Junior Analyst in Vulnerability Management and Compliance at Tempest, focusing on technical guidance and vulnerability assessments. Collaborating with experts and working in a tech-driven environment.
Responsibilities
Execute scans using VA tools (Tenable, Qualys, Fortra VM, or similar).
Analyze identified vulnerabilities, assess initial severity, and assist with prioritization.
Perform post-remediation validations and help investigate false positives.
Analyze configurations and compliance deviations.
Support baseline reviews (GPO, CIS, and internal benchmarks).
Propose recommendations to improve security posture, under guidance from mid/senior team members.
Monitor remediation metrics and record evidence submitted by clients.
Document analyses and deliverables in Tempest's ticketing platform.
Prepare technical reports and concise executive summaries.
Use Python (or an equivalent language) for basic automation.
Create simple scripts for data processing, spreadsheet generation, and analysis optimization.
Follow team processes and contribute to operational improvements.
Requirements
Foundations of Information Security (CIA — confidentiality, integrity, availability — and risk) and understanding of vulnerabilities (CVSS, impact, technical description).
Technical English (reading and writing; conversational fluency is a plus).
Basic knowledge of a programming language (Python, PowerShell, Go, or similar), including automation concepts, scripting, and simple pipelines (e.g., Python + Bash + Pandas).
Basic knowledge of frameworks/methodologies such as CVSS, MITRE ATT&CK, NIST CSF, or ISO 27001.
Foundations of networking and operating systems, including basic TCP/IP, ports, protocols, and basic network modeling.
Prior experience (including internships) in Vulnerability Management, SOC, GRC, Infrastructure, IT, offensive security, or technical support.
Experience or familiarity with tools such as Tenable.sc / Nessus, Qualys VMDR, Fortra VM, Rapid7, or similar.
Experience with lightweight scripting (Python, PowerShell, or Bash) for automation, including API queries and basic data manipulation.
Ability to interpret results and support analyses using these tools.
Basic use of Windows and Linux, with knowledge of GPO, Active Directory, system hardening, and CIS benchmarks.
Intermediate spreadsheet skills (Excel or Google Sheets).
Benefits
Health insurance;
Dental insurance;
TotalPass — physical health and wellness;
Childcare allowance per child;
Empresa Cidadã: 6-month maternity leave;
Home office allowance for fully remote employees;
Flash Card — greater flexibility;
Work arrangements: On-site, Hybrid, or Remote;
Day Off — one day off to celebrate your birthday;
Profit Sharing (PLR);
Quarterly Revenue Target (MFT);
Internal training/course program;
Job title
Junior Vulnerability Management and Compliance Analyst
Compliance Reporting Assistant supporting compliance activities and gaining hands - on experience in a dynamic international environment. Assist in preparing reports and dashboards while collaborating with various stakeholders.
Environmental Compliance Specialist managing compliance with environmental laws for natural gas projects in multi - state areas. Supervising consultants, preparing compliance reports, and conducting audits.
Compliance Analyst ensuring adherence to Federal Energy Regulatory Commission and ERCOT standards. Collaborating with various teams to manage compliance documentation and processes.
Manage compliance testing for Manulife within the Canada Segment team. Analyze key business controls and recommend improvements for compliance in financial institutions.
Senior Gas Pipeline Compliance Analyst maintaining safe, reliable natural gas operations at Enbridge. Analyzing regulations and partnering with teams for federal and state compliance.
Regulatory Analyst managing compliance obligations associated with regulatory requirements at Tallgrass, an energy infrastructure company. Involved in preparation, analysis, and administration in relevant areas.
Trainee supporting product compliance and legal regulation at ZF, engaging in training activities and various legal assistance tasks. Collaborating with experts on compliance projects.
VAT Compliance Specialist managing VAT - relevant data and ensuring compliance in an international team. Collaborating with various departments to maintain data quality and support documentation processes.
Working Student supporting the VATrules Team with data management and documentation processes. Engaging in VAT compliance and improving data structures in a hybrid work environment.
Specialist II in Regulatory Affairs preparing and maintaining global submissions for conducting clinical investigations. Collaborating with engineering and regulatory teams to ensure compliance with worldwide regulations.