[Job - 31023] Security Triage & Remediation Lead, Brazil
ciandt
Brazil
Posted Aug 14, 2026
- Other
- Remote
- Theta
ciandt
Brazil
Posted Aug 14, 2026
At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions. With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy. We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day. At CI&T, our rapid growth is fueled by the innovative solutions we create for our global clients. We are seeking talented Security Remediation Developers to accelerate vulnerability remediation throughput for a large US mortgage lender. Their vulnerability management program is surfacing more fixes than the internal teams can execute, and you will close that gap — researching each finding, implementing the fix at code and configuration level, deploying it, and proving it is closed. This is hands-on engineering work, not advisory work: you will spend your days in the codebase and in AWS. Responsibilities: • Take prioritized remediation items from the backlog and drive them to deployed, validated completion. • Research assigned vulnerabilities: reproduce where possible, identify root cause, and determine the correct fix rather than the fastest one. • Implement code-level remediation in PHP: refactor vulnerable patterns, fix injection, authentication, deserialization, and exposure defects, and remove hardcoded credentials. • Perform dependency and package upgrades, resolving breaking changes and transitive conflicts. • Perform AWS-side remediation and deployment, including configuration hardening and IAM adjustments. • Execute secret rotation tasks in coordination with the Remediation Lead, updating consumers and migrating credentials to a managed secrets store. • Validate every fix: write or extend automated tests, confirm the finding no longer reproduces, and document closure evidence the client's risk program can report on. • Work embedded with the client's engineering team, following their branching, code review, CI/CD, and definition of done. • Identify recurring patterns that warrant a systemic fix rather than repeated one-off remediation, and contribute them to the remediation playbook. • Support the client's engineers in adopting secure coding practices. Requirements: • Bachelor's degree in Computer Science, Information Technology, or a related field. • Professional PHP development experience, including work on legacy or inherited codebases. • Good English communication skills (reading, writing, and speaking) — daily collaboration with a US-based engineering team. • Demonstrated secure coding practice, with the OWASP Top 10 as vulnerabilities you have personally remediated. • Practical AWS experience • Strong dependency management with Composer, including resolving upgrade conflicts. • Proficiency with Git, code review discipline, and CI/CD pipelines. • Experience writing automated tests with PHPUnit or an equivalent framework. Nice to Have: • Experience remediating scanner findings at volume (Snyk, Veracode, Dependabot, Checkmarx). • Prior experience burning down a security or technical debt backlog against throughput targets. • Modern PHP frameworks such as Laravel or Symfony, alongside legacy pre-framework PHP. • Infrastructure as Code with Terraform or CloudFormation. •AWS experience deploying and operating PHP applications, covering compute (EC2, ECS, Elastic Beanstalk, or Lambda), IAM, S3, RDS, CloudWatch, and Secrets Manager or Parameter Store. •Containerization experience with Docker and ECS or EKS. • Experience integrating with legacy systems such as IBM i / RPG or SOAP services. • Experience in mortgage, lending, or financial services. • Experience working with international clients. Join CI&T and be a part of our mission to build secure, resilient software for our global clients. If you have a passion for PHP and AWS engineering and take satisfaction in closing security findings for good, we want to hear from you! #LI-JM5 At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions. With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy. We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day. At CI&T, our rapid growth is fueled by the innovative solutions we create for our global clients. We are seeking talented Security Remediation Developers to accelerate vulnerability remediation throughput for a large US mortgage lender. Their vulnerability management program is surfacing more fixes than the internal teams can execute, and you will close that gap — researching each finding, implementing the fix at code and configuration level, deploying it, and proving it is closed. This is hands-on engineering work, not advisory work: you will spend your days in the codebase and in AWS. Responsibilities: • Take prioritized remediation items from the backlog and drive them to deployed, validated completion. • Research assigned vulnerabilities: reproduce where possible, identify root cause, and determine the correct fix rather than the fastest one. • Implement code-level remediation in PHP: refactor vulnerable patterns, fix injection, authentication, deserialization, and exposure defects, and remove hardcoded credentials. • Perform dependency and package upgrades, resolving breaking changes and transitive conflicts. • Perform AWS-side remediation and deployment, including configuration hardening and IAM adjustments. • Execute secret rotation tasks in coordination with the Remediation Lead, updating consumers and migrating credentials to a managed secrets store. • Validate every fix: write or extend automated tests, confirm the finding no longer reproduces, and document closure evidence the client's risk program can report on. • Work embedded with the client's engineering team, following their branching, code review, CI/CD, and definition of done. • Identify recurring patterns that warrant a systemic fix rather than repeated one-off remediation, and contribute them to the remediation playbook. • Support the client's engineers in adopting secure coding practices. Requirements: • Bachelor's degree in Computer Science, Information Technology, or a related field. • Professional PHP development experience, including work on legacy or inherited codebases. • Good English communication skills (reading, writing, and speaking) — daily collaboration with a US-based engineering team. • Demonstrated secure coding practice, with the OWASP Top 10 as vulnerabilities you have personally remediated. • Practical AWS experience • Strong dependency management with Composer, including resolving upgrade conflicts. • Proficiency with Git, code review discipline, and CI/CD pipelines. • Experience writing automated tests with PHPUnit or an equivalent framework. Nice to Have: • Experience remediating scanner findings at volume (Snyk, Veracode, Dependabot, Checkmarx). • Prior experience burning down a security or technical debt backlog against throughput targets. • Modern PHP frameworks such as Laravel or Symfony, alongside legacy pre-framework PHP. • Infrastructure as Code with Terraform or CloudFormation. •AWS experience deploying and operating PHP applications, covering compute (EC2, ECS, Elastic Beanstalk, or Lambda), IAM, S3, RDS, CloudWatch, and Secrets Manager or Parameter Store. •Containerization experience with Docker and ECS or EKS. • Experience integrating with legacy systems such as IBM i / RPG or SOAP services. • Experience in mortgage, lending, or financial services. • Experience working with international clients. Join CI&T and be a part of our mission to build secure, resilient software for our global clients. If you have a passion for PHP and AWS engineering and take satisfaction in closing security findings for good, we want to hear from you! #LI-JM5 Our benefits: -Health and dental insurance -Meal and food allowance -Childcare assistance -Extended paternity leave -Partnership with gyms and health and wellness professionals via Wellhub (Gympass) TotalPass; -Profit Sharing and Results Participation (PLR); -Life insurance -Continuous learning platform (CI&T University); -Discount club -Free online platform dedicated to physical, mental, and overall well-being -Pregnancy and responsible parenting course -Partnerships with online learning platforms -Language learning platform And many more! More details about our benefits here: https://ciandt.com/br/pt-br/carreiras At CI&T, inclusion starts at the first contact. If you are a person with a disability, it is important to present your assessment during the selection process. See which data needs to be included in the report by clicking here.This way, we can ensure the support and accommodations that you deserve. If you do not yet have the assessment, don't worry: we can support you in obtaining it. We have a dedicated Health and Well-being team, inclusion specialists, and affinity groups who will be with you at every stage. Count on us to make this journey side by side. At CI&T, our rapid growth is fueled by the innovative solutions we create for our global clients. We are seeking an experienced Security Triage & Remediation Lead to own the triage and strategy function for a large US mortgage lender's enterprise vulnerability program. You will decide what gets fixed, in what order, and how — analyzing blast radius, sequencing remediation across teams you don't manage, and leading a live secrets rotation effort. You will also help upskill the client's internal engineering team, who know their codebase deeply but are new to enterprise-level triage work. Responsibilities: • Triage inbound vulnerabilities: validate, classify, and prioritize based on real exploitability and business impact rather than scanner severity alone.• Perform blast-radius and impact analysis across affected systems, services, and downstream consumers.• Own the secrets rotation strategy: inventory affected credentials, map ownership and consumers, and sequence rotation safely across production systems.• Coordinate remediation across multiple client delivery teams, aligning owners and unblocking work that spans team boundaries.• Define and maintain the remediation playbook: intake, severity criteria, SLAs, escalation paths, and closure criteria.• Report risk posture and backlog burn-down to VP-level client stakeholders in business language.• Provide technical direction to the remediation engineers: scope their work, review approach, and validate that fixes actually close the finding.• Upskill the client's internal team on triage methodology and secure remediation practices.• Integrate security validation and evidence capture into the client's existing delivery pipeline. Requirements: • Bachelor's degree in Computer Science, Information Technology, or a related field.• Solid experience in application security, vulnerability management, or security engineering.• Excellent English communication skills (reading, writing, and speaking) — this role leads calls with VP-level stakeholders.• Proven ownership of a vulnerability remediation program or triage function at enterprise scale.• Hands-on experience with secrets management and production credential rotation (AWS Secrets Manager, HashiCorp Vault, Parameter Store, or equivalent).• Strong AWS security fundamentals: IAM, least privilege, network exposure, and logging.• Ability to read and assess PHP code well enough to validate a remediation approach.• Expertise in threat modeling and blast-radius analysis, with practical command of CVSS, CWE, and the OWASP Top 10.• Proven track record of coordinating technical work across teams without formal authority. Nice to Have: • Experience in financial services, mortgage, or another regulated industry.• Incident response experience — containment, investigation, and post-incident hardening.• Familiarity with SAST, DAST, and SCA tooling (Snyk, Veracode, Checkmarx, Dependabot).• Exposure to legacy stacks, particularly IBM i / RPG or mainframe-adjacent systems.• Security certifications such as CISSP, OSCP, AWS Security Specialty, or GIAC.• Experience working with international clients in an embedded consulting role. Join CI&T and be a part of our mission to help global clients turn security risk into resolved risk. If you have a passion for vulnerability management and a track record of driving remediation programs at enterprise scale, we want to hear from you! #LI-JM5 At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions. With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy. We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.At CI&T, our rapid growth is fueled by the innovative solutions we create for our global clients. We are seeking an experienced Security Triage & Remediation Lead to own the triage and strategy function for a large US mortgage lender's enterprise vulnerability program. You will decide what gets fixed, in what order, and how — analyzing blast radius, sequencing remediation across teams you don't manage, and leading a live secrets rotation effort. You will also help upskill the client's internal engineering team, who know their codebase deeply but are new to enterprise-level triage work. Responsibilities: • Triage inbound vulnerabilities: validate, classify, and prioritize based on real exploitability and business impact rather than scanner severity alone.• Perform blast-radius and impact analysis across affected systems, services, and downstream consumers.• Own the secrets rotation strategy: inventory affected credentials, map ownership and consumers, and sequence rotation safely across production systems.• Coordinate remediation across multiple client delivery teams, aligning owners and unblocking work that spans team boundaries.• Define and maintain the remediation playbook: intake, severity criteria, SLAs, escalation paths, and closure criteria.• Report risk posture and backlog burn-down to VP-level client stakeholders in business language.• Provide technical direction to the remediation engineers: scope their work, review approach, and validate that fixes actually close the finding.• Upskill the client's internal team on triage methodology and secure remediation practices.• Integrate security validation and evidence capture into the client's existing delivery pipeline. Requirements: • Bachelor's degree in Computer Science, Information Technology, or a related field.• Solid experience in application security, vulnerability management, or security engineering.• Excellent English communication skills (reading, writing, and speaking) — this role leads calls with VP-level stakeholders.• Proven ownership of a vulnerability remediation program or triage function at enterprise scale.• Hands-on experience with secrets management and production credential rotation (AWS Secrets Manager, HashiCorp Vault, Parameter Store, or equivalent).• Strong AWS security fundamentals: IAM, least privilege, network exposure, and logging.• Ability to read and assess PHP code well enough to validate a remediation approach.• Expertise in threat modeling and blast-radius analysis, with practical command of CVSS, CWE, and the OWASP Top 10.• Proven track record of coordinating technical work across teams without formal authority. Nice to Have: • Experience in financial services, mortgage, or another regulated industry.• Incident response experience — containment, investigation, and post-incident hardening.• Familiarity with SAST, DAST, and SCA tooling (Snyk, Veracode, Checkmarx, Dependabot).• Exposure to legacy stacks, particularly IBM i / RPG or mainframe-adjacent systems.• Security certifications such as CISSP, OSCP, AWS Security Specialty, or GIAC.• Experience working with international clients in an embedded consulting role. Join CI&T and be a part of our mission to help global clients turn security risk into resolved risk. If you have a passion for vulnerability management and a track record of driving remediation programs at enterprise scale, we want to hear from you! #LI-JM5