Senior Analyst, Cyber Defense
Listed on 2026-02-07
-
IT/Tech
Cybersecurity, Security Manager
ABOUT THE DEPARTMENT
The University of Southern California (USC) is advancing its cybersecurity posture with a renewed focus on resilience, cyber risk management, and threat-informed defense. As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape.
This role sits within a newly restructured cybersecurity organization that's leading this transformation. You'll join a team focused on scalable, proactive defense strategies, incident preparedness, and operational excellence—working alongside experts who are deeply committed to service, innovation, and impact.
If you're driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your leadership to the table.
POSITION SUMMARYAs the Senior Analyst, Cyber Defense
, you will be an integral member of the cybersecurity department, partnering closely with internal stakeholders across the university ecosystem and reporting to the Manager, Cyber Defense. This is a full-time exempt position, eligible for USC's Benefits + Perks. This opportunity is remote.
The Senior Analyst, Cyber Defense plays a hands-on role in responding to and investigating security incidents across a large, decentralized university environment. This role focuses on identifying, triaging, and analyzing security incidents and events; executing incident response and forensic investigations; and validating detections related to phishing, SaaS-based attacks, credential misuse, and other threats. The role works closely with Tier 1 analysts, MSSP partners, and threat intelligence teams;
executes SOAR playbooks; and contributes to continuous improvements in detection, response, and incident handling. The Senior Analyst documents findings, performs root cause analysis, and supports the development and refinement of incident response and recovery strategies.
The Senior Analyst, Cyber Defense will:
Oversees, coordinates, and manages the response to actual and potential security breaches, engaging in the identification, triage, categorization of security incidents and events. Leads, coordinates, and manages in-depth investigations and forensic analysis on endpoints, servers, and network data, resolving incidents by identifying root causes and solutions; implements remediation actions as necessary. Works with cyber defense team members to assign criticality and priority levels to security incidents and events.
Executes SOAR playbooks to drive consistent response actions; suggests automation improvements. Actively reports on security incidents and events as they are escalated or identified to cyber leadership and management. Maintains detailed documentation of incidents, including timelines, actions taken, and lessons learned.Develops and implements security incident response plans (SIRPs), as well as detection, containment, eradication, and recovery strategies. Follows and executes defined incident processes and procedures as well as SIRPs when investigating security incidents and events. Applies risk analysis techniques and critical thinking strategies when evaluating the impact of cyber threats and vulnerabilities, as well as recommended remediation steps. Designs and delivers incident response exercises to test client SIRPs.
Supports digital forensic investigations on a variety of digital devices (e.g., computers, mobile devices, network systems).Works with cyber defense team members and lead security operations center analyst to assign criticality and priority levels to security incidents and events. Conducts in-depth investigations of security incidents, utilizing forensic tools and techniques to identify root causes and gather evidence. Communicates with university management and other cybersecurity teams during high-security events, following incident response guidelines. Collaborates with MSSP analysts to investigate escalated alerts and validate detection logic.
Works with information security officers (ISOs) and cyber governance to exchange information with IT directors and support departments, schools, or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).