ABOUT THE DEPARTMENT
The University of Southern California (USC) is advancing its cybersecurity posture with a renewed focus on resilience, cyber risk management, and threat-informed defense. As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape.
This role sits within a newly restructured cybersecurity organization that’s leading this transformation. You’ll join a team focused on scalable, proactive defense strategies, incident preparedness, and operational excellence—working alongside experts who are deeply committed to service, innovation, and impact.
If you’re driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your leadership to the table.
POSITION SUMMARY
As the Analyst, Attack Surface Management (ASM) you will be an integral member of the cybersecurity department while also collaborating with stakeholders across the university ecosystem, and reporting to the ASM Manager. This is a full-time exempt position, eligible for all of USC’s fantastic Benefits + Perks. This opportunity is remote.
The Analyst, Attack Surface Management (ASM) works to identify, assess, and mitigate vulnerabilities across the university's digital environment. Responsible for continuously monitoring and managing the university's attack surface (e.g., on-premises and cloud-based systems, network perimeter, Operational Technology (OT) environments, applications, and external-facing services) to prevent unauthorized access and data breaches. Works with cross-functional teams (e.g., Cyber Threat Intel, Cyber Defense, Cyber Governance) to identify and prioritize threats utilizing vulnerability assessments, penetration testing, and risk evaluations. Collaborates with university IT teams, Departments Schools Units (DSUs), and other stakeholders to implement effective security controls. Works with USC Defense to support security response efforts and ensures ASM practices align with regulatory compliance and university cybersecurity policies.
The Analyst, Attack Surface Management (ASM) will:
Identifies, catalogs, and continuously maintains an inventory of the university’s digital assets (e.g., on-premises and cloud-based systems, Operational Technology (OT) environments, applications, and services).
Consistently monitors the university’s digital environment for new threats, changes to the attack surface, and emerging risks.
Conducts vulnerability assessments, attack and penetration testing, and risk evaluations to determine security gaps. Scans digital assets for vulnerabilities, assesses their potential impact, and prioritizes risks based on severity. Analyzes potential threats and their impact on the university’s systems, applications, and data. Recommends appropriate mitigation strategies.
Develops and recommends appropriate mitigation strategies to reduce identified risks.
Works with IT teams, Departments, Schools, and Units (DSUs), and other stakeholders to validate and implement effective remediation. Ensures timely application of security patches and updates to minimize vulnerabilities (e.g., Patch Management).
Assists in responding to security incidents, focusing on how the attack surface was exploited and how to prevent future attacks. Serves as a subject matter expert (SME) in Attack Surface Management (ASM), formulating and prioritizing intelligence requirements within a risk management framework.
Provides regular reports on the attack surface status, including potential risks, vulnerabilities, and the effectiveness of implemented security controls. Ensures ASM strategies align with university cybersecurity policies and compliance requirements.
Engages with IT teams and DSUs to advise on remediation strategies and best practices for reducing the attack surface. Integrates ASM efforts into broader security and risk management initiatives to validate end-to-end remediation.
Maintains awareness and knowledge of changes within legal, regulatory, and technology environments which may affect operations. Promotes a workplace culture aligned with USC’s Code of Ethics, where all employees are valued and empowered to contribute.
MINIMUM QUALIFICATIONS
Great candidates for the position of Analyst, Attack Surface Management (ASM) will meet the following qualifications:
2 years of experience in attack surface and vulnerability management.
A bachelor’s degree or combined experience and education as substitute for minimum education.
Ability to interface with teams across the CISO Office and ITS, such as Enterprise and Infrastructure Services, and across USC IT teams.
Thorough understanding of technology, tools, policies, and standards related to security systems and incident response.
Understanding of Operational Technology environments and the security requirements needed to support them.
Technical knowledge of Cyber Defense concepts, including incident response, security monitoring, cyber threat
intelligence, attack surface, and vulnerability management.
Strong leadership and people management skills.
Solid technical knowledge and troubleshooting skills.
Ability to work effectively in high-stress situations and manage crisis situations.
Skilled in communicating with a wide range of stakeholders and business partners.
Experience in the management and/or implementation of security monitoring, anti-malware, and vulnerability management technologies.
In-depth experience in application security management and knowledge of cyber threat intelligence.
Strong understanding of ASM management, security testing practices, and methodologies.
Experience in building infrastructure and application vulnerability management programs.
Comprehensive knowledge of cloud computing and associated security challenges.
Ability to assess business risks and recommend suitable cybersecurity measures.
Familiarity with common vulnerability frameworks such as CVSS and OWASP Top 10.
Adaptability to changes in the external environment and organizational shifts.
Knowledge of system, application, and database hardening techniques.
Effective communication skills and the ability to interact with all organizational levels.
Project management experience and the ability to lead complex security initiatives.
Commitment to staying current with the latest security threats, trends, and technologies.
PREFERRED QUALIFICATIONS
Exceptional candidates for the position of Analyst, Attack Surface Management (ASM) will also bring the following qualifications or more:
5 years of related experience in IT security roles with hands-on vulnerability analysis
A master's degree.
Strong understanding of cybersecurity threats and remediation practices
Ability to communicate effectively across technical and non-technical audiences
In addition, the successful candidate must also demonstrate, through ideas, words and actions, a strong commitment to USC’s Unifying Values of integrity, excellence, community, well-being, open communication, and accountability.
SALARY AND BENEFITS
The annual base salary range for this position is $112,575.21-$127,577. When extending an offer of employment, the University of Southern California considers factors such as (but not limited to) the scope and responsibilities of the position, the candidate’s work experience, education/training, key skills, internal peer alignment, federal, state, and local laws, contractual stipulations, grant funding, as well as external market and organizational considerations.
To support the well-being of our faculty and staff, USC provides benefits-eligible employees with a broad range of perks to help protect their and their dependents’ health, wealth, and future. These benefits are available as part of the overall compensation and total rewards package. You can learn more about USC’s comprehensive benefits here.
Join the USC cybersecurity team within an environment of innovation and excellence.
Minimum Education: Bachelor's degree
USC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, or any other characteristic protected by law or USC policy. USC observes affirmative action obligations consistent with state and federal law. USC will consider for employment all qualified applicants with criminal records in a manner consistent with applicable laws and regulations, including the Los Angeles County Fair Chance Ordinance for employers and the Fair Chance Initiative for Hiring Ordinance, and with due consideration for patient and student safety. Please refer to the Background Screening Policy Appendix D for specific employment screen implications for the position for which you are applying.
We provide reasonable accommodations to applicants and employees with disabilities. Applicants with questions about access or requiring a reasonable accommodation for any part of the application or hiring process should contact USC Human Resources by phone at (213) 821-8100, or by email at uschr@usc.edu. Inquiries will be treated as confidential to the extent permitted by law.
If you are a current USC employee, please apply to this USC job posting in Workday by copying and pasting this link into your browser:
https://wd5.myworkday.com/usc/d/inst/1$9925/9925$132710.htmldIf an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
Senior nursing leader needed to direct clinical programs, accreditation, and quality across Culinary Health Centers, ensuring regulatory compliance and operational excellence.
Strategically manage presidential initiatives and high-profile events at USC’s Office of the President, coordinating cross-functional teams and executive communications.
Provide on-call, in-person PC, Mac, and printer support as an independent contractor for Geeks on Site's residential and small-business customers in the Salt Lake City area.
Geeks on Site is hiring experienced on-call field technicians in the Madison, WI area to provide PC, Mac, network and printer support for local residential and small business customers.
Palo Alto Networks seeks a Distinguished Architect to lead the design and scaling of an AI-first enterprise platform and developer productivity systems for IT and business functions.
Murgado Automotive Group is hiring an IT Helpdesk Technician to deliver first-line support, resolve end-user issues, and maintain desktop reliability across its Illinois locations.
A DoD-focused SDVOSB JV seeks a Web/SharePoint Administrator to operate, secure, and maintain portal servers and web applications at NEC Picatinny Arsenal.
Wyetech is hiring a senior Exploitation Analyst to perform advanced vulnerability and exploitation analysis in support of classified federal missions, requiring active TS/SCI with polygraph and extensive cyber experience.
TensorWave is hiring an AI Infrastructure Engineer to design, operate, and optimize high-performance GPU clusters that power its AI cloud services.
Lead application strategy and delivery at Wisenbaker by bridging business and technology to drive AI-enabled, data-informed solutions that scale across the enterprise.
Contribute to GLS's enterprise security posture as an entry-level IT Security Analyst responsible for monitoring threats, maintaining security systems, and supporting incident response and risk mitigation.
Geeks on Site seeks experienced on-call field IT technicians in the New Haven–Milford, CT area to provide PC, Mac, printer, and network support for residential and small business customers.
A summer 2026 Digital Technology Intern will support SCADA/MES development, production reporting, and tool testing at McNeilus' Dodge Center manufacturing facility.
Support the IT team at Winsupply’s support services campus as a Client Support Intern focused on Tier 2 troubleshooting, hardware provisioning, onboarding, and asset management.
Avint is hiring a senior Cybersecurity SME with an active Top Secret clearance to lead RMF/A&A efforts, advise leadership, and manage cybersecurity posture for DoD-affiliated systems.