Cyber Security Engineer - Vulnerability Management
HybridSão Paulo, São Paulo, Brazil or Sao Paulo, São Paulo, Federative Republic of Brazil
Job Summary
Operate and maintain vulnerability and exposure management platforms, executing, validating, and troubleshooting scanning activities across enterprise infrastructure, applications, and cloud environments. Serve as a technical subject matter expert by resolving complex issues, improving platform performance, and correlating vulnerability data with asset criticality to support risk-based prioritization. Engineer dashboards, reporting, and data pipelines to enable visibility into vulnerability posture, while developing engineering processes for scanning, exception handling, and compliance reporting. Lead proof of concepts to evaluate and optimize tooling and automation, including AI/ML-assisted lifecycle management and anomaly detection. This role supports StoneX Group's mission to connect clients to global markets through innovation and world-class products.
Required Qualifications
- 5–7+ years of overall technology experience
- at least 3–5 years in vulnerability management, exposure management, or information security engineering roles
- hands-on responsibility for tooling and platforms
- Strong hands-on experience operating, configuring, optimizing, and troubleshooting vulnerability management and exposure management tools
- Solid understanding of enterprise environments, including operating systems (Windows, Linux, MacOS), cloud platforms (AWS, Azure, GCP), networking, and identity systems
- Working knowledge of vulnerability prioritization methodologies (CVSS, EPSS), vulnerability intelligence (CISA KEV), and their application to risk-based decision making
- Strong analytical, technical problem-solving, and communication skills
- ability to diagnose complex issues
- ability to improve system performance
- ability to work independently
- ability to collaborate effectively with emotional intelligence
- Associates, Bachelor’s or Master’s degree in Information Security, Information Assurance, Information Systems, Computer Science, Engineering Sciences, STEM, or a related field
- equivalent hands-on experience
- SANS related certifications (GSEC, GCIA, GCED, GCIH, GCCC, GMON, GPEN, GEVA, etc.)
Desired Qualifications
- Experience integrating vulnerability management tools with exposure management and vulnerability prioritization platforms
- Experience integrating vulnerability management tools with ticketing systems (ServiceNow, Jira)
- Experience integrating vulnerability management tools with asset management
- Experience integrating vulnerability management tools with SIEM (Splunk, Sentinel), or SOAR
- Experience building or enhancing automation and workflows using scripting languages (Python, PowerShell)
- Experience collaborating with threat intelligence or red team functions to assess exploitability
- Familiarity with security frameworks and regulatory requirements (CIS, NIST CSF, PCI, ISO, SOX, FINRA, ITIL)
- Additional relevant certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.