Full-Time

Lead Analyst

Attack Surface Management

University of Southern California

University of Southern California

Research university in Los Angeles, CA

Compensation Overview

$162.3k - $201.5k/yr

Los Angeles, CA, USA

Remote

Bachelor's

Category
Cybersecurity (1)
Required Skills
Microsoft Azure
Incident Response
ISO/IEC 27001
Vulnerability Analysis
AWS

Get referred to University of Southern California

See people who can refer or advise you

Requirements
  • A bachelor's degree, or combined experience and education as a substitute for the minimum education requirement.
  • At least 5 years of experience in attack surface and vulnerability management.
  • Knowledge of the NIST Cybersecurity Framework, ISO/IEC 27001, MITRE ATT&CK Framework, OWASP Top Ten, CIS Controls, COBIT, SANS Critical Security Controls, PCI DSS, NIST SP 800-53, and ITIL.
  • Strong understanding of attack surface management and vulnerability management, including security testing practices and methodologies.
  • Technical knowledge of cyber defense concepts, including incident response, security monitoring, cyber threat intelligence, attack surface management, and vulnerability management.
  • Understanding of operational technology environments and the security requirements needed to manage the broader attack landscape.
  • Experience building infrastructure and application vulnerability management programs.
  • Experience deploying and operating vulnerability scanning infrastructure and services, with deep understanding of vulnerability scanning platforms.
  • Comprehensive knowledge of cloud-native vulnerability practices in Amazon Web Services, Microsoft Azure, and software-as-a-service platforms.
  • Ability to assess business risks and recommend suitable cybersecurity measures.
  • Experience managing vulnerability assessment tools.
  • Knowledge of system, application, and database hardening techniques.
  • Strong communication and interpersonal skills for effective interaction across organizational levels, along with analytical, problem-solving, and attention-to-detail abilities.
  • Project management experience leading complex security initiatives and the ability to teach and train others effectively.
  • Ability to work with cybersecurity teams, managed service providers, and university information technology teams.
  • Ability to work evenings, weekends, and holidays as required.
Responsibilities
  • Oversee the vulnerability lifecycle management process, including detection, monitoring, reporting, and assessing vulnerability impact.
  • Support regular vulnerability assessments and scans to identify security weaknesses in systems, applications, networks, and operational technology and Internet of Things environments.
  • Develop and implement remediation strategies to address vulnerabilities and minimize the university's attack surface.
  • Implement remediation required by audits and advise distributed service units on vulnerability remediation strategies.
  • Collaborate with information technology teams and stakeholders to validate end-to-end vulnerability remediation and maintain a consistent customer experience.
  • Collaborate with vulnerability-management managed service teams and manage daily operations and communications.
  • Evaluate vulnerability trends in third-party applications and services and collaborate with managed service providers as needed.
  • Serve as an attack surface management subject matter expert and formulate and prioritize intelligence requirements according to the established risk management framework.
  • Participate in and influence the roadmap for the university's vulnerability management program.
  • Collaborate on detailed reports about vulnerabilities, their impact, and remediation status, and communicate findings to stakeholders.
  • Help develop and maintain vulnerability and attack surface management policies, procedures, and best practices.
  • Maintain awareness of legal, regulatory, and technology changes that may affect operations.
  • Monitor university threat intelligence feeds and reports to stay informed about emerging threats and vulnerabilities affecting the organization's attack surface.
  • Maintain knowledge of emerging vulnerabilities, exploits, and remediation techniques.
Desired Qualifications
  • At least 7 years of related experience.
  • A bachelor's degree in Information Science, Computer Science, Computer Engineering, or a related field.
  • Experience working in higher education or complex, decentralized environments.
  • CISSP, GCIH, GPEN, Security+, or a similar certification.
University of Southern California

University of Southern California

View

The University of Southern California is a private research university with academic programs across the arts, sciences, business, engineering, law, health, and other professional fields.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

Get referred to University of Southern California

See people who can refer or advise you