[Job - 31023] Security Triage & Remediation Lead, Brazil

Ci&T
Remote
Posted 3 days ago
Theta

AI summary

The Security Triage & Remediation Lead will manage the triage and strategy for an enterprise vulnerability program, coordinating remediation efforts and upskilling the client's engineering team on triage practices.

Eligible from: Brazil

Job Description

At CI&T, our rapid growth is fueled by the innovative solutions we create for our global clients.

We are seeking an experienced Security Triage & Remediation Lead to own the triage and strategy function for a large US mortgage lender's enterprise vulnerability program. You will decide what gets fixed, in what order, and how — analyzing blast radius, sequencing remediation across teams you don't manage, and leading a live secrets rotation effort. You will also help upskill the client's internal engineering team, who know their codebase deeply but are new to enterprise-level triage work.
 
 
Responsibilities:
 
• Triage inbound vulnerabilities: validate, classify, and prioritize based on real exploitability and business impact rather than scanner severity alone.
• Perform blast-radius and impact analysis across affected systems, services, and downstream consumers.
• Own the secrets rotation strategy: inventory affected credentials, map ownership and consumers, and sequence rotation safely across production systems.
• Coordinate remediation across multiple client delivery teams, aligning owners and unblocking work that spans team boundaries.
• Define and maintain the remediation playbook: intake, severity criteria, SLAs, escalation paths, and closure criteria.
• Report risk posture and backlog burn-down to VP-level client stakeholders in business language.
• Provide technical direction to the remediation engineers: scope their work, review approach, and validate that fixes actually close the finding.
• Upskill the client's internal team on triage methodology and secure remediation practices.
• Integrate security validation and evidence capture into the client's existing delivery pipeline.
 
 
Requirements:
 
• Bachelor's degree in Computer Science, Information Technology, or a related field.
• Solid experience in application security, vulnerability management, or security engineering.
• Excellent English communication skills (reading, writing, and speaking) — this role leads calls with VP-level stakeholders.
• Proven ownership of a vulnerability remediation program or triage function at enterprise scale.
• Hands-on experience with secrets management and production credential rotation (AWS Secrets Manager, HashiCorp Vault, Parameter Store, or equivalent).
• Strong AWS security fundamentals: IAM, least privilege, network exposure, and logging.
• Ability to read and assess PHP code well enough to validate a remediation approach.
• Expertise in threat modeling and blast-radius analysis, with practical command of CVSS, CWE, and the OWASP Top 10.
• Proven track record of coordinating technical work across teams without formal authority.
 
 
Nice to Have:
 
• Experience in financial services, mortgage, or another regulated industry.
• Incident response experience — containment, investigation, and post-incident hardening.
• Familiarity with SAST, DAST, and SCA tooling (Snyk, Veracode, Checkmarx, Dependabot).
• Exposure to legacy stacks, particularly IBM i / RPG or mainframe-adjacent systems.
• Security certifications such as CISSP, OSCP, AWS Security Specialty, or GIAC.
• Experience working with international clients in an embedded consulting role.
 
 
Join CI&T and be a part of our mission to help global clients turn security risk into resolved risk. If you have a passion for vulnerability management and a track record of driving remediation programs at enterprise scale, we want to hear from you!

#LI-JM5

Ready to Apply?

Take the next step in your career journey

Apply Now

About the job

Posted on
Aug 14, 2026
Job type
Full-time
Location
BrazilRemote

Keep looking

Related roles you might like

Explore more

Browse more jobs like this

Category

Work arrangement

Disclaimer: Real Jobs From Anywhere is an independent platform dedicated to providing information about job openings. We are not affiliated with, nor do we represent, any company, agency, or agent mentioned in the job listings. Please refer to our Terms of Services for further details.