Lead Analyst, Cyber Defense

University of Southern California
Los Angeles, CA
Remote
Job Description
The Lead Analyst, Cyber Defense will be an integral member of the cybersecurity department while also collaborating with stakeholders across the university ecosystem and reporting to the Manager, Cyber Defense. This is a full-time exempt position, eligible for all of USC’s fantastic Benefits + Perks. This opportunity is remote.

Requirements

  • 5 years in key Cyber Defense areas (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management)
  • Bachelor's degree or combined experience/education as substitute for minimum education
  • Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations
  • Significant experience in a SOC analyst or detection engineering role
  • Experience in a senior incident response role or threat hunting capacity
  • Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams
  • Ability to work closely with other cybersecurity teams (e.g., cyber threat intelligence, cybersecurity monitoring)
  • Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations
  • Familiarity with detection tuning languages and tooling
  • Ability to develop and maintain incident response OT cybersecurity policies, standards, and related documentations
  • Knowledge of industrial control systems (ICS)
  • Knowledge of digital forensics and incident response (DFIR), as well as digital forensic investigation processes related to OT/IoT systems
  • Demonstrated understanding of security threats, vulnerabilities, intrusion techniques, malware capabilities and system diagnostics
  • Demonstrated understanding of electronic investigation, forensic tools and methodologies (e.g., log correlation and analysis)
  • Experience with computer security investigative processes and malware identification and analysis
  • Experience with incident response and digital forensics across IT and cloud platforms
  • Knowledge of network security zones, firewall configurations, and intrusion detection systems (IDS)
  • Familiarity with various log protocols/formats (e.g., syslog, HTTP logs, database logs) and the ability to perform forensic traceability
  • Proficiency in packet capture and analysis, as well as experience with log management or security information management tools
  • Experience with security assessment tools (e.g., NMAP, Nessus, Metasploit, Netcat)
  • Skill in log source validation and coverage assessment in a decentralized environment
  • Ability to guide playbook design and SOC process improvement without formal management
  • Demonstrated organizational, critical thinking and analytical skills; ability to assess cybersecurity risks and make informed decisions
  • Excellent written and oral communication skills, and an exemplary attention to detail
  • Ability to analyze complex data sets and logs to identify anomalies and potential threats
  • In-depth knowledge of industry standards and regulations (e.g., ISO 27001, NIST CSF)

Benefits

  • Generous Paid Time Off
  • 401k Matching
  • Retirement Plan
  • Visa Sponsorship
  • Four Day Work Week
  • Generous Parental Leave
  • Tuition Reimbursement
  • Relocation Assistance
]]>