Manager, Cyber Risk Management
University of Southern CaliforniaAbout the role
ABOUT THE DEPARTMENT
The University of Southern California (USC) is advancing its cybersecurity posture with a renewed focus on resilience, cyber risk management, and threat-informed defense. As a world-class research institution, USC is building a culture of security that supports its academic and research mission in a rapidly evolving threat landscape.
This role sits within a newly restructured cybersecurity organization that’s leading this transformation. You’ll join a team focused on scalable, proactive defense strategies, incident preparedness, and operational excellence—working alongside experts who are deeply committed to service, innovation, and impact.
If you’re driven by purpose, thrive in complexity, and want to help shape the future of cybersecurity at a leading university, we invite you to bring your leadership to the table.
POSITION SUMMARY
As the Manager, Cyber Risk Management you will be an integral leader of the cybersecurity department while also collaborating with stakeholders across the university ecosystem, and reporting to the Senior Director, Cyber Governance. This is a full-time exempt position, eligible for all of USC’s fantastic Benefits + Perks. This opportunity is remote.
The Manager, Cyber Risk Management develops, implements, and supports cybersecurity risk management plans, as well as governance and remediation strategies. Plays a crucial role in establishing that the university's cybersecurity risk management procedures are comprehensive, up-to-date, and effectively mitigate risks to provide consistency and enable the departments, schools, and units to perform processes in a more secure manner. Manages the development, enhancement, and maintenance of cybersecurity policies and standards. Ensures the university complies with relevant laws, regulations, and standards related to cybersecurity and privacy. Collaborates with various stakeholders to align cybersecurity policies with strategic goals and operational needs. Collaborates and manages relationship with managed service providers as required to support ongoing operations across in scope capabilities. Identifies and mitigates potential risks through threat analysis and carries out assessments on the effectiveness of established strategies. Responsible for overseeing both internal/external cyber risk management, third-party related risks, responding to audit needs, and collaborating with departments, schools, units, and functions across the university.
The Manager, Cyber Risk Management will:
Develops, implements and supports cybersecurity risk management plans, as well as governance and remediation strategies. Drives the execution of second line of defense risk management plans. Provides structured consulting in cyber risk management; promotes and instills a risk-aware and action-oriented culture throughout the university. Oversees third-party management and risk policy managed services.
Manages the development, enhancement, and maintenance of cybersecurity policies and standards. Drafts, reviews, and updates cybersecurity policies, standards, and guidelines in accordance with regulatory requirements and best practices. Develops and enforces cybersecurity policies that protect sensitive information (e.g., health records, personal data) from cyber threats. Ensures policies and procedures are robust and effective.
Supports university compliance with relevant laws, regulations, and standards related to cybersecurity and privacy (e.g., FERPA, HIPAA, GDPR). Collaborates with various stakeholders across the university (e.g., IT staff, faculty, and administration). Aligns cybersecurity policies with strategic goals and operational needs. Supports the verification that departments, schools, and units (DSUs) adhere to the latest security and privacy legal, regulatory, and contractual requirements.
Identifies and mitigates potential risks through threat analysis. Carries out regular assessments on the effectiveness of existing governance and risk management strategies. Monitors compliance with security policies; reports on the effectiveness of the security program to the chief information security officer (CISO) and executive leadership. Collaborates with OCEC Policy change management to identify change impacts; provides communications team with information necessary to disseminate any changes or additions to policy and/or standard requirements.
Serves as the second line of defense (works with other second line of defense, e.g., Ethics & Compliance) and works with the third line of defense which includes Internal Audit (providing Assurance services) and privacy teams to gain input and maintain knowledge of the latest applicable security and privacy legal, regulatory and contractual requirements as well as industry b
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s