Stefanini Brasil logo
Stefanini Brasil

Co-creating Solutions for a Better Future

Mid-level Security Analyst

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 10,001+Since 1987H1B No SponsorCompany SiteLinkedIn

Location

Brazil

Posted

4 days ago

Salary

0

Seniority

Senior

Job Description

Mid-level Security Analyst

Stefanini Brasil

• Operate and evolve the Vulnerability Management process, being responsible for identifying, analyzing, prioritizing, tracking and validating the remediation of vulnerabilities in IT, OT (Operational Technology) and Cloud environments. • Execute and monitor vulnerability scans on infrastructure assets, operating systems, applications, APIs, cloud environments and industrial assets. • Analyze results from Vulnerability Management tools, identifying vulnerabilities, validating false positives and supporting the definition of remediation strategies. • Classify and prioritize vulnerabilities based on risk criteria, asset criticality, business impact and exploitation potential. • Plan, coordinate and follow up on remediation actions with responsible teams, ensuring improvements in security indicators and adherence to established deadlines. • Perform technical re-validations to demonstrate the effectiveness of implemented fixes. • Support hardening initiatives, risk management and continuous improvement of the organization’s security posture. • Continuously monitor new vulnerabilities, emerging threats and risks that may impact the corporate environment. • Prepare technical reports, dashboards and executive metrics to monitor the maturity of the Vulnerability Management process. • Participate in alignment meetings with infrastructure, cloud, security, development teams and business stakeholders. • Contribute to the advancement of processes, automations and integrations related to Vulnerability Management.

Job Requirements

  • Experience in Vulnerability Management.
  • Experience operating and analyzing Vulnerability Management tools.
  • Experience operating and administering the Qualys VMDR platform.
  • Experience with Orca Security for identifying and analyzing risks in Cloud environments.
  • Experience with Claroty for identifying and analyzing vulnerabilities in OT/ICS environments.
  • Knowledge of Windows and Linux operating systems.
  • Knowledge of Cloud environments (Azure, AWS, GCP or Oracle Cloud).
  • Good communication skills for interacting with technical teams, managers and business areas.

Benefits

  • Meal allowance or food voucher
  • Discounts on courses, universities and language schools
  • Stefanini Academy — platform with free, up-to-date online courses and certificates
  • Mentoring
  • Benefits club for medical consultations and exams
  • Health insurance
  • Dental insurance
  • Discount club with offers at top establishments
  • Travel club
  • Pet care partnership/benefits

Related Job Pages

More Security Analyst Jobs

Rubrik, Inc. logo

SOC Security Analyst – FedRAMP

Rubrik, Inc.

As the pioneer in Zero Trust Data Security™, we enable cyber and operational resilience for enterprises and governments.

Full TimeRemoteTeam 1,001-5,000Since 2014H1B No Sponsor

• Monitor and respond to security alerts across Rubrik’s corporate network, endpoints, cloud, and SaaS environments. • Rapidly detect and accurately identify signs of intrusions and other malicious activity. • Manage the end-to-end incident response lifecycle, encompassing triage, deep-dive investigations, and remediation to ensure accurate identification of root causes and organizational impact. • Partner with vulnerability management, FedRAMP, and engineering teams to assess threats, prioritize vulnerabilities, and drive timely remediation efforts. • Collaborate with cross functional teams to drive resolution of events. • Contribute to overall program maturity through providing feedback and ideas to refine and improve detection capabilities and response processes. • Update and maintain accurate incident case attributes and investigation details.

United States
$111.8K - $186.2K / year
Full TimeRemoteTeam 51-200Since 1994H1B No Sponsor

• Review, investigate, and adjudicate security incidents escalated from the Security Operations Center (SOC), including triage, root cause analysis, containment, remediation, and post-incident review while partnering with the SOC to improve detection logic, escalation workflows, and operational effectiveness • Drive the vulnerability management lifecycle through identification, risk-based prioritization, remediation tracking, and reporting while coordinating penetration testing activities, supporting remediation efforts, and performing application security assessments and reviews • Partner with engineering teams to identify, prioritize, and remediate security risks across production environments while contributing to secure configuration standards, monitoring coverage, security best practices, and the protection of AI-enabled workloads • Support the ongoing maturation of the security program by improving security tools, processes, and operational capabilities while recommending enhancements that strengthen the organization's overall security posture • Ensure complete and reliable collection of security logs and telemetry into the SIEM while supporting security data architecture decisions, onboarding new data sources, validating monitoring coverage, and identifying visibility gaps across systems and environments • Support internal and external audits, including HITRUST, SOC 2, client assessments, and regulatory reviews while coordinating evidence collection, tracking remediation activities, conducting third-party risk assessments, maintaining risk registers, and supporting ongoing audit readiness • Develop, analyze, and present security and risk metrics, KPIs, KRIs, dashboards, and executive-level reporting that translate technical findings into meaningful business insights and support organizational decision-making • Partner with engineering, infrastructure, operations, compliance, risk management, and business stakeholders to support security initiatives, policy and control mapping efforts, risk remediation activities, and strategic security projects

Ohio
$120K - $140K / year
GEHA Health logo

Continuity & Security Assurance Analyst

GEHA Health

G.E.H.A (Government Employees Health Association, Inc) is a nonprofit member association that provides medical and dental benefits to more than two million federal employees and retirees, military retirees, and their families. We celebrate diversity and are committed to creating an inclusive environment for all employees. G.E.H.A has one mission: To empower federal workers to be healthy and well. We serve our members with products they value and a personalized customer experience, sustained by a nimble and efficient organization.

Full TimeRemoteTeam 1,001-5,000

Role Description The Continuity and Security Assurance Analyst supports G.E.H.A’s Cybersecurity and Information Protection (CIP) program by executing security, compliance, and business continuity initiatives. This role is responsible for: - Assessing controls - Monitoring compliance with regulatory and internal standards - Supporting audit activities - Contributing to the resilience and security posture of G.E.H.A’s systems, data, and third-party relationships Qualifications - Bachelor’s degree in Computer Science, Information Systems, or a related discipline - Three (3) or more years of experience in Information Technology, Information Security, IT Assurance, Risk Management, Governance, or Business Continuity - Equivalent combinations of education and additional experience may be considered in lieu of formal degree or certification requirements - One or more industry certifications such as: CISSP, HCISPP, CRMA, CGEIT, CRISC, CISM, CISA, CBCP, GIAC, or similar governance, risk, security, or BCDR certifications Requirements - Working knowledge of governance, risk, and compliance frameworks such as: COSO, COBIT, ITIL, ISO 31000, ISO 27002, ISO 22301, NIST CSF, NIST 800‑53, and SANS Critical Security Controls - Experience with enterprise Governance, Risk, and Compliance (GRC) platforms (e.g., Archer, MetricStream, LockPath, etc.) - Proficiency with Microsoft Office applications - Strong analytical and problem-solving skills with the ability to identify risk and recommend practical solutions - Effective written and verbal communication skills, including the ability to translate technical risks into business-focused language - Ability to build relationships, influence stakeholders, and collaborate across multiple business units and teams - Strong organizational skills with the ability to manage multiple priorities in a fast-paced environment - Customer service orientation with a focus on delivering high-quality, accurate outcomes - Effective presentation and interpersonal skills Benefits - Competitive pay/salary ranges - Incentive plan - Health/Vision/Dental benefits effective day one - 401(k) retirement plan: company match – dollar for dollar up to 4% employee contribution (pretax or Roth options) plus a 6% annual company contribution - Robust employee well-being program - Paid Time Off - Personal Community Enrichment Time - Company-provided Basic Life and AD&D - Company-provided Short-Term & Long-Term Disability - Tuition Assistance Program

United States
$75.9K - $106.9K / year

Senior Physical Red Team Security Analyst

UnitedHealth Group

UnitedHealth Group is a healthcare and well-being company that’s dedicated to improving the health outcomes of millions around the world. We are comprised of

Title: Senior Physical Red Team Security Analyst Location: Remote United States Requisition number: 2354040 Job category: Technology Travel: Yes, 50 % of the Time Job Description: Optum is a global organization that delivers care, aided by technology, to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by diversity and inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health equity on a global scale. Join us to start Caring. Connecting. Growing together. We are seeking a highly skilled and resourceful offensive security assessment member to join our Physical Red Team. In this role, you will simulate real-world adversaries to evaluate and improve the physical security posture of our facilities, personnel, and processes. You will plan and execute covert operations-such as facility penetration, surveillance, and social engineering-and provide detailed reporting to help strengthen defenses against sophisticated threats. You'll enjoy the flexibility to work remotely * from anywhere within the U.S. as you take on some tough challenges. Primary Responsibilities: - Conduct physical security assessments of facilities by attempting to bypass locks, alarms, access controls, and security personnel - Perform covert entry operations including reconnaissance, surveillance, and red team exercises - Test human-factor vulnerabilities through social engineering, impersonation, or tailgating - Conduct intelligence (OSINT, HUMINT, SIGINT) collection on facilities, personnel, and businesses - Design, source, build, and deploy physical and technological offensive security tools - Create and communicate risk-profiles for executive members - Document findings with accurate reporting, photography, and after-action reviews, including remediation recommendations - Collaborate with cybersecurity, corporate security, and defensive security teams to ensure findings are integrated into broader risk management strategies - Maintain strict compliance with legal, ethical, and safety guidelines during all engagements - Stay current with emerging tools, techniques, and threat actor behaviors relevant to physical security testing - Effectively communicate successes and obstacles with fellow team members and team lead(s) - Create written reports, detailing assessment findings and recommendations - Interface with customer contact(s) and staff in a constructive and professional manner - Have subject matter expertise in advanced testing specialties: containerization, automation, wireless/IoT, exploit development, hardware, radio frequency, reconnaissance procedures - Ethically operate with appreciable latitude in developing methodology and applying it in the field - Research and analyze adversary methodologies and develop testing models to mimic adversaries - Ability to communicate clearly and effectively through oral or written communication with all levels in the organization - Ability to initiate, design, execute, complete, and provide metrics on projects with minimal direction - Drive cross-team efforts to address systemic risks across the business - Conduct business/risk portfolio research and test planning work that encompasses holistic testing efforts You'll be rewarded and recognized for your performance in an environment that will challenge you and give you clear directions on what it takes to succeed in your role as well as provide development for other roles you may be interested in. Required Qualifications: - High School Diploma/GED (or higher) - 6 + years of experience in demonstrable ability to think critically and creatively to solve complex problems with limited to no guidance - 6 + years of experience in time operating within a team which produced superior results to bring increased value and proficiency to an organization - 4+ years of experience conducting risk assessments, identifying and implementing controls, and adhering to safety, legal, ethical, and moral rules and guidelines - 3+ years of in-depth experience in physical red team assessments and reporting - 3+ years of demonstrable experience deploying RF detection, monitoring, baselining, and alerting tools - 3+ years of experience with intelligence gathering and sorting (HUMINT, OSINT, SIGINT, etc.) used in cohesive reports on action operations - 3+ years of demonstrable coding experience and capabilities - 3+ years of demonstrable experience in ability to design, source, build, and deploy various offensive security tools (wireless detection, SDR, drone, surveillance), both hardware and software - 3+ years of hands-on experience with assessment and exploitation tools including: - Software-defined radios - RFID scanners - WiFi Pineapple - RaspberryPi - Directional antennas - 2+ years of hands-on experience with assessment and exploitation tools including: - Kali, Burp, Cobalt Strike, and Metasploit - Malware development - Technology C2 infrastructure - CCTV (NVR, DVR) exploitation - Ability to travel up to 50% of the time; including outside the United States Preferred Qualification: - Physical Red Team certification (CCRTS, PSP, CEE, etc.) - Offensive security certification (GPEN, OSCP, CRT) - Law enforcement, military, or private/government security experience - Ham radio license - FAA Part 107 drone license - Located in Minneapolis/St. Paul, MN - All Telecommuters will be required to adhere to UnitedHealth Group's Telecommuter Policy. Pay is based on several factors including but not limited to local labor markets, education, work experience, certifications, etc. In addition to your salary, we offer benefits such as, a comprehensive benefits package, incentive and recognition programs, equity stock purchase and 401k contribution (all benefits are subject to eligibility requirements). No matter where or when you begin a career with us, you'll find a far-reaching choice of benefits and incentives. The salary for this role will range from $91,700 to $163,700 annually based on full-time employment. We comply with all minimum wage laws as applicable. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Application Deadline: This will be posted for a minimum of 2 business days or until a sufficient candidate pool has been collected. Job posting may come down early due to volume of applicants. At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location, and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups, and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission. UnitedHealth Group is an Equal Employment Opportunity employer under applicable law and qualified applicants will receive consideration for employment without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. UnitedHealth Group is a drug - free workplace. Candidates are required to pass a drug test before beginning employment. #RPO #GREEN

United States
$91.7K - $163.7K / year