Lead Analyst, Cyber Defense
University of Southern California | |
$164,175
| |
United States, California, Los Angeles | |
3720 Flower Street (Show on map) | |
May 27, 2026 | |
|
ABOUT THE DEPARTMENT The University of Southern California (USC) is committed to strengthening its cybersecurity posture through resilience, cyber risk management, and threat-informed defense. As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape. This role sits within USC's cybersecurity organization, which is advancing threat-informed defense and operational excellence. You'll join a team committed to scalable, proactive defense strategies, incident preparedness, and high-impact partnership across the university, working alongside experts who are deeply committed to service, innovation, and impact. If you're driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your expertise to the table. POSITION SUMMARY As the Lead Analyst, Cyber Defense you will be an integral member of the cybersecurity department while also collaborating with stakeholders across the university ecosystem and reporting to the Manager, Cyber Defense. This is a full-time exempt position, eligible for all of USC's fantastic Benefits + Perks. This opportunity is remote. The Lead Analyst, Cyber Defense serves as a technical authority responsible for elevating the university's cyber detection and response posture. Leads advanced incident investigations, threat hunting and detection development while partnering across the SOC, threat intelligence, MSSPs, and distributed university partners. Ensures high-fidelity threat detection by operationalizing threat intel, optimizing SIEM tools (e.g., Splunk and Chronicle) and shaping detection logic, playbooks and standards. Drives cyber defense maturity across diverse systems, aligning with MITRE ATT&CK and other frameworks. Contributes to the development of detection standards, SOC engineering priorities, and incident readiness and response. The Lead Analyst, Cyber Defense:
MINIMUM QUALIFICATIONS Great candidates for the position of Lead Analyst, Cyber Defense will meet the following qualifications:
PREFERRED QUALIFICATIONS Exceptional candidates for the position of Lead Analyst, Cyber Defense will also bring the following qualifications or more:
In addition, the successful candidate must also demonstrate, through ideas, words and actions, a strong commitment to USC's Unifying Values of integrity, excellence, community, well-being, open communication, and accountability. SALARY AND BENEFITS The annual base salary range for this position is $164,175.55 to $196,000. When extending an offer of employment, the University of Southern California considers factors such as (but not limited to) the scope and responsibilities of the position, the candidate's work experience, education/training, key skills, internal peer alignment, federal, state, and local laws, contractual stipulations, grant funding, as well as external market and organizational considerations. To support the well-being of our faculty and staff, USC provides benefits-eligible employees with a broad range of perks to help protect their and their dependents' health, wealth, and future. These benefits are available as part of the overall compensation and total rewards package. You can learn more about USC's comprehensive benefits here. Join the USC cybersecurity team within an environment of innovation and excellence. Minimum Education: Bachelor's degree Addtional Education Requirements Combined experience/education as substitute for minimum education Minimum Experience: 5 years in key Cyber Defense areas, (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management). Minimum Skills: Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations. Significant experience in a SOC analyst or detection engineering role. Experience in a senior incident response role or threat hunting capacity. Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams. Ability to work closely with other cybersecurity teams (e.g., cyber threat intelligence, cybersecurity monitoring). Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams. Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations. Familiarity with detection tuning languages and tooling. Ability to develop and maintain incident response OT cybersecurity policies, standards, and related documentations. Knowledge of industrial control systems (ICS). Knowledge of digital forensics and incident response (DFIR), as well as digital forensic investigation processes related to OT/IoT systems. Demonstrated understanding of security threats, vulnerabilities, intrusion techniques, malware capabilities and system diagnostics. Demonstrated understanding of electronic investigation, forensic tools and methodologies (e.g., log correlation and analysis). Experience with computer security investigative processes and malware identification and analysis. Experience with incident response and digital forensics across IT and cloud platforms. Knowledge of network security zones, firewall configurations, and intrusion detection systems (IDS). Familiarity with various log protocols/formats (e.g., syslog, HTTP logs, database logs) and the ability to perform forensic traceability. Proficiency in packet capture and analysis, as well as experience with log management or security information management tools. Experience with security assessment tools (e.g., NMAP, Nessus, Metasploit, Netcat). Skill in log source validation and coverage assessment in a decentralized environment. Ability to guide playbook design and SOC process improvement without formal management. Demonstrated organizational, critical thinking and analytical skills; ability to assess cybersecurity risks and make informed decisions. Excellent written and oral communication skills, and an exemplary attention to detail. Ability to analyze complex data sets and logs to identify anomalies and potential threats. In-depth knowledge of industry standards and regulations (e.g., ISO 27001, NIST CSF). Preferred Education: Bachelor's degree In Information Science Or Computer Science Or Computer Engineering Or in related field(s) Preferred Certifications: GIAC Certified Incident Handler (GCIH), GIAC Security Essentials (GSEC), or equivalent. Cisco Certified CyberOps Associate or similar. MITRE ATT&CK Defender certifications preferred. Preferred Experience: 7 years Job ID REQ20175708
Posted Date 05/27/2026 Apply
Current employees apply here | |
$164,175
May 27, 2026