- Expertini Resume Scoring: Our Semantic Matching Algorithm evaluates your CV/Résumé before you apply for this job role: Lead Analyst, Attack Surface Management (ASM).
Urgent! Lead Analyst, Attack Surface Management (ASM) Job Opening In – Now Hiring University of Southern California
Lead Analyst, Attack Surface Management (ASM)Apply (https://usc.wd5.myworkdayjobs.com/ExternalUSCCareers/job/Los-Angeles-CA---University-Park-Campus/Lead-Analyst--Attack-Surface-Management--ASM-_REQ20164593-1/apply) Information Technology Services ITS Los Angeles, California
ABOUT THE DEPARTMENT
The University of Southern California (USC) is advancing its cybersecurity posture with a renewed focus on resilience, cyber risk management, and threat-informed defense.
As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape.
This role sits within a newly restructured cybersecurity organization that’s leading this transformation.
You’ll join a team focused on scalable, proactive defense strategies, incident preparedness, and operational excellence—working alongside experts who are deeply committed to service, innovation, and impact.
If you’re driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your leadership to the table.
POSITION SUMMARY
As theLead Analyst, Attack Surface Management (ASM)you will be an integral member of the cybersecurity department while also collaborating with stakeholders across the university ecosystem, and reporting to the ASM Manager.
This is a full-time exempt position, eligible for all of USC’s fantastic Benefits + Perks.
This opportunity is remote.
The Lead Analyst, Attack Surface Management (ASM) responsible for identifying, assessing, and mitigating security vulnerabilities across our organization's systems, networks, and applications and supports attack surface management operations.
Conducts vulnerability assessments, penetration testing, compliance, and risk management activities.
Oversees the university's attack surface and vulnerability lifecycle management process, (e.g., detection, monitoring, reporting, and assessing the impact of vulnerabilities) with focus on continuous improvement to mitigate risks associated with vulnerabilities, application security, and cyber threat intelligence.
Develops and implements remediation strategies to address vulnerabilities and minimize the university's attack surface.
Directly supports program maturity efforts and plays a key role in integrating threat intelligence into the broader university environment.
TheLead Analyst, Attack Surface Management (ASM)will:
+ Oversees the vulnerability lifecycle management process (e.g., detection, monitoring, reporting, and assessing the impact of vulnerabilities).
Supports regular vulnerability assessments and scans to identify security weaknesses in systems, applications, networks, and OT/IoT environment.
+ Develops and implements remediation strategies to address vulnerabilities and minimize the university's attack surface.
Implements remediation required by audits.
Engages with DSUs to advise on remediation strategies of vulnerabilities.
+ Collaborates with IT teams and stakeholders to validate effective end-to-end vulnerability remediation and maintain a consistent customer experience.
Collaborates with VM managed service teams and manages daily operations and communications.
Evaluates vulnerability trends in third-party applications and services and collaborates with managed service providers as needed.
+ Serves as an ASM subject matter expert, formulating and prioritizing intelligence requirements according to established risk management framework.
Participates in and influences the roadmap for the university’s vulnerability management program.
+ Collaborates on detailed reports on vulnerabilities, their impact, and the status of remediation efforts and communicates findings to stakeholders.
Provides expertise to help develop and maintain vulnerability and attack surface management policies, procedures, and best practices for the university.
+ Maintains awareness and knowledge of current changes within legal, regulatory, and technology environments which may affect operations.
Maintains awareness of current university threat intelligence feeds and reports to stay informed about emerging threats and vulnerabilities that may affect the organization's attack surface.
Maintains knowledge of emerging vulnerabilities, exploits, and remediation techniques.
+ Encourages a workplace culture where all employees are valued, value others and have the opportunity to contribute through their ideas, words and actions, in accordance with the USC Code of Ethics.
MINIMUM QUALIFICATIONS
Great candidates for the position ofLead Analyst, Attack Surface Management (ASM)will meet the following qualifications:
+ 5 years in attack surface and vulnerability management.
+ A bachelor’s degree or combined experience/education as substitute for minimum education.
+ Knowledge of the following frameworks: NIST Cybersecurity Framework (NIST CSF), ISO/IEC 27001, MITRE ATT&CK
+ Framework, OWASP Top Ten, CIS Controls, COBIT, SANS Critical Security Controls, PCI DSS, NIST SP 800-53, and ITIL.
+ Strong understanding of ASM/vulnerability management, security testing practices, and methodologies.
+ Understanding and technical knowledge of Cyber Defense concepts, (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management).
+ Understanding of Operational Technology environments and security requirements needed to manage the broader attack landscape across the university.
+ Experience in building infrastructure and application vulnerability management programs.
+ Experience in deploying and operating vulnerability scanning infrastructure and services and deep understanding of vulnerability scanning platforms.
+ Comprehensive knowledge of cloud-native vulnerability practices in AWS, Azure, and SaaS platforms and associated security challenges.
+ Ability to assess business risks and recommend suitable cybersecurity measures.
+ Experience in managing vulnerability assessment tools.
+ Knowledge of system, application, and database hardening techniques.
+ Strong communication and interpersonal skills, enabling effective interaction across all organizational levels, along with proven analytical and problem-solving abilities, and exceptional attention to detail.
+ Project management experience with a track record of leading complex security initiatives, coupled with the ability to teach and train others effectively.
+ Ability to work with teams across the cybersecurity function, with managed service providers, and with IT teams across the university.
+ Ability to work evenings, weekends and holidays as the schedule dictates.
PREFERRED QUALIFICATIONS
Exceptional candidates for the position ofLead Analyst, Attack Surface Management (ASM)will also bring the following qualifications or more:
+ 7 years of related experience.
+ A bachelor's degree or combined experience/education as substitute for minimum education.
+ Experience working in higher education or complex, decentralized environments.
+ CISSP, GCIH, GPEN, Security+, or similar.
In addition, the successful candidate must also demonstrate, through ideas, words and actions, a strong commitment toUSC’s Unifying Values (https://culturejourney.usc.edu/explore/unifying-values/) of integrity, excellence, community, well-being, open communication, and accountability.
SALARY AND BENEFITS
The annual base salary range for this position is $162,315.11-$201.452.98.
When extending an offer of employment, the University of Southern California considers factors such as (but not limited to) the scope and responsibilities of the position, the candidate’s work experience, education/training, key skills, internal peer alignment, federal, state, and local laws, contractual stipulations, grant funding, as well as external market and organizational considerations.
To support the well-being of our faculty and staff, USC provides benefits-eligible employees with a broad range of perks to help protect their and their dependents’ health, wealth, and future.
These benefits are available as part of the overall compensation and total rewards package.
You can learn more about USC’s comprehensive benefitshere (https://employees.usc.edu/benefits-perks/) .
Join the USC cybersecurity team within an environment of innovation and excellence.
Minimum Education: Bachelor's degree Addtional Education Requirements Combined experience/education as substitute for minimum education Minimum Experience: 5 years in attack surface and vulnerability management.
Minimum Skills: Knowledge of the following frameworks: NIST Cybersecurity Framework (NIST CSF), ISO/IEC 27001, MITRE ATT&CK Framework, OWASP Top Ten, CIS Controls, COBIT, SANS Critical Security Controls, PCI DSS, NIST SP 800-53, and ITIL.
Strong understanding of ASM/vulnerability management, security testing practices, and methodologies.
Understanding and technical knowledge of Cyber Defense concepts, (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management).
Understanding of Operational Technology environments and security requirements needed to manage the broader attack landscape across the university.
Experience in building infrastructure and application vulnerability management programs.
Experience in deploying and operating vulnerability scanning infrastructure and services and deep understanding of vulnerability scanning platforms.
Comprehensive knowledge of cloud-native vulnerability practices in AWS, Azure, and SaaS platforms and associated security challenges.
Ability to assess business risks and recommend suitable cybersecurity measures.
Experience in managing vulnerability assessment tools.
Knowledge of system, application, and database hardening techniques.
Strong communication and interpersonal skills, enabling effective interaction across all organizational levels, along with proven analytical and problem-solving abilities, and exceptional attention to detail.
Project management experience with a track record of leading complex security initiatives, coupled with the ability to teach and train others effectively.
Ability to work with teams across the cybersecurity function, with managed service providers, and with IT teams across the university.
Preferred Education: Bachelor's degree In Information Science Or Computer Science Or Computer Engineering Or in related field(s) Preferred Certifications: CISSP, GCIH, GPEN, Security+, or similar.
Preferred Experience: 7 years Preferred Skills: Experience working in higher education or complex, decentralized environments.
REQ20164593 Posted Date: 10/23/2025
✨ Smart • Intelligent • Private • Secure
Practice for Any Interview Q&A (AI Enabled)
Predict interview Q&A (AI Supported)
Mock interview trainer (AI Supported)
Ace behavioral interviews (AI Powered)
Record interview questions (Confidential)
Master your interviews
Track your answers (Confidential)
Schedule your applications (Confidential)
Create perfect cover letters (AI Supported)
Analyze your resume (NLP Supported)
ATS compatibility check (AI Supported)
Optimize your applications (AI Supported)
O*NET Supported
O*NET Supported
O*NET Supported
O*NET Supported
O*NET Supported
European Union Recommended
Institution Recommended
Institution Recommended
Researcher Recommended
IT Savvy Recommended
Trades Recommended
O*NET Supported
Artist Recommended
Researchers Recommended
Create your account
Access your account
Create your professional profile
Preview your profile
Your saved opportunities
Reviews you've given
Companies you follow
Discover employers
O*NET Supported
Common questions answered
Help for job seekers
How matching works
Customized job suggestions
Fast application process
Manage alert settings
Understanding alerts
How we match resumes
Professional branding guide
Increase your visibility
Get verified status
Learn about our AI
How ATS ranks you
AI-powered matching
Join thousands of professionals who've advanced their careers with our platform
Unlock Your Lead Analyst Potential: Insight & Career Growth Guide
Real-time Lead Analyst Jobs Trends in , United States (Graphical Representation)
Explore profound insights with Expertini's real-time, in-depth analysis, showcased through the graph below. This graph displays the job market trends for Lead Analyst in , United States using a bar chart to represent the number of jobs available and a trend line to illustrate the trend over time. Specifically, the graph shows 224098 jobs in United States and 0 jobs in . This comprehensive analysis highlights market share and opportunities for professionals in Lead Analyst roles. These dynamic trends provide a better understanding of the job market landscape in these regions.
Great news! University of Southern California is currently hiring and seeking a Lead Analyst, Attack Surface Management (ASM) to join their team. Feel free to download the job details.
Wait no longer! Are you also interested in exploring similar jobs? Search now: Lead Analyst, Attack Surface Management (ASM) Jobs .
An organization's rules and standards set how people should be treated in the office and how different situations should be handled. The work culture at University of Southern California adheres to the cultural norms as outlined by Expertini.
The fundamental ethical values are:The average salary range for a Lead Analyst, Attack Surface Management (ASM) Jobs United States varies, but the pay scale is rated "Standard" in . Salary levels may vary depending on your industry, experience, and skills. It's essential to research and negotiate effectively. We advise reading the full job specification before proceeding with the application to understand the salary package.
Key qualifications for Lead Analyst, Attack Surface Management (ASM) typically include Other General and a list of qualifications and expertise as mentioned in the job specification. Be sure to check the specific job listing for detailed requirements and qualifications.
To improve your chances of getting hired for Lead Analyst, Attack Surface Management (ASM), consider enhancing your skills. Check your CV/Résumé Score with our free Resume Scoring Tool. We have an in-built Resume Scoring tool that gives you the matching score for each job based on your CV/Résumé once it is uploaded. This can help you align your CV/Résumé according to the job requirements and enhance your skills if needed.
Here are some tips to help you prepare for and ace your job interview:
Before the Interview:To prepare for your Lead Analyst, Attack Surface Management (ASM) interview at University of Southern California, research the company, understand the job requirements, and practice common interview questions.
Highlight your leadership skills, achievements, and strategic thinking abilities. Be prepared to discuss your experience with HR, including your approach to meeting targets as a team player. Additionally, review the University of Southern California's products or services and be prepared to discuss how you can contribute to their success.
By following these tips, you can increase your chances of making a positive impression and landing the job!
Setting up job alerts for Lead Analyst, Attack Surface Management (ASM) is easy with United States Jobs Expertini. Simply visit our job alerts page here, enter your preferred job title and location, and choose how often you want to receive notifications. You'll get the latest job openings sent directly to your email for FREE!