--- title: 'Insider Threat Monitoring Lead (CBP) at Agile Defense' canonical: 'https://feeny.ai/job/insider-threat-monitoring-lead-cbp-agile-defense-reston-g6xrrdmqafmf' type: 'job' last_seen: '2026-09-13' --- # Insider Threat Monitoring Lead (CBP) at Agile Defense - **Company:** Agile Defense - **Location:** Reston, VA - **Compensation:** $155k–$185k - **Work type:** hybrid - **Posted:** 2026-08-18 - **Last confirmed live:** 2026-09-13 - **Apply:** https://jobs.lever.co/agile-defense/f8ddce84-bed3-491a-a521-482a0ff90bd4 ## Job description ## About Agile Defense At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests. Title: Insider Threat Monitoring Lead (CBP) Clearance: Active Top Secret with SCI Eligibility, and ability to obtain CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can begin processing for candidates who do not hold one. Citizenship: U.S. Citizenship required Location: Reston, VA - Hybrid, 3-5 days onsite Salary Range: $160,000-$185,000 Signing Bonus: $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply. Travel: Rare, as needed Required Certification(s): Active CISSP ## The Role U.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. The systems behind that mission hold sensitive law enforcement and personal data, and the people with legitimate access to it are, by definition, trusted. Most of the damage an insider threat program exists to catch does not come from a sophisticated outside attacker. It comes from someone who already has the access, and the work is telling the difference between normal use and misuse without treating every employee as a suspect. You lead that function. You will build and run the monitoring, analysis, and escalation process that catches insider risk early, working closely with the Security Operations Center Manager, human resources and security partners, and the incident response and digital forensics leads when a case moves from monitoring to action. One thing is worth knowing before you apply. This work carries real privacy and proportionality weight. Getting it wrong in either direction, missing real risk or treating ordinary behavior as suspicious, costs the program trust it needs to keep doing the job. What Success Looks Like Objective 1: Catch real insider risk without drowning in noise Cases that escalate to investigation are the ones that warrant it, not everything that triggered an alert. Patterns that matter, unusual access, data movement, or behavior change, get identified before they become an incident rather than after. Analysts working under you can explain why a case escalated in terms someone outside the program would find reasonable. Objective 2: Run the program in a way people can trust is fair Monitoring stays proportional to actual risk indicators rather than expanding because it is easy to collect more data. Cases get handled consistently regardless of who the subject is. When a case does not substantiate, it closes cleanly rather than leaving a lingering question mark on someone's record. Objective 3: Hand off cleanly when a case becomes something else Cases that move to investigation or incident response arrive with a record that the next team can act on immediately, not one they have to reconstruct. You know where insider threat monitoring's job ends and where forensics or HR involvement begins, and you do not sit on a case past that line. Findings that reveal a systemic gap, not just an individual case, reach the people who can fix the gap. Objective 4: Improve what the program watches for over time Detection logic gets tuned based on what real cases actually looked like, not left static after initial setup. Near misses and lessons learned change what the program monitors going forward. You can explain the program's current blind spots honestly, rather than presenting coverage as complete. ## What You Bring ## Minimum Required Experience Minimum of five (5) years of professional experience leading the cyber component of an insider threat program An in-depth understanding of the principles, methodologies, and best practices for establishing, operating, and maturing an insider threat program. Active Certified Information Systems Security Professional (CISSP) Bachelor’s degree in computer science, Engineering, STEM, Information Technology, or Cybersecurity ## Preferred Experience You have run or been a senior analyst in an insider threat program, ideally in a federal or cleared environment where NITTF-aligned or equivalent standards applied. You have handled a case that involved coordination with HR, legal, or security partners, and can describe how you kept it proportional. You have tuned detection logic based on real case outcomes rather than left it as originally configured. You can explain a sensitive finding to people outside the program in terms they can act on without oversharing what they should not see. You hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance. Any of these shortens your start date. You are comfortable working closely with human behavior data and understand the privacy and legal boundaries around it, not only the technical monitoring tools. Counter-intelligence experience Digital Forensics and related certifications User Activity Monitoring (UAM) User Behavior Analytics (UBA) A note on timing We are staffing this program now. If you already hold an active CBP BI and EOD, your start date is short and a $10,000 signing bonus comes with the role, payable after 90 days under standard terms. We would like to talk this week. If you do not, we can begin processing a CBP BI for you. That takes months rather than weeks, so applying now means joining a pipeline rather than starting immediately. We would rather tell you that up front than have you find out after you apply. Employee Benefits Agile's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections. Our Core Values Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together. What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are. Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do. Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated. Honest - Be Trustworthy.Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support. Humble - Be Grounded.Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task. Hungry - Be Eager.Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges. Hustle - Be Driven.Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities ## About Agile Defense ## Company Overview - **One-liner**: Agile Defense delivers advanced digital transformation, data analytics, and cybersecurity solutions to support critical national security and civilian missions. - **Entity Type**: Private (owned by Enlightenment Capital; last private equity round in November 2022) - **Headquarters**: McLean, Virginia, United States - **Founded**: Year not publicly available - **Founders**: Not publicly available ## Core Business - **Primary industries**: IT Services and IT Consulting, National Security, Defense, Civilian Government - **Target customers**: U.S. federal government (defense and civilian agencies), B2G (business-to-government) - **Mission/Purpose**: “Bring adaptive innovation to support our nation’s most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility.” ## Products & Services - **Digital Transformation**: Applying advanced services, capabilities, and solutions securely to enhance mission operations and achieve optimal outcomes. - **Data Analytics**: Leveraging a data-driven approach to deliver insights that accelerate decision-making. - **Cyber**: Delivering Cyber Systems and Cyber Operations capabilities to defend against advanced and emerging cyber threats. ## Market Standing - **Valuation/Market Cap**: Not disclosed (private company) - **Key Metric**: Annual revenue of $110M (as of latest data); 816 employees ( -7.4% YoY) - **Notable Investors/Partners**: - **Investor**: Enlightenment Capital (private equity sponsor) - **Partners**: AWS, Microsoft, Atlassian, ServiceNow, Snowflake, CrowdStrike, Splunk, Red Hat, GitLab, and many more. - **Growth Signals**: - Headcount declined 7.4% year-over-year, but job postings increased 133.9% year-over-year. - Active job postings: 131 (as of Sep 2026). - Recognized as Washington Post Top Work Places 2023, 2024, and 2026. - ISO 9001, ISO 20000-1, ISO 27001 certified; CMMI DEV/SVC ML3 appraised. ## Competitive Advantages - **Certifications & Compliance**: ISO 9001, 20000-1, 27001; CMMI ML3; critical for government contracts. - **Extensive Partner Ecosystem**: Ties with major cloud/platform providers (AWS, Microsoft, ServiceNow, etc.) and security vendors (CrowdStrike, Splunk, Recorded Future). - **Mission Focus**: Deep expertise in national security and civilian missions, with global presence (North America, Europe, Asia, Middle East). - **Award-Winning Culture**: Consecutive Washington Post Top Workplaces recognition reinforces employer brand. ## Strategic Focus - Scaling digital transformation, data analytics, and cyber capabilities for U.S. government clients. - Investing in innovation through “Agile Labs” and research. - Expanding hiring in key technical areas (Data Scientist, Splunk Architect, Cyber Incident Handler, AI SME). ## Why Work Here - **Culture**: Emphasizes teamwork, collaboration, and “elite teams” working on high-impact national security projects. - **Work Policy**: Some roles are listed as “Remote – Regular Remote” (e.g., certain positions on Lever job board), but many roles likely require clearance and on-site work. - **Benefits**: Competitive health plans, education and certification reimbursement, paid parental leave, PTO, fitness reimbursement, employee assistance program, referral bonuses up to $2,500. - **Recognition**: Washington Post Top Work Places 2023, 2024, 2026; Glassdoor rating 3.9/5 (287 reviews) with work-life balance 4.1/5. - **Professional Development**: Knowledge-sharing sessions, team-building activities, ongoing training. ## Sources 1. [Agile Defense About Page](https://agiledefense.com/about/) 2. [Agile Defense LinkedIn](https://linkedin.com/company/agiledefense) 3. [Agile Defense Careers Page](https://agiledefense.com/careers/) 4. [Agile Defense Open Positions (Lever)](https://jobs.lever.co/agile-defense) ## Other roles at Agile Defense - [Intelligence Analyst SME (National Security Mission Support)](https://feeny.ai/job/intelligence-analyst-sme-national-security-mission-support-agile-defense-p8sx2a0n0xdx) — Clarksburg, WV - [Intelligence Analyst (National Security Mission Support)](https://feeny.ai/job/intelligence-analyst-national-security-mission-support-agile-defense-clarksburg-mdyfyff4n0x7) — Clarksburg, WV - [Data Engineer (Various Locations)](https://feeny.ai/job/data-engineer-various-locations-agile-defense-peterson-space-force-base-cx93jswff513) — Peterson Space Force Base, CO - [Senior Security Architect](https://feeny.ai/job/senior-security-architect-agile-defense-washington-6kpdjfhd1vrh) — Washington, DC - [Marketing Manager](https://feeny.ai/job/marketing-manager-agile-defense-mclean-naxr96b1vn9g) — Mclean, VA - [Contract Writing System Test and Evaluation Analyst](https://feeny.ai/job/contract-writing-system-test-and-evaluation-analyst-agile-defense-fort-huachuca-7nct6dxyvfy8) — Fort Huachuca, AZ - [MSS Developers (Various Locations)](https://feeny.ai/job/mss-developers-various-locations-agile-defense-peterson-space-force-base-49gnyq6qcphj) — Peterson Space Force Base, CO - [Software Engineer (Mid & Senior)](https://feeny.ai/job/software-engineer-mid-senior-agile-defense-remote-5wmkh8cr59tb) - [Project Analyst](https://feeny.ai/job/project-analyst-agile-defense-colorado-springs-bt414cf39xpd) — Colorado Springs, CO - [Intelligence Production Editor](https://feeny.ai/job/intelligence-production-editor-agile-defense-rosslyn-ysm7s6480ts9) — Rosslyn, VA