Vulnerability Assessment (VA) Team Lead (CBP)

Agile DefenseAshburn, VA
Hybrid

About The Position

U.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. Every system supporting that mission has weaknesses somewhere, and the job is not to pretend otherwise. It is to find them before someone else does, and to make sure the ones that matter actually get fixed instead of sitting on a list nobody prioritizes. You lead vulnerability assessment for this program. You will run the scanning, assessment, and prioritization work that finds weaknesses across the environment, and you own getting real remediation out of that work rather than a report that lands and goes nowhere. You will coordinate closely with the network, cloud, and security engineering teams who fix what you find, and hand confirmed exploitable findings to the threat hunt and incident response leads when they need that context. One thing is worth knowing before you apply. A vulnerability scan is the easy part. What makes this role hard is getting busy engineering teams to prioritize a fix for something that has not caused a problem yet, and doing that without becoming the person everyone tunes out.

Requirements

  • Active CBP Background Investigation (CBP BI) and EOD strongly preferred.
  • U.S. Citizenship required.
  • Ability to lead vulnerability assessment or penetration testing work that produced findings engineering teams actually acted on.
  • Ability to prioritize findings by real exploitability rather than by scanner severity score alone.
  • Experience working in a federal or highly regulated environment.
  • Ability to get a team to fix something that had not caused a visible problem yet.
  • Hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance.
  • Certifications such as OSCP, GPEN, or equivalent are useful, but they are not a substitute for having driven real remediation.

Nice To Haves

  • We can begin processing for candidates who do not hold an active CBP BI.
  • We can begin processing a CBP BI for you if you do not hold one.

Responsibilities

  • Lead vulnerability assessment for the program.
  • Run scanning, assessment, and prioritization work to find weaknesses across the environment.
  • Ensure real remediation of identified weaknesses.
  • Coordinate with network, cloud, and security engineering teams.
  • Hand confirmed exploitable findings to threat hunt and incident response leads.
  • Prioritize findings by real exploitability and impact to the environment.
  • Ensure assessment coverage reaches critical systems.
  • Ensure critical findings are fixed and track the trend of closures.
  • Involve engineering teams in the remediation process when it's not obvious.
  • Trace recurring finding types to build standards or process gaps and close them at the source.
  • Ensure reported status of findings (open, in progress, accepted) matches reality.
  • Document accepted risk decisions with justification.
  • Provide leadership with an accurate picture of the environment's exposure.
  • Assess new systems and changes before they go live.
  • Improve assessment methodology based on real findings.
  • Identify areas with thin assessment coverage and determine what is needed to close those gaps.

Benefits

  • Health Insurance
  • Life Insurance
  • Paid Time Off
  • Holiday Pay
  • Short-term and long-term Disability
  • Retirement
  • Learning and Development opportunities
  • Other optional benefit elections
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service