Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Analyst, Cyber Defense

$164.18k - $196k
Full-time

University of Southern California

ABOUT THE DEPARTMENT The University of Southern California (USC) is committed to strengthening its cybersecurity posture through resilience, cyber risk management, and threat-informed defense. As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape. This role sits within USC’s cybersecurity organization, which is advancing threat-informed defense and operational excellence. You’ll join a team committed to scalable, proactive defense strategies, incident preparedness, and high-impact partnership across the university, working alongside experts who are deeply committed to service, innovation, and impact. If you’re driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your expertise to the table. POSITION SUMMARY As the Lead Analyst, Cyber Defense you will be an integral member of the cybersecurity department while also collaborating with stakeholders across the university ecosystem and reporting to the Manager, Cyber Defense. This is a full-time exempt position, eligible for all of USC’s fantastic Benefits + Perks. This opportunity is remote. The Lead Analyst, Cyber Defense serves as a technical authority responsible for elevating the university’s cyber detection and response posture. Leads advanced incident investigations, threat hunting and detection development while partnering across the SOC, threat intelligence, MSSPs, and distributed university partners. Ensures high-fidelity threat detection by operationalizing threat intel, optimizing SIEM tools (e.g., Splunk and Chronicle) and shaping detection logic, playbooks and standards. Drives cyber defense maturity across diverse systems, aligning with MITRE ATT&CK and other frameworks. Contributes to the development of detection standards, SOC engineering priorities, and incident readiness and response. The Lead Analyst, Cyber Defense: Coordinates and manages the response to actual and potential security breaches, engaging in the identification, triage, categorization of security incidents and events. Leads incident response efforts (e.g., investigation, remediation) during security breaches. Leads major incident investigations and complex forensic analysis of systems, logs, and artifacts inclusive of identifying, investigating, and responding to security incidents. Works with cyber defense team members to assign criticality and priority levels to security incidents and events. Actively reports on security incidents as they are escalated or identified to cyber leadership and management. Collaborates with SOC teams and MSSPs to support round-the-clock monitoring and triage. Assists in the development and implementation of incident response policies and procedures to ensure a structured approach to handling security incidents. Assists with development and implementation of SIRPs, as well as detection, containment, eradication, and recovery strategies. Develops and maintains incident response plans specific to OT and IoT environments. Applies risk analysis techniques and strategies when evaluating the impact of cyber threats and vulnerabilities, as well as recommended remediation steps. Assists with design and delivery of incident response exercises to test client SIRP. Supports purple team initiatives and adjusts detections based on red team findings. Communicates with university management and other cybersecurity teams during high-security events, following incident response guidelines and escalating issues when necessary. Works with information security officers (ISOs) and cyber governance to exchange information with IT directors and support departments, schools, or units (DSUs) in their recovery from incidents. Collaborates with the USC Office of Culture, Ethics and Compliance and Office of the General Counsel to build forensic case documentation, including chain-of-custody information, data categorization, and investigatory results. Provides executive communication, finished incident reports and forensics data, as appropriate, advising management on decisions that may significantly affect operations, policies, or procedures. Participates in and leads after-action reviews from tabletop exercises and major incidents. Works with senior cyber defense analysts to analyze security logs, network traffic, and other data sources to identify indicators of compromise (IOC) and malicious activity. Forensically analyzes end-user systems and servers found to have possible IOC, as well as artifacts collected during a security incidents. Reviews and addresses false positives, collaborating with other cyber teams (including pro and managed service teams) to refine and improve the accuracy of security tool configuration rules and policies. Documents security incidents and incident response activities; analyzes metrics and trends. Leads and conducts post-incident reviews and lessons learned sessions to identify areas for improvement. Produces and reviews related reports (e.g., incident reports, findings, impact assessments, remediation recommendations). Reviews analysis and conclusions of other analysts and/or consultants, when applicable. Supports digital forensic investigations on a variety of digital devices (e.g., computers, mobile devices, network systems). Ensures processes and procedures follow established standards, guidelines, and protocols. Maintains currency with legal, regulatory, and technological changes and/or advancements that may impact incident response operations; communicates changes to cyber defense leadership and staff. Collaborates with senior cyber defense analyst and cyber threat team to stay informed about the latest threats, vulnerabilities, and attack vectors to enhance the organization's incident response capabilities. Maintains currency with emerging OT security trends, technologies, and compliance requirements. Supports performance analysis of detection and response workflows through KPIs and SLA metrics. Encourages a workplace culture where all employees are valued, value others and have the opportunity to contribute through their ideas, words and actions, in accordance with the USC Code of Ethics. MINIMUM QUALIFICATIONS Great candidates for the position of Lead Analyst, Cyber Defense will meet the following qualifications: 5 years in key Cyber Defense areas (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management). Bachelor's degree or combined experience/education as substitute for minimum education. Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations. Significant experience in a SOC analyst or detection engineering role. Experience in a senior incident response role or threat hunting capacity. Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams. Ability to work closely with other cybersecurity teams (e.g., cyber threat intelligence, cybersecurity monitoring). Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams. Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations. Familiarity with detection tuning languages and tooling. Ability to develop and maintain incident response OT cybersecurity policies, standards, and related documentations. Knowledge of industrial control systems (ICS). Knowledge of digital forensics and incident response (DFIR), as well as digital forensic investigation processes related to OT/IoT systems. Demonstrated understanding of security threats, vulnerabilities, intrusion techniques, malware capabilities and system diagnostics. Demonstrated understanding of electronic investigation, forensic tools and methodologies (e.g., log correlation and analysis). Experience with computer security investigative processes and malware identification and analysis. Experience with incident response and digital forensics across IT and cloud platforms. Knowledge of network security zones, firewall configurations, and intrusion detection systems (IDS). Familiarity with various log protocols/formats (e.g., syslog, logs, database logs) and the ability to perform forensic traceability. Proficiency in packet capture and analysis, as well as experience with log management or security information management tools. Experience with security assessment tools (e.g., NMAP, Nessus, Metasploit, Netcat). Skill in log source validation and coverage assessment in a decentralized environment. Ability to guide playbook design and SOC process improvement without formal management. Demonstrated organizational, critical thinking and analytical skills; ability to assess cybersecurity risks and make informed decisions. Excellent written and oral communication skills, and an exemplary attention to detail. Ability to analyze complex data sets and logs to identify anomalies and potential threats. In-depth knowledge of industry standards and regulations (e.g., ISO 27001, NIST CSF). Ability to work evenings, weekends and holidays as the schedule dictates. PREFERRED QUALIFICATIONS Exceptional candidates for the position of Lead Analyst, Cyber Defense will also bring the following qualifications or more: 7 years of related experience. A bachelor’s degree in information science or computer science or computer engineering or in related field(s). GIAC Certified Incident Handler (GCIH), GIAC Security Essentials (GSEC), or equivalent. Cisco Certified CyberOps Associate or similar. MITRE ATT&CK Defender certifications preferred. In addition, the successful candidate must also demonstrate, through ideas, words and actions, a strong commitment to USC’s Unifying Values of integrity, excellence, community, well-being, open communication, and accountability. SALARY AND BENEFITS The annual base salary range for this position is $164,175.55 to $196,000. When extending an offer of employment, the University of Southern California considers factors such as (but not limited to) the scope and responsibilities of the position, the candidate’s work experience, education/training, key skills, internal peer alignment, federal, state, and local laws, contractual stipulations, grant funding, as well as external market and organizational considerations. To support the well-being of our faculty and staff, USC provides benefits-eligible employees with a broad range of perks to help protect their and their dependents’ health, wealth, and future. These benefits are available as part of the overall compensation and total rewards package. You can learn more about USC’s comprehensive benefits here. Join the USC cybersecurity team within an environment of innovation and excellence. Minimum Education: Bachelor's degree Addtional Education Requirements Combined experience/education as substitute for minimum education Minimum Experience: 5 years in key Cyber Defense areas, (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management). Minimum Skills: Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations. Significant experience in a SOC analyst or detection engineering role. Experience in a senior incident response role or threat hunting capacity. Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams. Ability to work closely with other cybersecurity teams (e.g., cyber threat intelligence, cybersecurity monitoring). Ability to coordinate and work efficiently with cybersecurity monitoring and threat intelligence managed service teams. Familiarity with security tools and solutions such as security information and event management (SIEM), intrusion detection/prevention systems (IDS/IPS), as well as endpoint protection solutions, network security zones, and firewall configurations. Familiarity with detection tuning languages and tooling. Ability to develop and maintain incident response OT cybersecurity policies, standards, and related documentations. Knowledge of industrial control systems (ICS). Knowledge of digital forensics and incident response (DFIR), as well as digital forensic investigation processes related to OT/IoT systems. Demonstrated understanding of security threats, vulnerabilities, intrusion techniques, malware capabilities and system diagnostics. Demonstrated understanding of electronic investigation, forensic tools and methodologies (e.g., log correlation and analysis). Experience with computer security investigative processes and malware identification and analysis. Experience with incident response and digital forensics across IT and cloud platforms. Knowledge of network security zones, firewall configurations, and intrusion detection systems (IDS). Familiarity with various log protocols/formats (e.g., syslog, logs, database logs) and the ability to perform forensic traceability. Proficiency in packet capture and analysis, as well as experience with log management or security information management tools. Experience with security assessment tools (e.g., NMAP, Nessus, Metasploit, Netcat). Skill in log source validation and coverage assessment in a decentralized environment. Ability to guide playbook design and SOC process improvement without formal management. Demonstrated organizational, critical thinking and analytical skills; ability to assess cybersecurity risks and make informed decisions. Excellent written and oral communication skills, and an exemplary attention to detail. Ability to analyze complex data sets and logs to identify anomalies and potential threats. In-depth knowledge of industry standards and regulations (e.g., ISO 27001, NIST CSF). Preferred Education: Bachelor's degree In Information Science Or Computer Science Or Computer Engineering Or in related field(s) Preferred Certifications: GIAC Certified Incident Handler (GCIH), GIAC Security Essentials (GSEC), or equivalent. Cisco Certified CyberOps Associate or similar. MITRE ATT&CK Defender certifications preferred. Preferred Experience: 7 years USC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, or any other characteristic protected by law or USC policy. USC observes affirmative action obligations consistent with state and federal law. USC will consider for employment all qualified applicants with criminal records in a manner consistent with applicable laws and regulations, including the Los Angeles County Fair Chance Ordinance for employers and the Fair Chance Initiative for Hiring Ordinance, and with due consideration for patient and student safety. Please refer to the Background Screening Policy Appendix D for specific employment screen implications for the position for which you are applying. We provide reasonable accommodations to applicants and employees with disabilities. Applicants with questions about access or requiring a reasonable accommodation for any part of the application or hiring process should contact USC Human Resources by phone at View phone number on click.appcast.io, or by email at View email address on click.appcast.io. Inquiries will be treated as confidential to the extent permitted by law. Notice of Non-discrimination Employment Equity Read USC’s Clery A

Vacancy posted 10 hours ago
Similar jobs that could be interesting for youBased on the Lead Analyst, Cyber Defense in United States vacancy
  •  ...Security Operation Center (SOC) Analyst 1 primary function is to...  ...comprehensive Computer Network Defense and Response support through 2...  ...requires a solid understanding of cyber threats and information...  ...defense operations, ability to lead efforts in Incident Handling (... 
    Cyber
    Work at office

    IC-CAP, LLC

    Colorado Springs, CO
    17 hours ago
  •  ...Senior Soc Analyst T3 Lead Merlin Group operates at the intersection of cyber innovation, national security, and technology-driven transformation. With a mission...  ...our customers rely on. From next-generation cyber defense to secure cloud and AI, we are united by one purpose... 
    Cyber
    Work at office
    Local area
    Shift work

    Merlin Cyber

    McLean, VA
    2 days ago
  • $127k - $140k

    Deepwatch is looking for an Incident Response Analyst located in the United States, Colorado....  ...role requires a candidate proficient in leading incident response investigations and...  ...environments to defend organizations against cyber threats. Responsibilities include... 
    Cyber
    Remote job

    Deepwatch

    Denver, CO
    2 days ago
  • $173k - $224k

    RealmOne is hiring for a Signals Analyst 3 in Columbia, MD. Ideal candidates need a Doctoral degree with 7 years of experience or equivalent qualifications in engineering and cybersecurity. Responsibilities include conducting signals analysis to enhance national security... 
    Cyber

    RealmOne

    Columbia, MD
    2 days ago
  • A healthcare organization is looking for a senior cybersecurity professional to manage and enhance the security of data and systems. This role requires overseeing threat monitoring, coordinating responses to incidents, and collaborating with various teams to improve security...
    Cyber

    Kaiser Permanente

    Renton, WA
    1 day ago
  • $129.5k - $240.5k

     ...L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs...  ...the space, air, land, sea and cyber domains in the interest of national security. Job Title: Lead, Business Intelligence Analyst - People Analytics Job Code: 37660... 
    Cyber
    Local area
    Remote work
    Flexible hours

    L3Harris

    Melbourne, FL
    1 day ago
  •  ...is an expert responsible for leading high-impact initiatives, providing...  ...challenges. The analyst operates with significant autonomy...  ...and solutions in the areas of defense, security, intelligence, infrastructure...  ...uniquely qualified to deliver cyber/converged security, technology... 
    Cyber
    Local area
    Worldwide
    Flexible hours

    Parsons Company

    Springfield, VA
    6 days ago
  • $40 per hour

    A cybersecurity solutions provider is seeking experienced professionals to evaluate AI-generated security content and solve technical problems. Applicants should have 2+ years of hands-on cybersecurity experience and coding skills. This role is remote, allowing candidates...
    Cyber
    Hourly pay
    Remote work

    DataAnnotation

    Jackson, MS
    4 days ago
  • $40 per hour

    A cybersecurity technology firm is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. This remote position allows you to work on your own schedule with hourly pay starting at $40+. Ideal candidates should...
    Cyber
    Hourly pay
    Remote work

    DataAnnotation

    Wyoming, OH
    4 days ago
  • $40 per hour

    A leading AI cybersecurity firm is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. This role requires at least 2 years of hands-on experience in cybersecurity and offers the flexibility of working on... 
    Cyber
    Hourly pay
    Remote work

    DataAnnotation

    Topeka, KS
    2 days ago
  • $40 per hour

    A cybersecurity firm is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. This remote role offers flexibility in project selection, requiring 2+ years of hands-on experience in cybersecurity, some coding...
    Cyber
    Hourly pay
    Remote work

    DataAnnotation

    Springfield, IL
    17 hours ago
  • $40 per hour

    A cybersecurity solutions provider is seeking experienced cybersecurity professionals to join their team remotely. In this role, you will evaluate AI-generated cybersecurity content and solve technical challenges to enhance AI systems. Candidates should have over 2 years...
    Cyber
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Lincoln, NE
    4 days ago
  • $40 per hour

    A cybersecurity company is looking for experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. The ideal candidate has at least 2 years of hands-on experience in various cybersecurity domains, coding skills, and fluency...
    Cyber
    Hourly pay
    Remote work

    DataAnnotation

    Honolulu, HI
    17 hours ago
  • $40 per hour

    A cybersecurity solutions company seeks experienced professionals to evaluate AI-generated security content and solve technical problems. In this remote role, you will use your skills in penetration testing and incident response to validate AI outputs and enhance security...
    Cyber
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Florida, NY
    4 days ago
  • $104k - $166k

     ...CSOC Lead Analyst Job Locations US-OR-Portland Requisition ID 2026-162633 Position Category Cyber Security Clearance Public Trust Responsibilities...  ..., to remediate issues or improve defensive posture to CSOC and security... 
    Cyber
    Contract work
    Temporary work
    Shift work

    Peraton

    Portland, OR
    2 days ago
  • $96.8k - $161.5k

     ...NISSC 3 Configuration Analyst, Lead Location US-CO-Colorado Springs ID...  ...to support The North American Aerospace Defense Command (NORAD), Cheyene Mountain Complex...  ...Secret/ SCI Education: Bachelors in IT, Cyber, CS, IS, Data Science, or SW Engineering... 
    Cyber
    Full time
    Contract work
    Remote work

    American Systems

    Colorado Springs, CO
    17 hours ago
  • $40 per hour

    A cybersecurity innovations company is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. Candidates should have at least 2 years of hands-on cybersecurity experience and be fluent in English. This offers...
    Cyber
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Brooklyn, NY
    17 hours ago
  • $40 per hour

    A cybersecurity firm is looking for experienced professionals to evaluate AI-generated security content and solve technical problems. The role is flexible, allowing you to work from anywhere in the US, Canada, UK, Ireland, Australia, or New Zealand. Candidates should have...
    Cyber
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Madison, WI
    4 days ago
  • $40 per hour

    A cybersecurity innovation firm is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity issues. This remote role allows flexible project selection and scheduling, with competitive hourly pay starting at $40. Candidates...
    Cyber
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    El Paso, TX
    2 days ago
  • $40 per hour

    A cybersecurity firm is seeking experienced professionals for a flexible, remote role evaluating AI-generated security content. Candidates will assess the accuracy of AI outputs and provide feedback to improve AI security models. A minimum of 2 years' experience in cybersecurity...
    Cyber
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Phoenix, AZ
    4 days ago
  • $40 per hour

    A cybersecurity firm is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. Candidates should have over 2 years of hands-on experience in areas like penetration testing or incident response. This position...
    Cyber
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Nashville, TN
    4 days ago
  • A leading cybersecurity solutions provider is seeking experienced cybersecurity professionals to enhance AI models. In this remote role, you will evaluate AI-generated security content and solve cybersecurity-related technical problems. With flexible hours and project choice... 
    Cyber
    Remote work
    Flexible hours

    DataAnnotation

    Helena, MT
    17 hours ago
  • A cybersecurity-focused company is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. Responsibilities include designing security evaluations and providing feedback to enhance AI systems. Candidates should...
    Cyber
    Remote work
    Flexible hours

    DataAnnotation

    Indiana, PA
    4 days ago
  • A leading cybersecurity company is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. This role offers full-time or part-time remote working options, where you can choose projects and maintain a flexible... 
    Cyber
    Full time
    Part time
    Remote work
    Flexible hours

    DataAnnotation

    Vermont
    4 days ago
  • A global semiconductor leader in Wilmington, MA, is seeking a Senior SOC Analyst with expertise in Cyber Threat Intelligence. This role involves leading investigations into advanced threats, enhancing detection capabilities, and mentoring team members. Candidates should... 
    Cyber

    Analog Devices

    Wilmington, MA
    17 hours ago
  •  ...Insider Threat Analyst Lead cFocus Software seeks an Insider Threat Analyst Lead to join our program supporting the Administrative Office...  ...Cybersecurity Triage, Incident Response, Threat Hunting, and Cyber Threat Intelligence teams to support enterprise-wide insider... 
    Cyber
    Work at office

    cFocus Software

    Washington DC
    4 days ago
  • $157k - $224k

     ...Lead All-Source Analyst Arlington, VA STR is seeking a Lead All-source Analyst and Modeling Engineer...  ...research and development of models of cyber physical systems. Work must be...  ...advanced research and development for defense, intelligence, and national security in... 
    Cyber
    Full time
    Work experience placement
    Work at office
    Local area
    Night shift

    Science & Technology Research (STR)

    Arlington, VA
    11 days ago
  • $40 per hour

    A technology-driven cybersecurity firm is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. Candidates should have over two years of experience in areas like penetration testing, incident response, or...
    Cyber
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Denver, CO
    4 days ago
  • A leading semiconductor company seeks a Senior SOC Analyst in Wilmington, MA, to enhance their Cyber Threat Intelligence capabilities. The ideal candidate will lead complex investigations, mentor junior analysts, and drive improvements in threat detection and response.... 
    Cyber

    Analog Devices, Inc.

    Wilmington, MA
    2 days ago
  • $168k - $195k

     ...Principal Lead Analyst of DART At Corebridge Financial, we believe action is everything. That's why every day we partner with financial...  ...of DART, you are the ultimate technical authority for cyber defense and incident response. This is a high-impact leadership role... 
    Cyber
    Work at office
    Local area
    Immediate start
    Remote work
    Shift work

    Corebridge Financial

    Jersey City, NJ
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Analyst, Cyber Defense. Be the first to apply!