Junior Analyst in Vulnerability Management and Compliance at Tempest, focusing on technical guidance and vulnerability assessments. Collaborating with experts and working in a tech-driven environment.
Responsibilities
Execute scans using VA tools (Tenable, Qualys, Fortra VM, or similar).
Analyze identified vulnerabilities, assess initial severity, and assist with prioritization.
Perform post-remediation validations and help investigate false positives.
Analyze configurations and compliance deviations.
Support baseline reviews (GPO, CIS, and internal benchmarks).
Propose recommendations to improve security posture, under guidance from mid/senior team members.
Monitor remediation metrics and record evidence submitted by clients.
Document analyses and deliverables in Tempest's ticketing platform.
Prepare technical reports and concise executive summaries.
Use Python (or an equivalent language) for basic automation.
Create simple scripts for data processing, spreadsheet generation, and analysis optimization.
Follow team processes and contribute to operational improvements.
Requirements
Foundations of Information Security (CIA — confidentiality, integrity, availability — and risk) and understanding of vulnerabilities (CVSS, impact, technical description).
Technical English (reading and writing; conversational fluency is a plus).
Basic knowledge of a programming language (Python, PowerShell, Go, or similar), including automation concepts, scripting, and simple pipelines (e.g., Python + Bash + Pandas).
Basic knowledge of frameworks/methodologies such as CVSS, MITRE ATT&CK, NIST CSF, or ISO 27001.
Foundations of networking and operating systems, including basic TCP/IP, ports, protocols, and basic network modeling.
Prior experience (including internships) in Vulnerability Management, SOC, GRC, Infrastructure, IT, offensive security, or technical support.
Experience or familiarity with tools such as Tenable.sc / Nessus, Qualys VMDR, Fortra VM, Rapid7, or similar.
Experience with lightweight scripting (Python, PowerShell, or Bash) for automation, including API queries and basic data manipulation.
Ability to interpret results and support analyses using these tools.
Basic use of Windows and Linux, with knowledge of GPO, Active Directory, system hardening, and CIS benchmarks.
Intermediate spreadsheet skills (Excel or Google Sheets).
Benefits
Health insurance;
Dental insurance;
TotalPass — physical health and wellness;
Childcare allowance per child;
Empresa Cidadã: 6-month maternity leave;
Home office allowance for fully remote employees;
Flash Card — greater flexibility;
Work arrangements: On-site, Hybrid, or Remote;
Day Off — one day off to celebrate your birthday;
Profit Sharing (PLR);
Quarterly Revenue Target (MFT);
Internal training/course program;
Job title
Junior Vulnerability Management and Compliance Analyst
Cyber GRC Senior Consultant supporting companies in enhancing cybersecurity and compliance. Collaborating with client teams to implement cybersecurity policies and conduct risk assessments.
Internal Controls & Compliance Supervisor managing compliance with SOX and internal controls at Solventum, a healthcare company enhancing solutions for healthcare professionals.
Regulatory Affairs Specialist ensuring compliance and strategic oversight at Multiverse. Drafting regulatory submissions and coordinating oversight processes within a hybrid work environment.
Director of Deposit Compliance responsible for leading compliance efforts for deposit products at Northwest Bank. Ensuring adherence to regulations and managing risk assessment processes for effective compliance operations.
Chargé de la Qualité et Conformité en alternance pour Economie d’Energie. Soutenir la conformité et le contrôle interne tout en participant à la transition énergétique en France.
Senior Specialist responsible for corrective actions in Global Trade Compliance at L3Harris. Track compliance incidents and facilitate corrective action processes across US and non - US jurisdictions.
Regulatory Affair Specialist at Capgemini Engineering ensuring regulatory compliance with medical device documentation. Supporting regulatory activities and monitoring the regulatory context impact on site processes.
Compliance Analyst role at Leve Saúde ensuring adherence to regulations in the health sector. Responsibilities include audits, policy management, and due diligence processes.
Governance, Risk & Compliance Specialist at Quilter providing oversight on governance, risk, and compliance activities, strengthening Quilter Invest’s risk management culture across the organization.