Know ATS Score
CV/Résumé Score
  • Expertini Resume Scoring: Our Semantic Matching Algorithm evaluates your CV/Résumé before you apply for this job role: Manager, Attack Surface Management (ASM).
United States Jobs Expertini

Urgent! Manager, Attack Surface Management (ASM) Job Opening In – Now Hiring University of Southern California

Manager, Attack Surface Management (ASM)



Job description

Manager, Attack Surface Management (ASM)Apply (https://usc.wd5.myworkdayjobs.com/ExternalUSCCareers/job/Los-Angeles-CA---University-Park-Campus/Manager--Attack-Surface-Management--ASM-_REQ20164592-1/apply) Information Technology Services ITS Los Angeles, California

ABOUT THE DEPARTMENT


The University of Southern California (USC) is advancing its cybersecurity posture with a renewed focus on resilience, cyber risk management, and threat-informed defense.

As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape.


This role sits within a newly restructured cybersecurity organization that’s leading this transformation.

You’ll join a team focused on scalable, proactive defense strategies, incident preparedness, and operational excellence—working alongside experts who are deeply committed to service, innovation, and impact.


If you’re driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your leadership to the table.


POSITION SUMMARY


As theManager, Attack Surface Management (ASM)you will be an integral leader of the cybersecurity department while also collaborating with stakeholders across the university ecosystem, and reporting to the Cyber Defense Director.

This is a full-time exempt position, eligible for all of USC’s fantastic Benefits + Perks.

This opportunity is remote.


The Manager, Attack Surface Management (ASM) leads the university’s Attack Surface Management (ASM) program, integrating vulnerability management, cyber threat intelligence (CTI), and vendor-led managed security services (MSSPs) aligning to threat-informed defenses.

Responsible for external and internal attack surface visibility, prioritized remediation, and adversary-informed defense design.

Responsible for overseeing vulnerability assessments, penetration testing, and proactive risk mitigation to safeguard the university's digital assets.

Directs third-party security providers (e.g., managed services, professional services) as well as coordination with cross functional cyber teams to implement attack surface management strategies.

Responsible for establishing processes for the ASM team to continuously monitor and utilize security tools to assess the university's digital footprint, identifying vulnerabilities (internal and external), and implementing measures to mitigate risks and provide recommended remediation action.


TheManager, Attack Surface Management (ASM)will:
+ Oversees the entire attack surface management process (e.g., detection, monitoring, reporting, impact assessment).

Defines and maintains criteria to prioritize vulnerabilities based on risk, potential impact, and business continuity needs.

Leads ASM program strategy, operations, the execution of security and vulnerability scans to identify and mitigate risks proactively in a university environment.
+ Develops and implements strategic remediation plans to minimize the university’s internal and external attack surface.

Works with IT teams, Information Security Officers (ISOs), and Cyber Governance to ensure timely and effective remediation of vulnerabilities.

Collaborates with ISOs and Cyber Governance to engage with DSUs to provide expert guidance on risk mitigation strategies.

Continuously improves processes for addressing vulnerabilities, application security risks, and cyber threat intelligence gaps.
+ Leads the development of use cases and requirements for ASM security tools, ensuring proper configuration and deployment.

Manages and directs third-party security service providers that support ASM capabilities (e.g. vulnerability and cyber threats).

Ensures effective use of security tools such as vulnerability scanners, penetration testing platforms, and automated monitoring solutions.

Manages and directs managed service providers utilized to enable ASM capabilities.

Oversees managed service provider performance, defines KPIs, manages delivery quality, and guides threat-hunting activities.

Monitors the latest security threats, vulnerabilities, and industry best practices to proactively adapt ASM strategies.

Serves as an ASM subject-matter expert, aligning intelligence requirements with cyber defense strategies.

Directs vulnerability assessments, penetration testing, and risk management activities to enhance security resilience.

Provides tailored remediation guidance to DSUs based on threat telemetry and unit-specific exposures.
+ Assists in security incident response efforts, focusing on attack surface exploitation and future risk mitigation.

Ensures attack surface management aligns with broader cybersecurity frameworks, compliance regulations, and organizational risk management policies.

Formalizes and maintains the criteria and framework to prioritize vulnerabilities based on risk and potential impact.

Collaborates with IT teams to ensure attack surface initiatives comply with regulatory frameworks and industry standards.

Provides regular reports on vulnerability status, attack surface trends, and risk mitigation effectiveness.
+ Supports strategic planning efforts related to cybersecurity, compliance, and risk management.

Focuses on continuous improvement to mitigate risks associated with vulnerabilities, application security, and cyber threat intelligence.

Collaborates with IT teams and stakeholders to validate effective end-to-end vulnerability remediation and maintain a consistent customer experience.

Collaborates with ISOs and Cyber Governance to engage with DSUs to advise on recommended remediation strategies for vulnerabilities.
+ Participates in staff management activities (e.g., hiring, coaching, training, performance reviews, pay actions, and promotions).

Offers recommendations to leadership on security monitoring and incident response strategies based on informed analysis.
+ Maintains awareness and knowledge of current changes within legal, regulatory, and technology environments which may affect operations.

Encourages a workplace culture where all employees are valued, value others and have the opportunity to contribute through their ideas, words and actions, in accordance with the USC Code of Ethics.



MINIMUM QUALIFICATIONS


Great candidates for the position ofManager, Attack Surface Management (ASM)will meet the following qualifications:
+ 5 years in attack surface and vulnerability management.
+ A bachelor's degree or combined experience/education as substitute for minimum education.
+ Strong understanding of attack surface management, security testing practices, and methodologies.
+ Ability to develop and implement a comprehensive attack surface management strategy that aligns with the university’s objectives and risk appetite.
+ Deep understanding of cybersecurity principles, attack vectors, and the threat landscape.
+ Familiarity with MITRE ATT&CK, Diamond Model, OWASP Top 10, and CVSS frameworks
+ Experience operationalizing CTI and IOCs across SIEM, EDR, and ASM workflows
+ Ability to assess business risks and recommend suitable cybersecurity measures.
+ Adaptability to changes in the external environment and organizational shifts.
+ Knowledge of system, application, and database hardening techniques.
+ Effective communication skills and the ability to interact with all organizational levels.
+ Project management experience and the ability to lead complex security initiatives.
+ Ability to collaborate and manage managed service providers, including MSSPs, SLA tracking, contract influence, performance oversight.
+ Ability to engage with other teams across the cybersecurity function to push for continuous improvement of the attack surface management capability.
+ Experience managing MSSPs, including SLA tracking, contract influence, and performance oversight
+ Commitment to staying current with the latest security threats, trends, and technologies.
+ Strong leadership and people management skills.
+ Solid technical knowledge and troubleshooting skills.
+ Ability to work effectively in high-stress situations and manage crisis situations.
+ Skilled in communicating with a wide range of stakeholders and business partners.
+ Experience in the management and/or implementation of security monitoring, anti-malware, and vulnerability management technologies.
+ In-depth experience in application security management and knowledge of cyber threat intelligence.
+ Comprehensive knowledge of cloud computing and associated security challenges.
+ Ability to work evenings, weekends and holidays as the schedule dictates.



PREFERRED QUALIFICATIONS


Exceptional candidates for the position ofManager, Attack Surface Management (ASM)will also bring the following qualifications or more:
+ 7 years relevant experience.
+ 3 years leading a vulnerability management program, with the ability to prioritize projects and deliverables
+ Demonstrated success building or evolving a program from scratch
+ Strong interpersonal and communication skills
+ A Master's degree
+ Cyber certification (e.g., CISSP, GIAC, CISM).



In addition, the successful candidate must also demonstrate, through ideas, words and actions, a strong commitment toUSC’s Unifying Values (https://culturejourney.usc.edu/explore/unifying-values/) of integrity, excellence, community, well-being, open communication, and accountability.


SALARY AND BENEFITS


The annual base salary range for this position is $186,100.12 to $227,349.86.

When extending an offer of employment, the University of Southern California considers factors such as (but not limited to) the scope and responsibilities of the position, the candidate’s work experience, education/training, key skills, internal peer alignment, federal, state, and local laws, contractual stipulations, grant funding, as well as external market and organizational considerations.


To support the well-being of our faculty and staff, USC provides benefits-eligible employees with a broad range of perks to help protect their and their dependents’ health, wealth, and future.

These benefits are available as part of the overall compensation and total rewards package.

You can learn more about USC’s comprehensive benefitshere (https://employees.usc.edu/benefits-perks/) .


Join the USC cybersecurity team within an environment of innovation and excellence.

Minimum Education: Bachelor's degree Addtional Education Requirements Combined experience/education as substitute for minimum education Minimum Experience: 5 years in attack surface and vulnerability management.

Minimum Skills: Strong understanding of attack surface management, security testing practices, and methodologies.

Ability to develop and implement a comprehensive attack surface management strategy that aligns with the university’s objectives and risk appetite.

Deep understanding of cybersecurity principles, attack vectors, and the threat landscape.

Familiarity with MITRE ATT&CK, Diamond Model, OWASP Top 10, and CVSS frameworks Experience operationalizing CTI and IOCs across SIEM, EDR, and ASM workflows Ability to assess business risks and recommend suitable cybersecurity measures.

Adaptability to changes in the external environment and organizational shifts.

Knowledge of system, application, and database hardening techniques.

Effective communication skills and the ability to interact with all organizational levels.

Project management experience and the ability to lead complex security initiatives.

Ability to collaborate and manage managed service providers, including MSSPs, SLA tracking, contract influence, performance oversight.

Ability to engage with other teams across the cybersecurity function to push for continuous improvement of the attack surface management capability.

Experience managing MSSPs, including SLA tracking, contract influence, and performance oversight Commitment to staying current with the latest security threats, trends, and technologies.

Strong leadership and people management skills.

Solid technical knowledge and troubleshooting skills.

Ability to work effectively in high-stress situations and manage crisis situations.

Skilled in communicating with a wide range of stakeholders and business partners.

Experience in the management and/or implementation of security monitoring, anti-malware, and vulnerability management technologies.

In-depth experience in application security management and knowledge of cyber threat intelligence.

Comprehensive knowledge of cloud computing and associated security challenges.

Preferred Education: Master's degree Preferred Certifications: Cyber certification (e.g., CISSP, GIAC, CISM).

Preferred Experience: 7 years With 3 years leading a vulnerability management program, with the ability to prioritize projects and deliverables.

REQ20164592 Posted Date: 10/02/2025


Required Skill Profession

Other General



Your Complete Job Search Toolkit

✨ Smart • Intelligent • Private • Secure

Start Using Our Tools

Join thousands of professionals who've advanced their careers with our platform

Rate or Report This Job
If you feel this job is inaccurate or spam kindly report to us using below form.
Please Note: This is NOT a job application form.


    Unlock Your Manager Attack Potential: Insight & Career Growth Guide


  • Real-time Manager Attack Jobs Trends in , United States (Graphical Representation)

    Explore profound insights with Expertini's real-time, in-depth analysis, showcased through the graph below. This graph displays the job market trends for Manager Attack in , United States using a bar chart to represent the number of jobs available and a trend line to illustrate the trend over time. Specifically, the graph shows 412646 jobs in United States and 0 jobs in . This comprehensive analysis highlights market share and opportunities for professionals in Manager Attack roles. These dynamic trends provide a better understanding of the job market landscape in these regions.

  • Are You Looking for Manager, Attack Surface Management (ASM) Job?

    Great news! is currently hiring and seeking a Manager, Attack Surface Management (ASM) to join their team. Feel free to download the job details.

    Wait no longer! Are you also interested in exploring similar jobs? Search now: .

  • The Work Culture

    An organization's rules and standards set how people should be treated in the office and how different situations should be handled. The work culture at University of Southern California adheres to the cultural norms as outlined by Expertini.

    The fundamental ethical values are:
    • 1. Independence
    • 2. Loyalty
    • 3. Impartiality
    • 4. Integrity
    • 5. Accountability
    • 6. Respect for human rights
    • 7. Obeying United States laws and regulations
  • What Is the Average Salary Range for Manager, Attack Surface Management (ASM) Positions?

    The average salary range for a varies, but the pay scale is rated "Standard" in . Salary levels may vary depending on your industry, experience, and skills. It's essential to research and negotiate effectively. We advise reading the full job specification before proceeding with the application to understand the salary package.

  • What Are the Key Qualifications for Manager, Attack Surface Management (ASM)?

    Key qualifications for Manager, Attack Surface Management (ASM) typically include Other General and a list of qualifications and expertise as mentioned in the job specification. Be sure to check the specific job listing for detailed requirements and qualifications.

  • How Can I Improve My Chances of Getting Hired for Manager, Attack Surface Management (ASM)?

    To improve your chances of getting hired for Manager, Attack Surface Management (ASM), consider enhancing your skills. Check your CV/Résumé Score with our free Tool. We have an in-built Resume Scoring tool that gives you the matching score for each job based on your CV/Résumé once it is uploaded. This can help you align your CV/Résumé according to the job requirements and enhance your skills if needed.

  • Interview Tips for Manager, Attack Surface Management (ASM) Job Success
    University of Southern California interview tips for Manager, Attack Surface Management (ASM)

    Here are some tips to help you prepare for and ace your job interview:

    Before the Interview:
    • Research: Learn about the University of Southern California's mission, values, products, and the specific job requirements and get further information about
    • Other Openings
    • Practice: Prepare answers to common interview questions and rehearse using the STAR method (Situation, Task, Action, Result) to showcase your skills and experiences.
    • Dress Professionally: Choose attire appropriate for the company culture.
    • Prepare Questions: Show your interest by having thoughtful questions for the interviewer.
    • Plan Your Commute: Allow ample time to arrive on time and avoid feeling rushed.
    During the Interview:
    • Be Punctual: Arrive on time to demonstrate professionalism and respect.
    • Make a Great First Impression: Greet the interviewer with a handshake, smile, and eye contact.
    • Confidence and Enthusiasm: Project a positive attitude and show your genuine interest in the opportunity.
    • Answer Thoughtfully: Listen carefully, take a moment to formulate clear and concise responses. Highlight relevant skills and experiences using the STAR method.
    • Ask Prepared Questions: Demonstrate curiosity and engagement with the role and company.
    • Follow Up: Send a thank-you email to the interviewer within 24 hours.
    Additional Tips:
    • Be Yourself: Let your personality shine through while maintaining professionalism.
    • Be Honest: Don't exaggerate your skills or experience.
    • Be Positive: Focus on your strengths and accomplishments.
    • Body Language: Maintain good posture, avoid fidgeting, and make eye contact.
    • Turn Off Phone: Avoid distractions during the interview.
    Final Thought:

    To prepare for your Manager, Attack Surface Management (ASM) interview at University of Southern California, research the company, understand the job requirements, and practice common interview questions.

    Highlight your leadership skills, achievements, and strategic thinking abilities. Be prepared to discuss your experience with HR, including your approach to meeting targets as a team player. Additionally, review the University of Southern California's products or services and be prepared to discuss how you can contribute to their success.

    By following these tips, you can increase your chances of making a positive impression and landing the job!

  • How to Set Up Job Alerts for Manager, Attack Surface Management (ASM) Positions

    Setting up job alerts for Manager, Attack Surface Management (ASM) is easy with United States Jobs Expertini. Simply visit our job alerts page here, enter your preferred job title and location, and choose how often you want to receive notifications. You'll get the latest job openings sent directly to your email for FREE!