Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Analyst, Cyber Defense

$164.18k - $196k

University of Southern California

ABOUT THE DEPARTMENT

The University of Southern California (USC) is committed to strengthening its cybersecurity posture through resilience, cyber risk management, and threat-informed defense. As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape.

This role sits within USC’s cybersecurity organization, which is advancing threat-informed defense and operational excellence. You’ll join a team committed to scalable, proactive defense strategies, incident preparedness, and high-impact partnership across the university, working alongside experts who are deeply committed to service, innovation, and impact.

If you’re driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your expertise to the table.

POSITION SUMMARY

As the Lead Analyst, Cyber Defense you will be an integral member of the cybersecurity department while also collaborating with stakeholders across the university ecosystem and reporting to the Manager, Cyber Defense. This is a full-time exempt position, eligible for all of USC’s fantastic Benefits + Perks. This opportunity is remote.

The Lead Analyst, Cyber Defense serves as a technical authority responsible for elevating the university’s cyber detection and response posture. Leads advanced incident investigations, threat hunting and detection development while partnering across the SOC, threat intelligence, MSSPs, and distributed university partners. Ensures high-fidelity threat detection by operationalizing threat intel, optimizing SIEM tools (e.g., Splunk and Chronicle) and shaping detection logic, playbooks and standards. Drives cyber defense maturity across diverse systems, aligning with MITRE ATT&CK and other frameworks. Contributes to the development of detection standards, SOC engineering priorities, and incident readiness and response.

The Lead Analyst, Cyber Defense:

  • Coordinates and manages the response to actual and potential security breaches, engaging in the identification, triage, categorization of security incidents and events. Leads incident response efforts (e.g., investigation, remediation) during security breaches. Leads major incident investigations and complex forensic analysis of systems, logs, and artifacts inclusive of identifying, investigating, and responding to security incidents. Works with cyber defense team members to assign criticality and priority levels to security incidents and events. Actively reports on security incidents as they are escalated or identified to cyber leadership and management. Collaborates with SOC teams and MSSPs to support round-the-clock monitoring and triage.

  • Assists in the development and implementation of incident response policies and procedures to ensure a structured approach to handling security incidents. Assists with development and implementation of SIRPs, as well as detection, containment, eradication, and recovery strategies. Develops and maintains incident response plans specific to OT and IoT environments. Applies risk analysis techniques and strategies when evaluating the impact of cyber threats and vulnerabilities, as well as recommended remediation steps. Assists with design and delivery of incident response exercises to test client SIRP. Supports purple team initiatives and adjusts detections based on red team findings.

  • Communicates with university management and other cybersecurity teams during high-security events, following incident response guidelines and escalating issues when necessary. Works with information security officers (ISOs) and cyber governance to exchange information with IT directors and support departments, schools, or units (DSUs) in their recovery from incidents. Collaborates with the USC Office of Culture, Ethics and Compliance and Office of the General Counsel to build forensic case documentation, including chain-of-custody information, data categorization, and investigatory results. Provides executive communication, finished incident reports and forensics data, as appropriate, advising management on decisions that may significantly affect operations, policies, or procedures. Participates in and leads after-action reviews from tabletop exercises and major incidents.

  • Works with senior cyber defense analysts to analyze security logs, network traffic, and other data sources to identify indicators of compromise (IOC) and malicious activity. Forensically analyzes end-user systems and servers found to have possible IOC, as well as artifacts collected during a security incidents. Reviews and addresses false positives, collaborating with other cyber teams (including pro and managed service teams) to refine and improve the accuracy of security tool configuration rules and policies.

  • Documents security incidents and incident response activities; analyzes metrics and trends. Leads and conducts post-incident reviews and lessons learned sessions to identify areas for improvement. Produces and reviews related reports (e.g., incident reports, findings, impact assessments, remediation recommendations). Reviews analysis and conclusions of other analysts and/or consultants, when applicable. Supports digital forensic investigations on a variety of digital devices (e.g., computers, mobile devices, network systems). Ensures processes and procedures follow established standards, guidelines, and protocols. Maintains currency with legal, regulatory, and technological changes and/or advancements that may impact incident response operations; communicates changes to cyber defense leadership and staff.

  • Collaborates with senior cyber defense analyst and cyber threat team to stay informed about the latest threats, vulnerabilities, and attack vectors to enhance the organization's incident response capabilities. Maintains currency with emerging OT security trends, technologies, and compliance requirements. Supports performance analysis of detection and response workflows through KPIs and SLA metrics.

  • Encourages a workplace culture where all employees are valued, value others and have the opportunity to contribute through their ideas, words and actions, in accordance with the USC Code of Ethics.

MINIMUM QUALIFICATIONS

Great candidates for the position of Lead Analyst, Cyber Defense will meet the following qualifications:

  • 5 years in key Cyber Defense areas (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management).

  • Bachelor's degree or combined experience/education as substitute for minimum education.

  • Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations.

  • Significant experience in a SOC analyst or detection engineering role.

  • Experience in a senior incident response role or threat hunting capacity.

  • Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams.

  • Ability to work closely with other cybersecurity teams (e.g., cyber threat intelligence, cybersecurity monitoring).

  • Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams.

  • Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations. Familiarity with detection tuning languages and tooling.

  • Ability to develop and maintain incident response OT cybersecurity policies, standards, and related documentations.

  • Knowledge of industrial control systems (ICS).

  • Knowledge of digital forensics and incident response (DFIR), as well as digital forensic investigation processes related to OT/IoT systems.

  • Demonstrated understanding of security threats, vulnerabilities, intrusion techniques, malware capabilities and system diagnostics.

  • Demonstrated understanding of electronic investigation, forensic tools and methodologies (e.g., log correlation and analysis).

  • Experience with computer security investigative processes and malware identification and analysis. Experience with incident response and digital forensics across IT and cloud platforms.

  • Knowledge of network security zones, firewall configurations, and intrusion detection systems (IDS).

  • Familiarity with various log protocols/formats (e.g., syslog, logs, database logs) and the ability to perform forensic traceability.

  • Proficiency in packet capture and analysis, as well as experience with log management or security information management tools.

  • Experience with security assessment tools (e.g., NMAP, Nessus, Metasploit, Netcat).

  • Skill in log source validation and coverage assessment in a decentralized environment.

  • Ability to guide playbook design and SOC process improvement without formal management.

  • Demonstrated organizational, critical thinking and analytical skills; ability to assess cybersecurity risks and make informed decisions.

  • Excellent written and oral communication skills, and an exemplary attention to detail.

  • Ability to analyze complex data sets and logs to identify anomalies and potential threats.

  • In-depth knowledge of industry standards and regulations (e.g., ISO 27001, NIST CSF).

  • Ability to work evenings, weekends and holidays as the schedule dictates.

PREFERRED QUALIFICATIONS

Exceptional candidates for the position of Lead Analyst, Cyber Defense will also bring the following qualifications or more:

  • 7 years of related experience.

  • A bachelor’s degree in information science or computer science or computer engineering or in related field(s).

  • GIAC Certified Incident Handler (GCIH), GIAC Security Essentials (GSEC), or equivalent.

  • Cisco Certified CyberOps Associate or similar.

  • MITRE ATT&CK Defender certifications preferred.

In addition, the successful candidate must also demonstrate, through ideas, words and actions, a strong commitment to USC’s Unifying Values ( of integrity, excellence, community, well-being, open communication, and accountability.

SALARY AND BENEFITS

The annual base salary range for this position is $164,175.55 to $196,000. When extending an offer of employment, the University of Southern California considers factors such as (but not limited to) the scope and responsibilities of the position, the candidate’s work experience, education/training, key skills, internal peer alignment, federal, state, and local laws, contractual stipulations, grant funding, as well as external market and organizational considerations.

To support the well-being of our faculty and staff, USC provides benefits-eligible employees with a broad range of perks to help protect their and their dependents’ health, wealth, and future. These benefits are available as part of the overall compensation and total rewards package. You can learn more about USC’s comprehensive benefits here ( .

Join the USC cybersecurity team within an environment of innovation and excellence.

Minimum Education: Bachelor's degree Addtional Education Requirements Combined experience/education as substitute for minimum education Minimum Experience: 5 years in key Cyber Defense areas, (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management). Minimum Skills: Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations. Significant experience in a SOC analyst or detection engineering role. Experience in a senior incident response role or threat hunting capacity. Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams. Ability to work closely with other cybersecurity teams (e.g., cyber threat intelligence, cybersecurity monitoring). Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams. Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations. Familiarity with detection tuning languages and tooling. Ability to develop and maintain incident response OT cybersecurity policies, standards, and related documentations. Knowledge of industrial control systems (ICS). Knowledge of digital forensics and incident response (DFIR), as well as digital forensic investigation processes related to OT/IoT systems. Demonstrated understanding of security threats, vulnerabilities, intrusion techniques, malware capabilities and system diagnostics. Demonstrated understanding of electronic investigation, forensic tools and methodologies (e.g., log correlation and analysis). Experience with computer security investigative processes and malware identification and analysis. Experience with incident response and digital forensics across IT and cloud platforms. Knowledge of network security zones, firewall configurations, and intrusion detection systems (IDS). Familiarity with various log protocols/formats (e.g., syslog, logs, database logs) and the ability to perform forensic traceability. Proficiency in packet capture and analysis, as well as experience with log management or security information management tools. Experience with security assessment tools (e.g., NMAP, Nessus, Metasploit, Netcat). Skill in log source validation and coverage assessment in a decentralized environment. Ability to guide playbook design and SOC process improvement without formal management. Demonstrated organizational, critical thinking and analytical skills; ability to assess cybersecurity risks and make informed decisions. Excellent written and oral communication skills, and an exemplary attention to detail. Ability to analyze complex data sets and logs to identify anomalies and potential threats. In-depth knowledge of industry standards and regulations (e.g., ISO 27001, NIST CSF). Preferred Education: Bachelor's degree In Information Science Or Computer Science Or Computer Engineering Or in related field(s) Preferred Certifications: GIAC Certified Incident Handler (GCIH), GIAC Security Essentials (GSEC), or equivalent. Cisco Certified CyberOps Associate or similar. MITRE ATT&CK Defender certifications preferred. Preferred Experience: 7 years

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Lead Analyst, Cyber Defense in Los Angeles, CA vacancy
  •  ...Cyber Risk Defense Principal Advisor This senior level employee is primarily responsible for managing and directing the maintenance and protection...  ...to and learning from change, difficulties, and feedback. Leads team in the proactive monitoring and/or response to known or... 
    Cyber
    Full time
    Work experience placement
    Work from home
    Flexible hours
    Shift work

    Kaiser Permanente

    Pasadena, CA
    3 days ago
  • $86.6k - $150.4k

     ...that span satellite, launch, ground, and cyber systems for defense, civil and commercial customers. When...  ...on teams and collaborating with other analysts to expand their domain knowledge....  ...provide recommended solutions to technical leads, management, and customers Building... 
    Cyber
    Full time
    For contractors
    Work experience placement
    Immediate start
    Remote work
    Relocation package
    Flexible hours

    The Aerospace Corporation

    El Segundo, CA
    2 days ago
  • $129k - $249.6k

     ...innovative solutions that span satellite, launch, ground, and cyber systems for defense, civil and commercial customers. When you join our team,...  ...leaders, we want individuals who: Operate Strategically Lead Change Engage with Impact Foster Innovation... 
    Cyber
    Full time
    Immediate start
    Remote work
    Relocation package
    Flexible hours

    The Aerospace Corporation

    El Segundo, CA
    7 days ago
  • $128.1k - $239.6k

     ...prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and...  ...systems.    The opportunity The Active Defense team is responsible for four core areas:...  ...security.   In an Active Defense Analyst, we are looking for someone who has experience... 
    Cyber
    Summer holiday
    Local area
    Remote work
    Flexible hours
    Night shift
    Weekend work

    EY

    Los Angeles, CA
    2 days ago
  • $117.3k - $226.9k

     ...GPS Gen4 Satellite Lead (Project Engineer/Sr. Project Engineer – Systems Engineering – Acquisition) The Aerospace Corporation...  ...solutions that span satellite, launch, ground, and cyber systems for defense, civil and commercial customers. When you join our team, you... 
    Cyber
    Full time
    For contractors
    Work at office
    Immediate start
    Remote work
    Relocation package
    Flexible hours

    The Aerospace Corporation

    El Segundo, CA
    5 hours ago
  • $90k - $120k

     ...Information Security Analyst II The Marvin Group is a Strategic Partner for Global Alternate...  ...and Sustainment. The Marvin Group, a leading defense contractor, plays a crucial role in the...  ...the organization from all vectors of cyber-attacks including and not limited to network... 
    Cyber
    Permanent employment
    Contract work
    For contractors
    Work experience placement
    Work at office
    Flexible hours

    The Marvin Group

    Inglewood, CA
    11 days ago
  •  ...solutions in aerospace, biosecurity, and defense. We specialize in systems engineering, advanced...  ...for an experienced Senior Acquisition Lead to support our US Space Force, Space...  ...Executive Office (PEO) focused on delivering cyber, ground- and space-based systems that... 
    Cyber
    Contract work
    For contractors
    Work at office

    BryceTech

    El Segundo, CA
    1 day ago
  • $95.2k - $142.7k

     ...Senior Accountant/ Analyst ( Accounting Staff IV ) The Aerospace Corporation is...  ...that span satellite, launch, ground, and cyber systems for defense, civil and commercial customers. When...  ...weekly invoices to our primary customer; leading the month-end close process; preparing... 
    Cyber
    Full time
    Immediate start
    Remote work
    Relocation package
    Monday to Friday
    Flexible hours

    The Aerospace Corporation

    El Segundo, CA
    4 days ago
  • $131.75k - $178.25k

    Staff Analyst (Senior or Lead) Company: The Boeing Company Boeing Defense, Space & Security (BDS) is seeking a motivated and proactive Staff Analyst (Senior or Lead) to join our team in El Segundo, CA. The ideal candidate is a seasoned professional with a strong track record... 
    Permanent employment
    Full time
    Work experience placement
    Interim role
    Work at office
    Relocation
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work

    Boeing

    El Segundo, CA
    3 days ago
  •  ...Cybersecurity Analyst - Product Security Company: The Boeing Company Boeing is currently looking for a Product Security Analyst to...  ...states. A successful candidate will understand the importance of cyber security during all phases of a program and enjoy working... 
    Cyber
    Contract work

    Boeing

    El Segundo, CA
    16 days ago
  • $183.2k - $217.5k

     ...Modernization and Transformation business, focusing on Microsoft Security solutions. This role involves shaping client opportunities, leading technical and business discussions, and positioning modern SOC capabilities with emphasis on Microsoft Defender XDR and Microsoft... 
    Cyber
    Work at office
    Local area

    Avanade

    Los Angeles, CA
    4 days ago
  • $110k - $150k

     ...Lead Analyst, Corporate FPA LU Canada Corp. Litchfield Park, AZ, US, 85340Merrick, NY, US, 11566Bryson, TX, US, 76427Joplin, MO, US, 64801Tyler, TX, US, 75703Tahoe Vista, CA, US, 96148Downey, CA, US, 90241Joplin, MO, US, 64801Gainesville, GA, US, 30501Jackson, MO... 
    Work experience placement
    Local area
    Flexible hours

    Liberty Utilities

    Downey, CA
    8 hours ago
  • $120.8k - $151k

     ...Advanced Cyber Incident Response Leader This role provides leadership and expertise in advanced cyber incident response, forensic...  ...aligned with industry frameworks (NIST, MITRE ATT&CK, etc.). Lead and coordinate investigation and response activities for cybersecurity... 
    Cyber

    Sony Pictures Entertainment

    Culver City, CA
    5 days ago
  •  ...Data Analyst Job Location: Seattle, WA | San Francisco, CA | Los Angeles, CA (Onsite Day...  ...Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make reasonable...  ...thrive our resources to deliver industry-leading capabilities to our clients and customers... 
    Cyber

    InterSources

    Los Angeles, CA
    1 day ago
  • $30 - $32 per hour

    Job Description Job Description Position Summary:   Provides daily supervision, leadership and coordination in the maintenance of Regal Medical Group’s claims processing system.  Supports accuracy of member benefit set up, assignments, claims processing, financial...
    Hourly pay
    Full time
    Casual work
    Work at office
    Relocation package
    Flexible hours

    Regal Medical Group

    Los Angeles, CA
    9 hours ago
  • $80k - $140k

     ...Lead AI Enablement Analyst WHAT IS THE OPPORTUNITY? The Lead AI Enablement Analyst will serve as an operationally-focused right hand to the AI & Automation Manager, driving day-to-day execution of enterprise AI and automation initiatives while maintaining visibility... 
    Remote work

    City National Bank

    Los Angeles, CA
    1 day ago
  •  ...organization's Information Security Policy. This role involves coordinating and prioritizing key activities, formalizing cyber risk controls, and leading the team to ensure compliance and continuous control monitoring. The Director will also be tasked with establishing a... 
    Cyber
    Work experience placement

    Confidential

    Los Angeles, CA
    3 days ago
  •  ...members across North America, EMEA, and APAC. The TDR Senior Analyst brings deep technical expertise and acts as a functional leader...  ...Analysis ~ Incident Response & Management ~ Threat Hunting ~ Cyber Threat Intelligence ~ Network Security ~ Securing and... 
    Cyber
    Full time
    Part time
    Work at office
    Worldwide

    Worldwide Flight Services

    Los Angeles, CA
    5 days ago
  • $200k

     ...Description A nationally recognized litigation firm is seeking a Senior Cyber Security Class Action Associate Attorney to join its Los Angeles...  ..., and insurers in high-stakes litigation and class action defense matters. This role is ideal for an experienced litigator who... 
    Cyber
    Work at office
    Remote work
    Flexible hours

    Aionios

    Los Angeles, CA
    9 hours ago
  •  ...Risk Analyst Location: El Segundo, CA (3 day onsite and 2 day remote...  ...for internal and external cyber initiatives, including the annual...  ...exercises as required. Leads awareness and training for the...  ...actors and support the cyber defense program. Required Qualifications... 
    Cyber
    Work experience placement
    Remote work

    Software Technology Inc

    El Segundo, CA
    2 days ago
  • $112.2k - $176.3k

     ...systems and technologies. Our differentiated battle management and cyber ( solutions deliver timely, mission-enabling information and...  ...looking for you to join our team as a Principal Program Cost Control Analyst - Program Control Integrated Systems (PCIS) Tools . The... 
    Cyber
    Relocation
    Shift work

    Northrop Grumman

    Los Angeles, CA
    2 days ago
  •  ...Data/Business Analyst Responsibilities: We are looking for business/data analysts...  ...Analytics Infrastructure & Cloud Solutions, Cyber Security Services, etc. We make...  ...thrive our resources to deliver industry-leading capabilities to our clients and customers... 
    Cyber
    Temporary work

    InterSources

    Los Angeles, CA
    1 day ago
  • $85k - $120k

     ...'s Venable Blue team seeks an Analyst, Trust & Safety and Public Affairs...  ...serve as an important line of defense to help improve the quality...  ...& Safety approaches based on leading industry practices and latest...  ...data access, account takeover, cyber harassment, child safety, or a... 
    Cyber
    Work experience placement

    Venable LLP

    Los Angeles, CA
    6 hours ago
  • $130k - $160k

     ...alternate mission equipment and sustainment. The Marvin Group, a leading defense contractor, plays a crucial role in the development and...  ...migration projects in a lead role. Change management experience. Cyber security compliance experience within the development and security... 
    Cyber
    For contractors
    Work at office

    The Marvin Group

    Inglewood, CA
    1 day ago
  • $70k - $80k

     ...Risk Analyst Lead Location: Los Angeles, CA Job Type: Full-Time | Exempt | Eligible Remote Salary Range: $70,000 - $80,000 per year About Commercial Bank of California Commercial Bank of California (CBC) is the largest Latino-owned bank in... 
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Commercial Bank of California

    Los Angeles, CA
    4 days ago
  • $170k - $230k

     ...every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract...  ...operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our... 
    Cyber
    Temporary work
    Local area
    Immediate start
    Remote work
    Worldwide
    Relocation
    Flexible hours

    General Dynamics Information Technology

    El Segundo, CA
    2 days ago
  • $87.8k - $160.9k

     ...clients to build confidence and trust with their customers, the overall market and when required by regulation or contract. For our Cyber Risk services, the ideal candidate will be responsible for identifying, evaluating, and managing cyber risks across the organization... 
    Cyber
    Contract work
    Summer holiday
    Work at office
    Flexible hours

    EY

    Los Angeles, CA
    4 days ago
  •  ...for custom smartwatch faces, empowering a global community of creators and enthusiasts. We’re looking for our first dedicated Lead Data Analyst to own and scale Facer’s analytics and growth measurement function, helping the entire company make smarter, data-driven decisions... 
    Full time
    Part time
    Remote work
    Flexible hours

    Facer

    Los Angeles, CA
    4 days ago
  • $155.2k - $184.3k

     ...on client needs. About Avanade Security Avanade is the leading Microsoft Security services partner, helping organizations...  ...consulting, and managed services across identity, cloud security, cyber defense, and governance-combining deep technical expertise with real-... 
    Cyber
    Contract work
    Work at office
    Local area

    Avanade

    Los Angeles, CA
    4 days ago
  • $120k - $180k

     ...cutting-edge research and technology in the cyber arena, CPMG focuses on using business...  ...integrative solutions for Department of Defense (DoD) contractors, among others, and specializes...  ...collaboration and continuity, while leading the team Ability to develop financial plans... 
    Cyber
    For contractors
    Work at office
    Flexible hours

    CPMG

    Los Angeles, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Analyst, Cyber Defense. Be the first to apply!