Insider Threat Monitoring Lead (CBP)

Agile DefenseAshburn, VA
Hybrid

About The Position

U.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. The systems behind that mission hold sensitive law enforcement and personal data, and the people with legitimate access to it are, by definition, trusted. Most of the damage an insider threat program exists to catch does not come from a sophisticated outside attacker. It comes from someone who already has the access, and the work is telling the difference between normal use and misuse without treating every employee as a suspect. You lead that function. You will build and run the monitoring, analysis, and escalation process that catches insider risk early, working closely with the Security Operations Center Manager, human resources and security partners, and the incident response and digital forensics leads when a case moves from monitoring to action. One thing is worth knowing before you apply. This work carries real privacy and proportionality weight. Getting it wrong in either direction, missing real risk or treating ordinary behavior as suspicious, costs the program trust it needs to keep doing the job.

Requirements

  • Active CBP Background Investigation (CBP BI) and EOD strongly preferred. We can begin processing for candidates who do not hold one.
  • U.S. Citizenship required
  • Comfortable working closely with human behavior data and understand the privacy and legal boundaries around it, not only the technical monitoring tools.

Nice To Haves

  • Run or been a senior analyst in an insider threat program, ideally in a federal or cleared environment where NITTF-aligned or equivalent standards applied.
  • Handled a case that involved coordination with HR, legal, or security partners, and can describe how you kept it proportional.
  • Tuned detection logic based on real case outcomes rather than left it as originally configured.
  • Can explain a sensitive finding to people outside the program in terms they can act on without oversharing what they should not see.
  • Hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance.

Responsibilities

  • Build and run the monitoring, analysis, and escalation process that catches insider risk early.
  • Work closely with the Security Operations Center Manager, human resources and security partners, and the incident response and digital forensics leads when a case moves from monitoring to action.
  • Ensure monitoring stays proportional to actual risk indicators rather than expanding because it is easy to collect more data.
  • Handle cases consistently regardless of who the subject is.
  • Ensure cases that move to investigation or incident response arrive with a record that the next team can act on immediately.
  • Identify findings that reveal a systemic gap, not just an individual case, and reach the people who can fix the gap.
  • Tune detection logic based on what real cases actually looked like, rather than leaving it static after initial setup.
  • Improve what the program watches for over time based on near misses and lessons learned.
  • Honestly explain the program's current blind spots, rather than presenting coverage as complete.

Benefits

  • Health Insurance
  • Life Insurance
  • Paid Time Off
  • Holiday Pay
  • short-term and long-term Disability
  • Retirement
  • Learning and Development opportunities
  • other optional benefit elections
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service