This opportunity is remote. The Lead Analyst, Attack Surface Management (ASM) responsible for ... Conducts vulnerability assessments, penetration testing, compliance, and risk management activities.
This opportunity is remote. The Lead Analyst, Attack Surface Management (ASM) responsible for ... Conducts vulnerability assessments, penetration testing, compliance, and risk management activities.
This opportunity is remote. The Lead Analyst, Attack Surface Management (ASM) responsible for ... Conducts vulnerability assessments, penetration testing, compliance, and risk management activities.
This opportunity is remote. The Lead Analyst, Attack Surface Management (ASM) responsible for ... Conducts vulnerability assessments, penetration testing, compliance, and risk management activities.
This opportunity is remote. The Lead Analyst, Attack Surface Management (ASM) responsible for ... Conducts vulnerability assessments, penetration testing, compliance, and risk management activities.
This opportunity is remote. The Lead Analyst, Attack Surface Management (ASM) responsible for ... Conducts vulnerability assessments, penetration testing, compliance, and risk management activities.
Manager of IT Security (Remote)
Carson, CA · Remote
Medical
Dental
Vision
Retirement
PTO
This is a remote role; candidates must be able to work effectively in a distributed environment and ... Guiding your team through the day-to-day work of vulnerability management, incident detection and ...
Quick apply
Manager of IT Security (Remote)
Carson, CA · Remote
Medical
Dental
Vision
Retirement
PTO
This is a remote role; candidates must be able to work effectively in a distributed environment and ... Guiding your team through the day-to-day work of vulnerability management, incident detection and ...
Manager of IT Security (Remote)
Carson, CA · Remote
$123K - $185K/yr
Medical
Dental
Vision
Retirement
PTO
This is a remote role; candidates must be able to work effectively in a distributed environment and ... Guiding your team through the day-to-day work of vulnerability management, incident detection and ...
Manager of IT Security (Remote)
Carson, CA · Remote
$123K - $185K/yr
Medical
Dental
Vision
Retirement
PTO
This is a remote role; candidates must be able to work effectively in a distributed environment and ... Guiding your team through the day-to-day work of vulnerability management, incident detection and ...
Product Security Engineer
San Jose, CA · On-site +1
$74.16 - $92.70/hr
Medical
Dental
Vision
Retirement
Product Security Engineer Full-time Remote You'll be joining Adobe on a contract opportunity ... Manage vulnerability backlog and enable risk hygiene across products Here's What You'll Need to Be ...
Product Security Engineer
San Jose, CA · On-site +1
$74.16 - $92.70/hr
Medical
Dental
Vision
Retirement
Product Security Engineer Full-time Remote You'll be joining Adobe on a contract opportunity ... Manage vulnerability backlog and enable risk hygiene across products Here's What You'll Need to Be ...
Network Security Engineer
San Francisco, CA · On-site +1
$123K - $168K/yr
Vulnerability Management & Risk Reduction * Oversee vulnerability assessments, penetration testing ... Architect secure, low-latency remote access and mesh VPN solutions for intra-fleet communication ...
Network Security Engineer
San Francisco, CA · On-site +1
$123K - $168K/yr
Vulnerability Management & Risk Reduction * Oversee vulnerability assessments, penetration testing ... Architect secure, low-latency remote access and mesh VPN solutions for intra-fleet communication ...
Security Operations Expert - AI Trainer
San Francisco, CA · Remote
$80 - $90/hr
Remote Role Responsibilities * Construct cybersecurity scenarios spanning security operations center monitoring , incident response and forensics , vulnerability management , and security ...
New
Quick apply
Security Operations Expert - AI Trainer
San Francisco, CA · Remote
$80 - $90/hr
Remote Role Responsibilities * Construct cybersecurity scenarios spanning security operations center monitoring , incident response and forensics , vulnerability management , and security ...
New
Threat & vulnerability management, such as vulnerability scanning & penetration tests * Database ... Asia Pacific (Remote) Estimated Annual Salary : 15K-35K USD / year Number of Positions: 2 Position ...
Threat & vulnerability management, such as vulnerability scanning & penetration tests * Database ... Asia Pacific (Remote) Estimated Annual Salary : 15K-35K USD / year Number of Positions: 2 Position ...
Threat & vulnerability management, such as vulnerability scanning & penetration tests * Database ... US (Remote) Estimated Annual Salary : 105K - 196K USD / year Number of Positions: 1 Position Type
Threat & vulnerability management, such as vulnerability scanning & penetration tests * Database ... US (Remote) Estimated Annual Salary : 105K - 196K USD / year Number of Positions: 1 Position Type
Perform vulnerability management activities, based on internal and external scans, and coordinate ... Experience working remotely - this is a remote position. * Professional certifications such as ...
Quick apply
Perform vulnerability management activities, based on internal and external scans, and coordinate ... Experience working remotely - this is a remote position. * Professional certifications such as ...
Perform vulnerability management activities, based on internal and external scans, and coordinate ... Experience working remotely - this is a remote position. * Professional certifications such as ...
Quick apply
Perform vulnerability management activities, based on internal and external scans, and coordinate ... Experience working remotely - this is a remote position. * Professional certifications such as ...
Perform vulnerability management activities, based on internal and external scans, and coordinate ... Experience working remotely - this is a remote position. * Professional certifications such as ...
Quick apply
Perform vulnerability management activities, based on internal and external scans, and coordinate ... Experience working remotely - this is a remote position. * Professional certifications such as ...
Security Engineer - AI Coding Agent
San Francisco, CA · Remote
$85/hr
Remote Role Responsibilities * Use frontier AI coding agents to complete and evaluate complex ... vulnerability management . * Regular use of AI coding agents such as Cursor, Claude Code, Codex ...
Quick apply
Security Engineer - AI Coding Agent
San Francisco, CA · Remote
$85/hr
Remote Role Responsibilities * Use frontier AI coding agents to complete and evaluate complex ... vulnerability management . * Regular use of AI coding agents such as Cursor, Claude Code, Codex ...
Senior Staff Security Engineer - (Agentic Systems)
San Francisco, CA · On-site +1
Retirement
Demonstrable technical expertise in managing complex security programs such as Vulnerability ... Unless approved for full remote work, employees must spend at least 50% of their time in-office.
Senior Staff Security Engineer - (Agentic Systems)
San Francisco, CA · On-site +1
Retirement
Demonstrable technical expertise in managing complex security programs such as Vulnerability ... Unless approved for full remote work, employees must spend at least 50% of their time in-office.
Director of Production Engineering
San Francisco, CA · Remote
$220K - $265K/yr
Medical
Dental
Vision
Retirement
PTO
Lead the organization's security operations (SecOps) practice, including vulnerability management ... As a fully remote employer, pay for positions is determined using local, national, and industry ...
Director of Production Engineering
San Francisco, CA · Remote
$220K - $265K/yr
Medical
Dental
Vision
Retirement
PTO
Lead the organization's security operations (SecOps) practice, including vulnerability management ... As a fully remote employer, pay for positions is determined using local, national, and industry ...
Security Engineer
Los Angeles, CA · On-site +1
Secure coding practices, vulnerability management, and integration into DevOps pipelines. • Cloud Security: Implement Zero Trust architectures, secure CI/CD workflows, and automate compliance in ...
Security Engineer
Los Angeles, CA · On-site +1
Secure coding practices, vulnerability management, and integration into DevOps pipelines. • Cloud Security: Implement Zero Trust architectures, secure CI/CD workflows, and automate compliance in ...
Senior Cyber Security Engineer
Milpitas, CA · On-site +1
$130K - $179K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Build and mature vulnerability management programs, including prioritization and remediation ... Assess and secure third-party access (vendors, OEMs, remote maintenance channels) * Evaluate risks ...
Quick apply
Senior Cyber Security Engineer
Milpitas, CA · On-site +1
$130K - $179K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Build and mature vulnerability management programs, including prioritization and remediation ... Assess and secure third-party access (vendors, OEMs, remote maintenance channels) * Evaluate risks ...
Senior Cyber Security Engineer
Milpitas, CA · On-site +1
$130K - $179K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Build and mature vulnerability management programs, including prioritization and remediation ... Assess and secure third-party access (vendors, OEMs, remote maintenance channels) * Evaluate risks ...
Senior Cyber Security Engineer
Milpitas, CA · On-site +1
$130K - $179K/yr
Medical
Dental
Vision
Life
Retirement
PTO
Build and mature vulnerability management programs, including prioritization and remediation ... Assess and secure third-party access (vendors, OEMs, remote maintenance channels) * Evaluate risks ...
CMMC Security Engineer
Los Angeles, CA · On-site +1
Lead vulnerability assessments, scan remediation tracking, and continuous risk management across hybrid and cloud environments. * Support incident response, threat hunting, and forensic analysis for ...
CMMC Security Engineer
Los Angeles, CA · On-site +1
Lead vulnerability assessments, scan remediation tracking, and continuous risk management across hybrid and cloud environments. * Support incident response, threat hunting, and forensic analysis for ...
Remote Vulnerability Management information
See California salary details
$33.1K - $45.7K
1% of jobs
$45.7K - $58.3K
0% of jobs
$58.3K - $70.9K
0% of jobs
$70.9K - $83.5K
0% of jobs
$83.5K - $96.1K
4% of jobs
$107.9K is the 25th percentile. Wages below this are outliers.
$96.1K - $108.7K
21% of jobs
$108.7K - $121.3K
15% of jobs
The median wage is $131K / yr.
$121.3K - $133.9K
12% of jobs
$133.9K - $146.5K
14% of jobs
$146.5K - $159.1K
7% of jobs
$159.7K is the 75th percentile. Wages above this are outliers.
$159.1K - $171.7K
26% of jobs
$33.1K
$135.9K
$171.7K
How much do remote vulnerability management jobs pay per year?
What are some typical challenges faced in remote vulnerability management?
Professionals in Remote Vulnerability Management often encounter challenges such as coordinating remediation efforts across global teams, prioritizing vulnerabilities in large, complex environments, and keeping up with rapidly evolving cyber threats. Working remotely also requires proactive communication to ensure all stakeholders stay informed and aligned on security initiatives. You will need to adapt to different IT infrastructures and collaborate effectively with both technical and non-technical colleagues. Successfully navigating these challenges builds your problem-solving skills and deepens your expertise in protecting organizational assets.
What is remote vulnerability management?
A Remote Vulnerability Management job involves identifying, assessing, and mitigating security vulnerabilities in an organization's systems, networks, and applications from a remote location. Professionals in this role use various tools to scan for weaknesses, analyze risks, and collaborate with IT and security teams to implement remediation measures. They also monitor threat intelligence, ensure compliance with security policies, and generate reports on findings. Strong knowledge of cybersecurity frameworks, vulnerability assessment tools, and risk management is crucial for success in this role.
What are the key skills and qualifications needed to thrive in remote vulnerability management?
To thrive in Remote Vulnerability Management, you need a solid understanding of cybersecurity principles, vulnerability assessment, and risk mitigation, often supported by a degree in information security or related certifications such as CompTIA Security+ or CISSP. Familiarity with vulnerability scanning tools like Nessus, Qualys, or Rapid7, as well as experience with SIEM platforms and ticketing systems, is essential. Strong analytical skills, problem-solving abilities, and effective written communication are critical for collaborating with distributed teams and reporting findings. These skills ensure accurate identification, remediation of security risks, and smooth teamwork in a remote, fast-paced digital environment.

Full-time
Posted 13 days ago
Job description
The University of Southern California (USC) is advancing its cybersecurity posture with a renewed focus on resilience, cyber risk management, and threat-informed defense. As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape.
This role sits within a newly restructured cybersecurity organization that's leading this transformation. You'll join a team focused on scalable, proactive defense strategies, incident preparedness, and operational excellence-working alongside experts who are deeply committed to service, innovation, and impact.
If you're driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your leadership to the table.
POSITION SUMMARY
As the Lead Analyst, Attack Surface Management (ASM) you will be an integral leader of the cybersecurity department while also collaborating with stakeholders across the university ecosystem, and reporting to the ASM Manager. This is a full-time exempt position, eligible for all of USC's fantastic Benefits + Perks. This opportunity is remote.
The Lead Analyst, Attack Surface Management (ASM) responsible for identifying, assessing, and mitigating security vulnerabilities across our organization's systems, networks, and applications and supports attack surface management operations. Conducts vulnerability assessments, penetration testing, compliance, and risk management activities. Oversees the university's attack surface and vulnerability lifecycle management process, (e.g., detection, monitoring, reporting, and assessing the impact of vulnerabilities) with focus on continuous improvement to mitigate risks associated with vulnerabilities, application security, and cyber threat intelligence. Develops and implements remediation strategies to address vulnerabilities and minimize the university's attack surface. Directly supports program maturity efforts and plays a key role in integrating threat intelligence into the broader university environment.
The Lead Analyst, Attack Surface Management (ASM) will:
Oversees the vulnerability lifecycle management process (e.g., detection, monitoring, reporting, and assessing the impact of vulnerabilities). Supports regular vulnerability assessments and scans to identify security weaknesses in systems, applications, networks, and OT/IoT environment.
Develops and implements remediation strategies to address vulnerabilities and minimize the university's attack surface. Implements remediation required by audits. Engages with DSUs to advise on remediation strategies of vulnerabilities.
Collaborates with IT teams and stakeholders to validate effective end-to-end vulnerability remediation and maintain a consistent customer experience. Collaborates with VM managed service teams and manages daily operations and communications. Evaluates vulnerability trends in third-party applications and services and collaborates with managed service providers as needed.
Serves as an ASM subject matter expert, formulating and prioritizing intelligence requirements according to established risk management framework. Participates in and influences the roadmap for the university's vulnerability management program.
Collaborates on detailed reports on vulnerabilities, their impact, and the status of remediation efforts and communicates findings to stakeholders. Provides expertise to help develop and maintain vulnerability and attack surface management policies, procedures, and best practices for the university.
Maintains awareness and knowledge of current changes within legal, regulatory, and technology environments which may affect operations. Maintains awareness of current university threat intelligence feeds and reports to stay informed about emerging threats and vulnerabilities that may affect the organization's attack surface. Maintains knowledge of emerging vulnerabilities, exploits, and remediation techniques.
Encourages a workplace culture where all employees are valued, value others and have the opportunity to contribute through their ideas, words and actions, in accordance with the USC Code of Ethics.
MINIMUM QUALIFICATIONS
Great candidates for the position of Lead Analyst, Attack Surface Management (ASM) will meet the following qualifications:
5 years in attack surface and vulnerability management.
A bachelor's degree or combined experience/education as substitute for minimum education.
Knowledge of the following frameworks: NIST Cybersecurity Framework (NIST CSF), ISO/IEC 27001, MITRE ATT&CK
Framework, OWASP Top Ten, CIS Controls, COBIT, SANS Critical Security Controls, PCI DSS, NIST SP 800-53, and ITIL.
Strong understanding of ASM/vulnerability management, security testing practices, and methodologies.
Understanding and technical knowledge of Cyber Defense concepts, (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management).
Understanding of Operational Technology environments and security requirements needed to manage the broader attack landscape across the university.
Experience in building infrastructure and application vulnerability management programs.
Experience in deploying and operating vulnerability scanning infrastructure and services and deep understanding of vulnerability scanning platforms.
Comprehensive knowledge of cloud-native vulnerability practices in AWS, Azure, and SaaS platforms and associated security challenges.
Ability to assess business risks and recommend suitable cybersecurity measures.
Experience in managing vulnerability assessment tools.
Knowledge of system, application, and database hardening techniques.
Strong communication and interpersonal skills, enabling effective interaction across all organizational levels, along with proven analytical and problem-solving abilities, and exceptional attention to detail.
Project management experience with a track record of leading complex security initiatives, coupled with the ability to teach and train others effectively.
Ability to work with teams across the cybersecurity function, with managed service providers, and with IT teams across the university.
Ability to work evenings, weekends and holidays as the schedule dictates.
PREFERRED QUALIFICATIONS
Exceptional candidates for the position of Lead Analyst, Attack Surface Management (ASM) will also bring the following qualifications or more:
7 years of related experience.
A bachelor's degree or combined experience/education as substitute for minimum education.
Experience working in higher education or complex, decentralized environments.
CISSP, GCIH, GPEN, Security+, or similar.
In addition, the successful candidate must also demonstrate, through ideas, words and actions, a strong commitment to USC's Unifying Values of integrity, excellence, community, well-being, open communication, and accountability.
SALARY AND BENEFITS
The annual base salary range for this position is $162,315.11-$201.452.98. When extending an offer of employment, the University of Southern California considers factors such as (but not limited to) the scope and responsibilities of the position, the candidate's work experience, education/training, key skills, internal peer alignment, federal, state, and local laws, contractual stipulations, grant funding, as well as external market and organizational considerations.
To support the well-being of our faculty and staff, USC provides benefits-eligible employees with a broad range of perks to help protect their and their dependents' health, wealth, and future. These benefits are available as part of the overall compensation and total rewards package. You can learn more about USC's comprehensive benefits here.
Join the USC cybersecurity team within an environment of innovation and excellence.
Minimum Education: Bachelor's degreeAddtional Education Requirements Combined experience/education as substitute for minimum education
Minimum Experience: 5 years in attack surface and vulnerability management.
Minimum Skills: Knowledge of the following frameworks: NIST Cybersecurity Framework (NIST CSF), ISO/IEC 27001, MITRE ATT&CK Framework, OWASP Top Ten, CIS Controls, COBIT, SANS Critical Security Controls, PCI DSS, NIST SP 800-53, and ITIL. Strong understanding of ASM/vulnerability management, security testing practices, and methodologies. Understanding and technical knowledge of Cyber Defense concepts, (e.g., incident response, security monitoring, cyber threat intelligence, attack surface and vulnerability management). Understanding of Operational Technology environments and security requirements needed to manage the broader attack landscape across the university. Experience in building infrastructure and application vulnerability management programs. Experience in deploying and operating vulnerability scanning infrastructure and services and deep understanding of vulnerability scanning platforms. Comprehensive knowledge of cloud-native vulnerability practices in AWS, Azure, and SaaS platforms and associated security challenges. Ability to assess business risks and recommend suitable cybersecurity measures. Experience in managing vulnerability assessment tools. Knowledge of system, application, and database hardening techniques. Strong communication and interpersonal skills, enabling effective interaction across all organizational levels, along with proven analytical and problem-solving abilities, and exceptional attention to detail. Project management experience with a track record of leading complex security initiatives, coupled with the ability to teach and train others effectively. Ability to work with teams across the cybersecurity function, with managed service providers, and with IT teams across the university.
Preferred Education: Bachelor's degree In Information Science Or Computer Science Or Computer Engineering Or in related field(s)
Preferred Certifications: CISSP, GCIH, GPEN, Security+, or similar.
Preferred Experience: 7 years
Preferred Skills: Experience working in higher education or complex, decentralized environments.
USC is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, or any other characteristic protected by law or USC policy. USC observes affirmative action obligations consistent with state and federal law. USC will consider for employment all qualified applicants with criminal records in a manner consistent with applicable laws and regulations, including the Los Angeles County Fair Chance Ordinance for employers and the Fair Chance Initiative for Hiring Ordinance, and with due consideration for patient and student safety. Please refer to theBackground Screening Policy Appendix Dfor specific employment screen implications for the position for which you are applying.
We provide reasonable accommodations to applicants and employees with disabilities. Applicants with questions about access or requiring a reasonable accommodation for any part of the application or hiring process should contact USC Human Resources by phone at (213) 821-8100, or by email atuschr@usc.edu. Inquiries will be treated as confidential to the extent permitted by law.
- Notice of Non-discrimination
- Employment Equity
- Read USC's Clery Act Annual Security Report
- USC is a smoke-free environment
- Digital Accessibility
If you are a current USC employee, please apply to this USC job posting in Workday by copying and pasting this link into your browser:
https://wd5.myworkday.com/usc/d/inst/1$9925/9925$150961.htmldAbout USC Auxiliary Services
Sourced by ZipRecruiter
Industry
Colleges, universities, and professional schools
Company size
1,001 - 5,000 Employees
Headquarters location
Los Angeles, CA, US
Year founded
1929