The University of Southern California (USC) is advancing its cybersecurity posture with a renewed focus on resilience, cyber risk management, and threat-informed defense. As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape. This role sits within a newly restructured cybersecurity organization that’s leading this transformation. You’ll join a team focused on scalable, proactive defense strategies, incident preparedness, and operational excellence—working alongside experts who are deeply committed to service, innovation, and impact. If you’re driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your leadership to the table. POSITION SUMMARY As the Lead Analyst, Attack Surface Management (ASM) you will be an integral member of the cybersecurity department while also collaborating with stakeholders across the university ecosystem, and reporting to the ASM Manager. This is a full-time exempt position, eligible for all of USC’s fantastic Benefits + Perks. This opportunity is remote. The Lead Analyst, Attack Surface Management (ASM) responsible for identifying, assessing, and mitigating security vulnerabilities across our organization's systems, networks, and applications and supports attack surface management operations. Conducts vulnerability assessments, penetration testing, compliance, and risk management activities. Oversees the university's attack surface and vulnerability lifecycle management process, (e.g., detection, monitoring, reporting, and assessing the impact of vulnerabilities) with focus on continuous improvement to mitigate risks associated with vulnerabilities, application security, and cyber threat intelligence. Develops and implements remediation strategies to address vulnerabilities and minimize the university's attack surface. Directly supports program maturity efforts and plays a key role in integrating threat intelligence into the broader university environment. The Lead Analyst, Attack Surface Management (ASM) will: Oversees the vulnerability lifecycle management process (e.g., detection, monitoring, reporting, and assessing the impact of vulnerabilities). Supports regular vulnerability assessments and scans to identify security weaknesses in systems, applications, networks, and OT/IoT environment. Develops and implements remediation strategies to address vulnerabilities and minimize the university's attack surface. Implements remediation required by audits. Engages with DSUs to advise on remediation strategies of vulnerabilities. Collaborates with IT teams and stakeholders to validate effective end-to-end vulnerability remediation and maintain a consistent customer experience. Collaborates with VM managed service teams and manages daily operations and communications. Evaluates vulnerability trends in third-party applications and services and collaborates with managed service providers as needed. Serves as an ASM subject matter expert, formulating and prioritizing intelligence requirements according to established risk management framework. Participates in and influences the roadmap for the university’s vulnerability management program. Collaborates on detailed reports on vulnerabilities, their impact, and the status of remediation efforts and communicates findings to stakeholders. Provides expertise to help develop and maintain vulnerability and attack surface management policies, procedures, and best practices for the university. Maintains awareness and knowledge of current changes within legal, regulatory, and technology environments which may affect operations. Maintains awareness of current university threat intelligence feeds and reports to stay informed about emerging threats and vulnerabilities that may affect the organization's attack surface. Maintains knowledge of emerging vulnerabilities, exploits, and remediation techniques. Encourages a workplace culture where all employees are valued, value others and have the opportunity to contribute through their ideas, words and actions, in accordance with the USC Code of Ethics.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
5,001-10,000 employees