
Search by job, company or skills
2
Stefanini Group is looking for a Cyber Security Vulnerability Analystto complement the technical capabilities of our Security Operations Center (SOC), part of Infrastructure Services (INFRA) Division.
As a Vulnerability Analyst, you will act as a expert and operational lead and will be responsible for overseeing vulnerability management service delivery, handling complex cases and escalations, providing strategic risk insights to clients, and ensuring the continuous improvement of vulnerability management processes across multiple customers.
Job Responsibilities
. Lead and oversee vulnerability management service delivery for multiple clients within an MSSP environment.
. Act as the primary escalation point for complex vulnerability analysis, false positives, and high-risk findings.
. Perform advanced risk, threat, and vulnerability analysis, including exploitation context and business impact assessment.
. Provide expert guidance on vulnerability remediation, compensating controls, and risk acceptance decisions.
. Support clients during audits, regulatory assessments, and security reviews related to vulnerability management.
. Define, optimize, and enforce vulnerability management processes, methodologies, and service standards.
. Ensure accurate prioritization of vulnerabilities based on business risk and threat landscape.
. Review and validate vulnerability reports, dashboards, and KPIs provided to clients and management.
. Collaborate with SOC, Incident Response, Threat Intelligence, and Architecture teams as needed.
. Mentor and provide technical guidance to junior and medium vulnerability analysts.
. Drive continuous improvement initiatives, automation, and optimization of vulnerability management services.
. Contribute to service strategy, tooling evaluations, and roadmap discussions.
. 4+ years of experience in vulnerability management, threat management, or related security operations roles.
. Advanced hands-on experience with vulnerability management platforms (e.g., Microsoft Defender VA, Qualys, Nessus, Rapid7).
. Deep understanding of vulnerability classification, scoring methodologies, and risk-based prioritization.
. Strong knowledge of enterprise IT environments, networks, operating systems, and security controls.
. Experience supporting audits, compliance initiatives, and executive-level reporting.
. Ability to translate technical vulnerability data into business risk insights.
. Strong leadership, mentoring, and stakeholder management skills.
. Excellent written and verbal communication skills in English.
. Relevant advanced certifications (e.g., CISSP, CISM, CEH, OSCP, vendor expert-level certifications) are a strong plus.
. High level of autonomy, accountability, and professionalism.
Based on Experience
Job ID: 153631025