Job Search and Career Advice Platform

Ativa os alertas de emprego por e-mail!

Principal Attack Surface Management

Johnson & Johnson

São Paulo

Presencial

BRL 435.000 - 654.000

Tempo integral

Hoje
Torna-te num dos primeiros candidatos

Cria um currículo personalizado em poucos minutos

Consegue uma entrevista e ganha mais. Sabe mais

Resumo da oferta

A global healthcare leader in São Paulo is seeking a Senior ASM Vulnerability Management Specialist with over 7 years of experience. The role focuses on identifying, prioritizing, and remediating vulnerabilities in web applications and infrastructure across both cloud and on-prem environments. The ideal candidate will have expertise in designing scanning controls and delivering compliance reports, while collaborating with various teams to enhance security posture and risk reduction strategies. Join a company dedicated to innovative healthcare solutions.

Qualificações

  • 7+ years in vulnerability management/secure configurations.
  • Solid experience with CIS Benchmarks and cloud security tooling.
  • Excellent stakeholder communication and executive reporting skills.

Responsabilidades

  • Define and implement secure baseline configurations aligned with CIS Benchmarks.
  • Develop remediation playbooks and policy-as-code.
  • Conduct regular vulnerability assessments and drive prioritized actions.
  • Lead remediation planning and track progress in ITSM systems.
  • Maintain continuous compliance monitoring and gap analysis.
  • Plan and implement targeted testing using automated tools.
  • Validate findings and collaborate with engineering.
  • Integrate vulnerability findings into SIEM and automate workflows.

Conhecimentos

Business Process Design
Crisis Management
Critical Thinking
Information Security Auditing
Information Security Management System (ISMS)
Information Technology (IT) Security Assessments
Information Technology Strategies
Mentorship
Organizing
Presentation Design
Process Optimization
Root Cause Analysis (RCA)
Security Architecture Design
Security Policies
Technical Credibility
Vulnerability Management

Formação académica

Relevant certifications (CISSP, GIAC, OSCP) preferred
Descrição da oferta de emprego
Job Function

Technology Enterprise Strategy & Security

Job Sub Function

Security & Controls

Job Category

Scientific/Technology

All Job Posting Locations

São Paulo, Brazil, Warsaw, Masovian, Poland

Job Description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com

Role Objective

Senior ASM vulnerability management specialist (7+ years) responsible for identifying, prioritizing, and remediating vulnerabilities across web apps and infrastructure in on-prem and cloud environments. Authority in designing, configuring, and maintaining scanning controls and programs. Leads exploitation simulations, exposure management, and meticulous analysis to drive risk reduction across a global enterprise. Collaborates with security, operations, and development teams; accelerates detection and remediation through automation; strengthens security posture and regulatory compliance.

Responsibilities
  • Define and implement secure baseline configurations aligned with CIS Benchmarks across OS, apps, and cloud resources.
  • Develop remediation playbooks and policy-as-code to ensure consistent secure configurations.
  • Conduct regular vulnerability assessments (Windows, Linux, network devices); map findings to controls and business risk; drive prioritized actions.
  • Lead remediation planning; track progress in ITSM systems; deliver executive-ready compliance reports.
  • Oversee onboarding, maintenance, and support of vulnerability assessment controls and other tools used by the ASM team.
  • Maintain continuous compliance monitoring and gap analysis for audit readiness.
  • Plan, coordinate, and implement targeted testing (web apps, APIs, infrastructure, cloud) using automated tools and skilled manual testing.
  • Validate findings with evidence; collaborate with engineering to verify remediation effectiveness; re-test as needed.
  • Integrate vulnerability findings into SIEM, ITSM, CMDB, and DevSecOps tooling; automate ticketing and remediation workflows.
  • Leverage threat intel and threat modeling to prioritize tests and remediation efforts.
  • Coordinate platform support and cloud security posture management (AWS/Azure) to scale and strengthen security posture.
  • Create clear, concise documentation to support colleagues and stakeholders.
Qualifications
  • 7+ years in vulnerability management/secure configurations; relevant certifications (e.g., CISSP, GIAC, OSCP) preferred.
  • Solid experience with CIS Benchmarks, cloud security tooling, SIEM/ITSM integrations, and threat modeling.
  • Excellent stakeholder communication and executive reporting skills.
Nice-to-haves
  • Experience with regulatory frameworks (NIST CSF, 800‑53, ISO 27001, PCI‑DSS, HIPAA).
  • Prior experience conducting controlled exploitation simulations or red‑team/blue‑team exercises.
Required Skills
  • Business Process Design
  • Crisis Management
  • Critical Thinking
  • Information Security Auditing
  • Information Security Management System (ISMS)
  • Information Technology (IT) Security Assessments
  • Information Technology Strategies
  • Mentorship
  • Organizing
  • Presentation Design
  • Process Optimization
  • Root Cause Analysis (RCA)
  • Security Architecture Design
  • Security Policies
  • Technical Credibility
  • Vulnerability Management
Preferred Skills
  • Business Process Design
  • Crisis Management
  • Critical Thinking
  • Information Security Auditing
  • Information Security Management System (ISMS)
  • Information Technology (IT) Security Assessments
  • Information Technology Strategies
  • Mentorship
  • Organizing
  • Presentation Design
  • Process Optimization
  • Root Cause Analysis (RCA)
  • Security Architecture Design
  • Security Policies
  • Technical Credibility
  • Vulnerability Management

Johnson & Johnson Family of Companies are equal opportunity employers, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, genetic information, national origin, protected veteran status, disability status, or any other characteristic protected by law.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta um ficheiro em formato PDF, DOC, DOCX, ODT ou PAGES até 5 MB.