Security Operations Center Manager (CBP)

Agile DefenseAshburn, VA
Onsite

About The Position

The U.S. Customs and Border Protection (CBP) runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. Every system that keeps that mission running, from biometric checks against watchlists to apprehension processing and surveillance feeds, is a potential target. An undetected intrusion risks not just data, but operational capability. This role involves managing the security operations center responsible for monitoring these systems, focusing on its people, process, and performance. Key aspects include how alerts are triaged, how work is prioritized during high-urgency situations, and the overall performance of the center. The manager will collaborate closely with leads for insider threat monitoring, threat hunting, incident response, digital forensics, and vulnerability assessment, ensuring these functions work cohesively. A critical part of the role is communicating the SOC's performance and the program's exposure to leadership in an actionable manner.

Requirements

  • Active CBP Background Investigation (CBP BI) and EOD strongly preferred (processing can begin for candidates without one).
  • U.S. Citizenship required.
  • Experience running a security operations center or an equivalent detection and response function.
  • Experience managing a team through a real incident.
  • Experience reporting security posture and incidents to non-technical leadership.
  • Experience working within a federal or highly regulated security program.
  • Comfort across disciplines including insider threat, threat hunting, incident response, forensics, and vulnerability assessment.

Nice To Haves

  • Active CBP BI, a fitness determination at another DHS component, or an active DoD clearance.
  • Certifications such as CISSP, GCIH, or CISM.

Responsibilities

  • Run a SOC that catches what matters and does not drown in what does not.
  • Ensure alert volume is triaged fast enough that real incidents are not delayed by noise.
  • Define clear standards for analysts to escalate or close alerts, moving beyond tribal knowledge.
  • Tune out recurring false positives at the source.
  • Make the SOC's specialist functions (insider threat, threat hunt, incident response, forensics, vulnerability assessment) work as one operation.
  • Ensure seamless handoffs between functions and identify potential bottlenecks before they impact the SOC.
  • Maintain coverage across shifts and staffing gaps.
  • Provide leadership with an accurate picture of the SOC's performance and the program's exposure.
  • Communicate changes and their implications to leadership, not just ticket counts.
  • Ensure risks requiring decisions above the SOC level reach the appropriate decision-makers in a timely manner.
  • Accurately communicate an incident's real severity and impact.
  • Build a SOC that continuously improves its performance.
  • Incorporate lessons from incidents to change SOC operations.
  • Develop analysts' skills over time.
  • Establish and enforce standards and playbooks for recurring SOC work.

Benefits

  • Health Insurance
  • Life Insurance
  • Paid Time Off
  • Holiday Pay
  • Short-term and long-term Disability
  • Retirement
  • Learning and Development opportunities
  • Other optional benefit elections
  • $10,000 signing bonus for candidates with an active CBP BI (Payable after 90 days; standard terms apply).
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service