We are looking for a professional responsible for operating and evolving the end-to-end vulnerability management process, ensuring the continuous reduction of the attack surface and compliance with remediation SLAs based on risk. Additionally, you will work in an integrated manner with Infrastructure, Systems, Cloud, and Development teams, connecting the discovery, prioritization, remediation, validation, and reporting of vulnerabilities.
Responsibilities:
- Perform and monitor vulnerability scans and interpret the results.
- Support infrastructure and development teams in mitigating flaws.
- Validate fixes (patches, configurations) and monitor hardening cycles.
- Utilize frameworks such as MITRE ATT&CK to identify threats.
- Automate processes using scripts (e.g., Python, PowerShell).
- Ensure adherence to the company's information security policies.
- Support security, compliance, and governance audits (LGPD, PCI, ISO 27001, NIST, etc.).
- Contribute to the development and review of internal policies, standards, and controls.
- Specify, manage, and evaluate Pentest routines.
- Collaborate with infrastructure and development areas to validate projects from a security perspective.
- Participate in the definition and implementation of security controls in new systems and applications.
- Promote security awareness among users and technical areas.
Requirements:
- Business English;
- Knowledge of security solutions for applications and standards for secure application development, OWASP;
- Knowledge of CVE, CVSS, exploitability, residual risk, and prioritization based on business context;
- Ability to validate evidence, discuss severity, and conduct pentests.
- Experience with triaging SAST/DAST/SCA findings and interacting with development teams.
Differentials:
- Official or hands-on courses in Vulnerability Management;
- Courses and certifications focused on security technologies;
- Qualys training (VMDR / Vulnerability Management);
- Desirable: CompTIA CySA+, OWASP Top 10 (Web, API, Mobile), Threat Hunting and MITRE ATT&CK, Incident Response and Digital Forensics, and Log Analysis and Monitoring with SIEM.
RTM offers:
- CLT employment contract (Brazilian labor law)
- Hybrid work model (3 days on-site and 2 days remote)
- Transportation allowance
- Coverage for courses and certifications in the field
- Bradesco Health and Dental Plan
- Corporate Life Insurance
- Total Pass
- Fully covered access to Alura
- Annual bonus
- No dress code
- Private Pension Plan
- App for Partnerships and Discounts
- Food/Meal Allowance: R$ 1,856.00 per month
- Birthday off
- Remote Work Allowance
- Orienteme (app for consultations with psychologists, nutritionists, and physical educators)