Agile Defense

Digital Forensics Lead (CBP)

Ashburn, VA · Posted 1w ago

salary not listedleadpermanenthybridDept: Cybersecurity

Job Description

About Agile Defense At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests. Title: Digital Forensics Lead (CBP) Clearance: Active Top Secret with SCI Eligibility. Ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can begin processing for candidates who do not hold one. Citizenship: U.S. Citizenship required Location: Reston, VA - Hybrid 3 to 5 days Salary Range: $155,000-175,000 Signing Bonus: $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply. The Role U.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. When something happens on a system supporting that mission, whether it is a confirmed intrusion, an insider case, or an incident that is still being scoped, the question everyone eventually asks is the same: what actually happened, and can you prove it. Getting that answer right, in a way that holds up, is what this role exists to do. You lead digital forensics for this program. You will preserve and analyze evidence from compromised or suspect systems, reconstruct what happened, and produce findings the incident response, threat hunt, and insider threat monitoring leads can act on and that can support disciplinary, legal, or law enforcement action when it comes to that. One thing is worth knowing before you apply. A forensic finding that cannot survive scrutiny is worse than no finding at all, because someone will have already acted on it. Chain of custody and defensible process are not paperwork here. They are the difference between a finding that holds and one that does not. What Success Looks Like Objective 1: Preserve evidence well enough that findings hold up under scrutiny Evidence handling follows chain of custody every time, not only when a case looks like it will matter. Your process would survive being challenged by someone whose job is to find the flaw in it. Nothing you needed for an analysis is missing because it was not preserved in time. ⠀Objective 2: Reconstruct what actually happened, not just what is easy to prove Your analysis answers the question that was actually asked, not the version of it that was easiest to investigate. Where evidence is ambiguous, you say so rather than rounding up to a conclusion the evidence does not fully support. Timelines you build reconcile activity across systems rather than describing one system in isolation. ⠀Objective 3: Deliver findings other teams and outside parties can actually use Incident response, threat hunt, and insider threat monitoring get findings framed for what they need to act, not a raw technical dump. Findings that support disciplinary, legal, or law enforcement action are documented to the standard those processes require. You can explain a technical finding to a non-technical decision maker without losing what matters about it. ⠀Objective 4: Build a forensics capability that gets faster and more reliable over time Case types that recur get a faster, more consistent process each time, not reinvestigated from scratch. Tooling and technique choices get reviewed against what actually worked in real cases. Lessons from a case change the program's practice, not just that one investigation. What You Bring Minimum required experience Candidates will have a minimum of seven (7) years of professional experience with a solid understanding of incident response, insider threat investigations, digital forensics, and cyber threats. A minimum of five (5) years of hands-on experience with experience in the last two (2) years that includes bare metal, cloud or virtual system-based and network-based security monitoring, identifying and analyzing anomalous activities with familiarity in insider threat monitoring software, endpoint forensic tools, intrusion detection systems, intrusion analysis functions, security information event management (SIEM) platforms, endpoint detection and response tools, security operations ticket management. The ability to create insider threat focused dashboards, reports and workflow diagrams. Experience collecting data, chain of custody and reporting results; handling and escalating security issues or emergency situations appropriately; providing incident response capabilities to isolate and mitigate threats to maintain confidentiality, integrity, and availability for protected data. Applicant will have excellent written and oral communication skills, be able to work independently and as part of a team. Willingness and experience with mentoring junior members in an open collaborative environment. Bachelor’s degree in computer science, Engineering, STEM, Information Technology, or Cybersecurity Preferred Experience GCFA, GREM, GFCE, GNFA, GIME, GASF, GX-FA, Encase, Cellebrite or equivalent preferred. Mobile Forensics You have led digital forensic investigations that produced findings used for disciplinary, legal, or law enforcement action, not only internal analysis. You can describe how you maintain chain of custody and why it matters for a finding to hold up. You have worked forensics in a federal or highly regulated environment and know what that adds to evidentiary standards. You have delivered a forensic finding to a non-technical audience, legal, HR, or leadership, and can describe how you framed it. You hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance. Any of these shortens your start date. Certifications such as GCFE, GCFA, or EnCE are useful, but they are not a substitute for having produced findings that held up. A note on timing We are staffing this program now. If you already hold an active CBP BI and EOD, your start date is short and a $10,000 signing bonus comes with the role, payable after 90 days under standard terms. We would like to talk this week. If you do not, we can begin processing a CBP BI for you. That takes months rather than weeks, so applying now means joining a pipeline rather than starting immediately. We would rather tell you that up front than have you find out after you apply. Employee Benefits Agile's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections.