Cyber Security Engineer - Vulnerability Management

StoneX Group Inc.

São Paulo

Híbrido

BRL 180 000 - 300 000

Tempo integral

Há 4 dias
Torna-te num dos primeiros candidatos

Recebe mais respostas dos empregadores

Envia um currículo específico para a oferta em poucos minutos.

Vantagens oferecidas por esta oferta de emprego

Medical and life insurance
Public transportation support
Meal and food allowances

Resumo da oferta

The Senior Vulnerability Management Engineer at StoneX Group Inc. is responsible for the technical ownership, reliability, and continuous improvement of vulnerability and exposure management across infrastructure, applications, and cloud environments.

This role emphasizes high‑fidelity data, accurate visibility, and integrated tooling to support risk‑based decision making and remediation. You'll work with a diverse tech stack (Tenable, Qualys, Rapid7, AWS/Azure/GCP, ServiceNow, Jira) and lead

Qualificações

  • 5–7+ years of technology experience with 3–5 years in vulnerability or exposure management.
  • Hands-on experience configuring, operating, and troubleshooting vulnerability tools (Tenable, Qualys, Rapid7, MDM, Armis Centrix/VIPR).
  • Strong analytical, problem‑solving and communication skills, able to work independently and with teams.

Responsabilidades

  • Operate and maintain vulnerability and exposure management platforms across enterprise environments.
  • Lead PoCs to evaluate, implement, and optimize tooling and automation.
  • Correlate vulnerability data with asset criticality to enable risk‑based prioritization.
  • Engineer dashboards and data pipelines for visibility into posture and trends.
  • Develop processes and documentation for vulnerability tooling and compliance reporting.
  • Integrate tooling with asset management, CMDB, ticketing and SIEM/SOAR where applicable.

Conhecimentos

Vulnerability management
Tool troubleshooting
Analytical thinking
Communication

Formação académica

Bachelor's degree in Information Security/CS/Engineering

Ferramentas

Tenable
Qualys
Rapid7
Microsoft Defender Vulnerability Management
Armis Centrix
ServiceNow
Jira
AWS
Azure
GCP
Python
PowerShell

Descrição da oferta de emprego

Overview

This role can be located in Sao Paulo (Brazil) or Bogota (Colombia)

Connecting clients to markets – and talent to opportunity.

With 5,400+ employees and over 80,000 institutional, commercial, and payments clients, we operate from more than 80 offices spread across six continents. As a Fortune 100, Nasdaq-listed provider, we connect clients to the global markets – focusing on innovation, human connection, and providing world‑class products and services to all types of investors.

With 5,400+ employees and over 80,000 institutional, commercial, and payments clients, we operate from more than 80 offices spread across six continents. As a Fortune 100, Nasdaq-listed provider, we connect clients to the global markets – focusing on innovation, human connection, and providing world‑class products and services to all types of investors.

Whether you want to forge a career connecting our retail clients to potential trading opportunities, or ingrain yourself in the world of institutional investing, StoneX Group is made up of four business segments that offer endless potential for progression and growth.

Business Segment Overview:

Engage in a deep variety of business‑critical activities that keep our company running efficiently. From strategic marketing and financial management to human resources and operational oversight, you’ll have the opportunity to optimize processes and implement game‑changing policies.

Position Purpose:

The Senior Vulnerability Management Engineer is responsible for the technical ownership, reliability, and continuous improvement of the organization’s vulnerability and exposure management capabilities across infrastructure, applications, and cloud environments. This role focuses on ensuring accurate visibility, high‑fidelity data, and well‑integrated tooling to support risk‑based decision making and effective remediation.

Technology Ecosystem:
  • Front-End: Vulnerability dashboards and reporting platforms (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, Armis VIPR)
  • Back End: Vulnerability scanners, data pipelines, integrations, and ticketing platforms (ServiceNow, Jira)
  • Exposure Management & Asset Intelligence: Armis Centrix, External Attack Surface Management tools, Continuous Threat Exposure Management (CTEM) tools
  • Cloud: AWS, Azure, GCP
Responsibilities
Primary duties will include:
  • Operate and maintain vulnerability and exposure management platforms, including execution, validation, and troubleshooting of scanning activities, ensuring accurate configuration, comprehensive coverage, and high‑fidelity results across enterprise environments.
  • Serve as a senior technical subject matter expert, resolving complex issues, improving platform performance, and enhancing vulnerability management capabilities.
  • Correlate vulnerability data with asset criticality, vulnerability intelligence, and exploitability indicators to support risk‑based prioritization efforts.
  • Engineer and maintain dashboards, reporting, and data pipelines to enable visibility into vulnerability posture, trends, and operational metrics.
  • Develop, maintain, and enhance engineering processes and documentation for vulnerability and exposure management tooling, including scanning, exception handling, and compliance reporting.
  • Lead proof of concepts (PoCs) to evaluate, implement, and optimize vulnerability and exposure management tooling and automation, integrating with asset management, CMDB, ticketing, and security platforms to enhance vulnerability detection, prioritization, and remediation workflows.
  • Evaluate, build, and deploy AI/ML-assisted tooling for VM lifecycle management, capacity planning, and anomaly detection.

This list of duties and responsibilities is not intended to be all-inclusive and can be expanded to include other duties or responsibilities that management deems necessary.

Qualifications
To land this role you will need
  • 5–7+ years of overall technology experience, including at least 3–5 years in vulnerability management, exposure management, or information security engineering roles with hands‑on responsibility for tooling and platforms.
  • Strong hands‑on experience operating, configuring, optimizing, and troubleshooting vulnerability management and exposure management tools (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, Armis Centrix/VIPR, and exposure management platforms such as EASM and CTEM tools).
  • Solid understanding of enterprise environments, including operating systems (Windows, Linux, MacOS), cloud platforms (AWS, Azure, GCP), networking, and identity systems.
  • Working knowledge of vulnerability prioritization methodologies (CVSS, EPSS), vulnerability intelligence (CISA KEV), and their application to risk‑based decision making.
  • Strong analytical, technical problem‑solving, and communication skills, with the ability to diagnose complex issues, improve system performance, and work independently while collaborating effectively with emotional intelligence.
What makes you stand out:
  • Experience integrating vulnerability management tools with exposure management and vulnerability prioritization platforms, ticketing systems (ServiceNow, Jira), asset management, SIEM (Splunk, Sentinel), or SOAR.
  • Experience building or enhancing automation and workflows using scripting languages (Python, PowerShell).
  • Experience collaborating with threat intelligence or red team functions to assess exploitability.
  • Familiarity with security frameworks and regulatory requirements (CIS, NIST CSF, PCI, ISO, SOX, FINRA, ITIL).
Education / Certification Requirements:
  • Associates, Bachelor’s or Master’s degree in Information Security, Information Assurance, Information Systems, Computer Science, Engineering Sciences, STEM, or a related field (or equivalent hands‑on experience).
  • SANS related certifications (GSEC, GCIA, GCED, GCIH, GCCC, GMON, GPEN, GEVA, etc.).
  • Additional relevant certifications may be considered.
Work environment:
  • FTE type of contract
  • Office location in São Paulo - Rua Joaquim Floriano - Rua Joaquim Floriano 413 SAO PAULO, São Paulo 04534-011 Brazil
  • Office location in Bogota - Avenida Carrera 9A - Avenida Carrera 9A # 115-06/30 Edificio Torre Tierrafirme Bogotá, 110111 Colombia
  • Hybrid model (4 days/week in the office, 1 day/week remote)
Benefits:
  • Medical and life insurance
  • Public Transportation support
  • Meal and food allowances
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Lead Engineer, Vulnerability & Exposure Management
Lead Engineer, Vulnerability & Exposure Management

Danaher • São Paulo

Presencial
BRL 200 000 - 320 000
Analista de Segurança da Informação Pleno — Gestão de Vulnerabilidades e Identidades
Analista de Segurança da Informação Pleno — Gestão de Vulnerabilidades e Identidades

Jobgether • Brasil

Presencial
BRL 90 000 - 130 000
Life insurance
Medical and dental plans
Learning and development platform
+7
Analista de Gestão de Vulnerabilidades (Híbrido/SP) - 130214
Analista de Gestão de Vulnerabilidades (Híbrido/SP) - 130214

GFT Technologies • Região Geográfica Intermediária de São Paulo

Híbrido
Especialista de Vulnerabilidades
Especialista de Vulnerabilidades

Banco Pine • São Paulo

Presencial
BRL 120 000 - 160 000
Benefícios de mercado
Analista de Vulnerabilidade
Analista de Vulnerabilidade

Stefanini Brasil • São Paulo

Presencial
BRL 134 000 - 201 000
Security Triage & Remediation Lead, Brazil
Security Triage & Remediation Lead, Brazil

CI&T • Brasil

Presencial
BRL 180 000 - 300 000
Health and dental insurance
Meal allowance
Extended paternity leave
+9
Cyber Security Engineer - São Paulo
Cyber Security Engineer - São Paulo

Yeah! Global • São Paulo

Presencial
Cyber Threat and Vulnerability Senior Analyst
Cyber Threat and Vulnerability Senior Analyst

Mars UK • Arujá

Presencial
BRL 180 000 - 280 000
[Job - 31023] Security Triage & Remediation Lead, Brazil
[Job - 31023] Security Triage & Remediation Lead, Brazil

CI&T • Brasil

Presencial
BRL 260 000 - 520 000
Health and dental insurance
Meal allowance
Childcare assistance
+2
14FA: Analista de Segurança da Informação Sênior
14FA: Analista de Segurança da Informação Sênior

Mazzatech • São Paulo

Híbrido
BRL 180 000 - 240 000