Threat Hunt Lead (CBP)

Agile Defense
United States
Workplace: HybridFull timeFunction: Administration & Executive AssistanceSkills: ["Hypothesis-driven thinking","Investigative judgment","Clear communication"]

Lead structured threat hunting for a U.S. Customs and Border Protection program, focusing on the gap between automated detections and real adversary activity. Form and test MITRE ATT&CK–grounded hypotheses, investigate ambiguous signals, and convert confirmed findings into durable production detection logic. Partner with the SOC manager and hand off actionable results to incident response and digital forensics while keeping hunts grounded in the threats relevant to a federal law enforcement environment.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Agile Defense
Agile Defense
4 days ago

Threat Hunt Lead (CBP)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 17 hours agoStatus: Live

Job Summary

Lead structured threat hunting for a U.S. Customs and Border Protection program, focusing on the gap between automated detections and real adversary activity. Form and test MITRE ATT&CK–grounded hypotheses, investigate ambiguous signals, and convert confirmed findings into durable production detection logic. Partner with the SOC manager and hand off actionable results to incident response and digital forensics while keeping hunts grounded in the threats relevant to a federal law enforcement environment.
Location: United States
Workplace: Hybrid
Employment Type: Full time
Job Function: Administration & Executive Assistance

Key Responsibilities

  • •Lead threat hunting by forming and testing hypotheses about activity SOC detections may miss.
  • •Investigate the environment to confirm or rule out suspicious behavior and explain why hypotheses were ruled out.
  • •Convert confirmed findings into detection logic so future activity is caught automatically.
  • •Tune detection as conditions change and make outputs usable for other analysts.
  • •Hand off confirmed findings cleanly to incident response and digital forensics with preserved evidence and context.
Travel: Low travel

Pay and Benefits

Perks:Health InsuranceLife InsurancePaid LeaveHoliday PayDisabilityRetirementLearning Budget

Key Requirements

  • •Hold an active CBP BI (or equivalent DHS component fitness determination) and EOD; otherwise be able to begin CBP BI processing.
  • •Have led/performed structured threat hunting using a framework such as MITRE ATT&CK to form and test hypotheses.
  • •Be able to turn threat-hunt findings into production detection logic and describe the process.
  • •Have experience defending against threats targeting government or law enforcement data.
  • •Be comfortable working from incomplete or ambiguous signals and deciding when a hypothesis is worth pursuing.
Skills:Hypothesis-driven thinkingInvestigative judgmentClear communication
Certifications:GCFAGNFA
Tech Stack:MITRE ATT&CK

Eligibility

Nationality:US National
Security Clearance:CBP Background Investigation (CBP BI)EOD

Company Brief

Agile Defense
Provides cybersecurity services including managed detection and response, incident response, vulnerability assessments, and security operations to help organizations detect, respond to, and remediate cyber threats while meeting regulatory and compliance requirements.
Industry: Cybersecurity
Website