Stefanini Group is seeking a skilled Cyber Security Services (CSS) Vulnerability Analyst to join our Security Operations Center (SOC), which operates as a Managed Security Service Provider (MSSP).
As a CSS Vulnerability Analyst, you will act as the technical point of contact for vulnerability management activities. You will independently deliver vulnerability assessment services, support client interactions, and provide actionable risk-based insights while ensuring high-quality service delivery within an MSSP environment.
Work Schedule:
Monday- Friday, 08:00 - 17:00 CET
Job Responsibilities:
- Serve as a technical escalation point for client vulnerability management-related issues.
- Perform vulnerability assessment scanning, false positive validation, compliance scanning, and policy configuration using various vulnerability management tools.
- Review security vulnerabilities across multiple technologies and environments to identify high-risk issues affecting business assets.
- Conduct risk, threat, and vulnerability analysis, including understanding exploitation techniques and attack paths.
- Provide clear remediation guidance and assist clients in prioritizing vulnerabilities based on risk and impact.
- Support patch management and remediation tracking activities.
- Integrate, analyze, and communicate vulnerability metrics, trends, and risk posture to clients and internal management.
- Ensure vulnerability management activities comply with defined SLAs, processes, and client requirements.
- Contribute to continuous improvement of vulnerability management processes and reporting.
- Participate in mentoring junior analysts and knowledge-sharing activities.
Job Requirements:
Education:
- Preferred: Bachelor's degree in computer science, Information Technology, Engineering, or a related field.
- Minimum education requirement: High school studies completed with Baccalaureate diploma.
- Excellent English communication skills, both verbal and written, for professional communication and documentation.
Experience:
- 3-5 years of experience in cybersecurity operations, including at least 2 years of hands‑on experience in vulnerability and/or patch management.
- Hands‑on experience with vulnerability assessment tools such as Microsoft Defender Vulnerability Management, Nessus, Qualys, or Rapid7.
Mandatory Technical Skills:
- Proficiency with vulnerability assessment tools, such as Microsoft Defender Vulnerability Management, Nessus, Qualys, and/or Rapid7.
- Strong understanding of vulnerability classes and classification schemes (CVE, CVSSv2/v3, CWE, CPE).
- Strong ability to analyze vulnerabilities and assign meaningful severity and remediation priorities.
- Good technical knowledge of networks, firewalls, operating systems, and enterprise environments.
- Understanding of related security domains (e.g., Incident Response, IAM, Threat Assessment).
Preferred / Nice-to-Have Qualifications:
- Hands‑on certifications in vulnerability management.
- Demonstrated experience working in a Security Operations Center, Global Security Operations Center, Managed Security Service, or similar 24/7 operational environment.
Professional Skills:
- Strong communication and collaboration skills, enabling effective interaction with a diverse range of technical and non‑technical stakeholders and internal teams.
- A customer‑focused mindset dedicated to delivering exceptional service.
- A collaborative mindset with an interest in internal operations and process improvement.
- Strong organizational, attention to detail, analytical thinking and a proactive approach to problem‑solving.
- Ability to work independently and manage multiple priorities in an MSSP environment.
- Ability to quickly adapt to changes, new requirements, or sudden shifts in direction.
- A commitment to continuous learning and improvement, staying abreast of industry best practices, emerging technologies, and methodologies.
- Absolute discretion and integrity in handling sensitive customer information and critical infrastructure data.
- Availability for on‑call responsibilities, if required.
This job description outlines the general nature and level of work performed by employees within this classification and is not intended to be a comprehensive inventory of all duties and responsibilities. Additionally, the responsibility to possess the necessary employment documents for this country rests with the candidate.
Diversity & Inclusion
Here at the Stefanini Group, we value diversity and equity, regardless of race, sexual orientation, disability, age, ancestry, religion, gender, or nationality. We understand and encourage the importance of being yourself and invest our efforts in maintaining an environment where it is safe to express oneself!
About Us
Global Tech Consulting Company All in One.
Stefanini is a Brazilian multinational company with 38 years of experience and presence in 41 countries. With more than 35,000 employees, we co‑create solutions for a better future, driving digital transformation with a focus on real results.
We operate in an integrated way through 7 specialized business units: Consulting (Technology and Business Agility), Analytics & AI, Banking & Payments, Cybersecurity, Manufacturing 4.0, and Digital Marketing. We are a group that breathes collaboration and offers a dynamic environment where you will learn by doing, grow alongside the team, and have space to contribute with ideas and projects.