[Job - 31023] Security Triage & Remediation Lead, Brazil

🏢 CI&T · all CI&T jobs
📍 Brazil
📅 Posted 2026-08-16 · via Himalayas
🏷 Security-Triage,Vulnerability-Management,Application-Security,Security-Remediation,Security-Engineering,Lead-Security-Incident-Responder,Lead-Security-Operations-Analyst,Security-Operations-Lead
Apply on original site ↗
At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions. With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy. We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day. At CI&T, our rapid growth is fueled by the innovative solutions we create for our global clients. We are seeking an experienced Security Triage & Remediation Lead to own the triage and strategy function for a large US mortgage lender's enterprise vulnerability program. You will decide what gets fixed, in what order, and how — analyzing blast radius, sequencing remediation across teams you don't manage, and leading a live secrets rotation effort. You will also help upskill the client's internal engineering team, who know their codebase deeply but are new to enterprise-level triage work. Responsibilities: • Triage inbound vulnerabilities: validate, classify, and prioritize based on real exploitability and business impact rather than scanner severity alone. • Perform blast-radius and impact analysis across affected systems, services, and downstream consumers. • Own the secrets rotation strategy: inventory affected credentials, map ownership and consumers, and sequence rotation safely across production systems. • Coordinate remediation across multiple client delivery teams, aligning owners and unblocking work that spans team boundaries. • Define and maintain the remediation playbook: intake, severity criteria, SLAs, escalation paths, and closure criteria. • Report risk posture and backlog burn-down to VP-level client stakeholders in business language. • Provide technical direction to the remediation engineers: scope their work, review approach, and validate that fixes actually close the finding. • Upskill the client's internal team on triage methodology and secure remediation practices. • Integrate security validation and evidence capture into the client's existing delivery pipeline. Requirements: • Bachelor's degree in Computer Science, Information Technology, or a related field. • Solid experience in application security, vulnerability management, or security engineering. • Excellent English communication skills (reading, writing, and speaking) — this role leads calls with VP-level stakeholders. • Proven ownership of a vulnerability remediation program or triage function at enterprise scale. • Hands-on experience with secrets management and production credential rotation (AWS Secrets Manager, HashiCorp Vault, Parameter Store, or equivalent). • Strong AWS security fundamentals: IAM, least privilege, network exposure, and logging. • Ability to read and assess PHP code well enough to validate a remediation approach. • Expertise in threat modeling and blast-radius analysis, with practical command of CVSS, CWE, and the OWASP Top 10. • Proven track record of coordinating technical work across teams without formal authority. Nice to Have: • Experience in financial services, mortgage, or another regulated industry. • Incident response experience — containment, investigation, and post-incident hardening. • Familiarity with SAST, DAST, and SCA tooling (Snyk, Veracode, Checkmarx, Dependabot). • Exposure to legacy stacks, particularly IBM i / RPG or mainframe-adjacent systems. • Security certifications such as CISSP, OSCP, AWS Security Specialty, or GIAC. • Experience working with international clients in an embedded consulting role. Join CI&T and be a part of our mission to help global clients turn security risk into resolved risk. If you have a passion for vulnerability management and a track record of driving remediation programs at enterprise scale, we want to hear from you! Our benefits: - Health a

← All remote jobs