Systems (IPS / IDS)
    • CSOC ticketing platforms

Required Certifications

  • Certified Information System Security Professional (CISSP) and
  • One or more of the following certifications:
    • GIAC Certified Intrusion Analyst (GCIA)
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Certified Forensic Analyst (GCFA)
    • SANS GIAC Certified Enterprise Defender (GCED)
    • Other Information Assurance Technician (IAT) Level III certification in accordance with DoD Directive 8570.1.

Education, Background, and Years of Experience

  • Bachelor of Science in computer science, engineering, STEM or cybersecurity IT or cyber security
  • Or eight (8) years of relevant work experience in lieu of a degree

Preferred Skills

  • One or more of the following:
    • GFCA
    • GPEN
    • GREM
    • GFNA
    • GIAC
  • Familiarity with Cloud environments

Our Core Values

Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together.

What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are.

  • Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
  • Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
  • Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
  • Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
  • Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
  • Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Job Tags

Work experience placement, Relocation package

Similar Jobs

USASJB

Work at Home - Remote Data Entry Clerk Job at USASJB

 ...Work From Home Survey Taker (Side Gig) We are looking for people who are motivated...  ...and in-person discussions. If you work remotely, there is no commute. No minimum hrs. This...  ...work is welcome to apply. No previous experience is necessary. This is an excellent opportunity... 

Radiant Industries

Senior Nuclear Engineer Job at Radiant Industries

 ...based startup building the worlds first mass-produced, portable nuclear microreactors. The companys first reactor, Kaleidos, is a 1-...  ...approach to nuclear development leverages modern software engineering to rapidly deliver safe, factory-built microreactors that use... 

Agile Defense

Technical Writer (CBP) Job at Agile Defense

 ...foundation of speed, flexibility, and ingenuity to strengthen and protect our nations vital interests. Title: Technical Writer (CBP) Clearance: Active CBP Background Investigation (CBP BI) and EOD strongly preferred. We can begin processing for candidates who do... 

URBN

Free People Temporary Assistant Print Designer Job at URBN

Free People is seeking an Assistant Print Designer to support the Textile team. This role plays a key part in the refinement and execution of seasonal prints by assisting in technical development, organization of artwork, ensuring all assets meet the standards and timelines... 

Link Up Overseas

Remote Data Entry Operator / Work from home - USA Job at Link Up Overseas

 ...Remote Data Entry Operator / Work from Home - USAPhiladelphia, PA, United StatesAbout the JobThis is your opportunity to start a durable career with...  ...breaks are offered from morning to evening and no experience is required.You will have a lot of opportunities for development...