FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Junior III Information Security Analyst – Vulnerability Management
Bellinati Perez. Execute and maintain authenticated and unauthenticated scanning cycles across servers, workstations, and exposed assets .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in vulnerability scanning, asset management, and compliance with security standards such as ISO 27001. Proficient in technical analysis, remediation tracking, and reporting for information security posture.
Highest-signal resume keywords
Vulnerability Scanning ToolsCVSS InterpretationWindows Server SkillsScripting with PowerShellISO 27001 Knowledge
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Vulnerability ScanningCVE InterpretationTCP/IP NetworkingLinux SkillsData Processing with SQLAutomation ScriptingExcel ProficiencyExposure ManagementRemediation TrackingSLA Management
Soft Skills
Technical GuidanceCollaborationAnalytical ThinkingProblem Solving
Tools & Technologies
Greenbone/OpenVASNessusQualysRapid7CrowdStrike FalconITSM ToolAzureEntra ID
Industry Keywords
ISO 27001LGPDBACEN Resolution 4.658Information SecurityVulnerability Management
Tech Stack
Tools & technologiesAzureITSMLinuxPandasPythonSQLTCP/IP
About the role
Key responsibilities & impact- Execute and maintain authenticated and unauthenticated scanning cycles across servers, workstations, and exposed assets
- Keep the scanning scope synchronized with the asset inventory, identifying uncovered assets
- Adjust credentials, scan policies, and execution windows to maximize analysis depth while minimizing operational impact
- Consolidate findings from scanners, the EDR platform, third-party reports, and penetration tests into a single repository
- Keep the database and tracking dashboard up to date and accurate
- Triage findings by combining CVSS with asset exposure, service criticality, the existence of a public exploit, and compensating controls
- Validate false positives before creating requests for other teams
- Open, track, and follow up on remediation tickets with Infrastructure and Development through the ITSM tool
- Monitor SLA compliance by severity and escalate deviations to the Head of Information Security
- Provide technical guidance for accepted-risk decisions and propose compensating controls
- Track post-remediation rescans and formally close findings
- Produce periodic vulnerability posture reports for the Information Security team and leadership
- Organize remediation evidence for ISO 27001 audits and audits conducted by financial-sector clients
- Support responses to security questionnaires and client findings related to vulnerabilities and patching
- Maintain and enhance program metrics, including coverage, SLA compliance, mean time to remediate, and backlog by severity
Requirements
What you’ll need- Bachelor’s degree in Information Technology, Information Security, or a related field
- Hands-on experience with at least one vulnerability scanning tool (Greenbone/OpenVAS, Nessus, Qualys, or Rapid7)
- Ability to read and interpret CVE, CVSS, and CWE, with the capacity to technically justify prioritization decisions
- Intermediate-level Windows Server and Linux skills, including services, patching processes, and basic hardening
- Fundamentals of TCP/IP networking, including ports, protocols, exposed services, and basic segmentation and firewall concepts
- Scripting skills for automation and data processing using PowerShell or Python
- Experience with CrowdStrike Falcon, particularly exposure management modules
- Experience handling large volumes of data using advanced Excel, SQL, or Pandas
- Familiarity with an ITSM tool (GLPI or equivalent) and SLA management
- Basic knowledge of Brazil’s LGPD, ISO 27001/27701, and financial-sector security requirements (BACEN Resolution 4.658)
- Basic knowledge of security in Azure and Entra ID environments
- Technical English for reading advisories, bulletins, and vendor documentation
Benefits
Comp & perks- Meal allowance of BRL 32.00 per working day
- Access to a flexible benefits card
- Life insurance
- SESC partnership
- Birthday day off
- Dress code aligned with the corporate environment
- Dental plan
- TotalPass membership
- Psychological support program, including qualified listening and well-being initiatives
- Occupational health and safety program, including preventive initiatives and occupational monitoring
- Partnership program with universities, educational institutions, restaurants, and local businesses (subject to availability)
- Hybrid work model