StoneX

Cyber Security Engineer - Vulnerability Management

Job Locations BR-SP-SAO PAULO | CO-Bogotá
Requisition ID 2026-14793
Category (Portal Searching)
Information Technology
Position Type (Portal Searching)
Experienced Professional

Overview

This role can be located in Sao Paulo (Brazil) or Bogota (Colombia)

 

Connecting clients to markets – and talent to opportunity.

With 5,400+ employees and over 80,000 institutional, commercial, and payments clients, we operate from more than 80 offices spread across six continents. As a Fortune 100, Nasdaq-listed provider, we connect clients to the global markets – focusing on innovation, human connection, and providing world-class products and services to all types of investors.

Whether you want to forge a career connecting our retail clients to potential trading opportunities, or ingrain yourself in the world of institutional investing, StoneX Group is made up of four business segments that offer endless potential for progression and growth.

 

Business Segment Overview: Engage in a deep variety of business-critical activities that keep our company running efficiently. From strategic marketing and financial management to human resources and operational oversight, you’ll have the opportunity to optimize processes and implement game-changing policies.

 

Position Purpose:

The Senior Vulnerability Management Analyst is responsible for the technical ownership, reliability, and continuous improvement of the organization’s vulnerability and exposure management capabilities across infrastructure, applications, and cloud environments. This role focuses on ensuring accurate visibility, high-fidelity data, and well-integrated tooling to support risk-based decision making and effective remediation.

Technology Ecosystem:

  • Front-End: Vulnerability dashboards and reporting platforms (Tenable, Qualys, Rapid7, Microsoft Defender Vulnerability Management, Armis VIPR)
  • Back End: Vulnerability scanners, data pipelines, integrations, and ticketing platforms (ServiceNow, Jira)
  • Exposure Management & Asset Intelligence: Armis Centrix, Axonius, External Attack Surface Management tools, Continuous Threat Exposure Management (CTEM) tools
  • Cloud: AWS, Azure, GCP

Responsibilities

Primary duties will include: 

  • Analyze vulnerability and exposure data across infrastructure, endpoints, applications, cloud environments, and externally exposed assets to identify security weaknesses, assess potential impact, and determine remediation priority.
  • Correlate vulnerability findings with asset criticality, threat intelligence, exploitability, external exposure, CVSS, EPSS, CISA KEV, and other contextual information to support risk-based vulnerability prioritization.
  • Coordinate with Infrastructure, Cloud, Application, Network, and other technology teams to communicate vulnerability findings, provide remediation guidance, monitor progress, and support timely remediation of critical and high-risk exposures.
  • Investigate significant vulnerability and exposure findings, validate available evidence, identify potential mitigating controls, provide remediation or mitigation recommendations, and support root cause analysis when appropriate.
  • Monitor vulnerability posture and remediation performance, identify emerging risks or trends, and prepare reports, dashboards, metrics, and presentations for technical and non-technical stakeholders.
  • Support vulnerability management processes including vulnerability intake, prioritization, remediation tracking, exception management, validation, audit requests, security assessments, Patch Tuesday activities, and exposure management initiatives.
  • Partner with Threat Intelligence, Security Operations, vulnerability management engineering, and other security teams to evaluate emerging vulnerabilities, active exploitation, threat actor activity, and potential impact to StoneX environments.
  • This list of duties and responsibilities is not intended to be all-inclusive and can be expanded to include other duties or responsibilities that management deems necessary.

This list of duties and responsibilities is not intended to be all-inclusive and can be expanded to include other duties or responsibilities that management deems necessary.

Qualifications

To land this role you will need:

 

  • 4–6+ years of cybersecurity or information technology experience, including demonstrated experience in vulnerability management, vulnerability analysis, security operations, infrastructure security, or a related security discipline.
  • Working knowledge of vulnerability management technologies such as Rapid7 InsightVM, Microsoft Defender Vulnerability Management, Tenable, Qualys, or comparable vulnerability and exposure management platforms.
  • Strong understanding of vulnerability risk and prioritization concepts, including CVSS, EPSS, CISA Known Exploited Vulnerabilities, exploitability, asset criticality, external exposure, and compensating controls.
  • Strong analytical, investigative, and critical-thinking skills, including the ability to work through ambiguous technical problems, research unfamiliar vulnerabilities, and translate technical findings into actionable recommendations.
  • Strong written and verbal communication skills with the ability to clearly explain vulnerability risk, remediation requirements, and technical findings to both technical and non-technical stakeholders while collaborating effectively 

What makes you stand out:

  • Experience working with exposure management, external attack surface management, CTEM, asset intelligence, or vulnerability prioritization platforms.
  • Experience collaborating with Threat Intelligence, Security Operations, Incident Response, penetration testing, red teams, or other cyber defense functions to evaluate exploitability and organizational risk.
  • Familiarity with enterprise operating systems, networking, cloud environments, identity technologies, and infrastructure concepts across Windows, Linux, macOS, AWS, Azure, or GCP.
  • Familiarity with security frameworks and regulatory requirements such as CIS Controls, NIST CSF, PCI DSS, ISO 27001, SOX, FINRA, or similar standards.
  • Experience preparing vulnerability reports, remediation metrics, executive summaries, audit evidence, or other security communications for diverse audiences.

Education / Certification Requirements:

  • Bachelor's, or Master's degree in Information Security, Cybersecurity, Information Technology, Information Systems, Computer Science, Engineering, STEM, or a related discipline; equivalent relevant professional experience may also be considered.
  • Relevant cybersecurity certifications such as CompTIA Security+, CySA+, SANS/GIAC certifications, Certified Vulnerability Assessor, or comparable vulnerability/security certifications are preferred.
  • Additional relevant industry certifications or demonstrated vulnerability management training may be considered.

Work environment:

  • FTE type of contract
  • Office location in São Paulo - Rua Joaquim Floriano - Rua Joaquim Floriano 413 SAO PAULO, São Paulo 04534-011 Brazil 
  • Office location in Bogota - Avenida Carrera 9A - Avenida Carrera 9A # 115-06/30 Edificio Torre Tierrafirme Bogotá, 110111 Colombia 
  • Hybrid model (4 days/week in the office, 1 day/week remote

Benefits:

  • Medical and life insurance
  • Public Transportation support
  • Meal and food allowances

 

#LI-DK1

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed