
At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions.
With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy.
We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.
At CI&T, our rapid growth is fueled by the innovative solutions we create for our global clients.
We are seeking an experienced Security Triage & Remediation Lead to own the triage and strategy function for a large US mortgage lender's enterprise vulnerability program. You will decide what gets fixed, in what order, and how — analyzing blast radius, sequencing remediation across teams you don't manage, and leading a live secrets rotation effort. You will also help upskill the client's internal engineering team, who know their codebase deeply but are new to enterprise-level triage work.
Responsibilities:
• Triage inbound vulnerabilities: validate, classify, and prioritize based on real exploitability and business impact rather than scanner severity alone.
• Perform blast-radius and impact analysis across affected systems, services, and downstream consumers.
• Own the secrets rotation strategy: inventory affected credentials, map ownership and consumers, and sequence rotation safely across production systems.
• Coordinate remediation across multiple client delivery teams, aligning owners and unblocking work that spans team boundaries.
• Define and maintain the remediation playbook: intake, severity criteria, SLAs, escalation paths, and closure criteria.
• Report risk posture and backlog burn-down to VP-level client stakeholders in business language.
• Provide technical direction to the remediation engineers: scope their work, review approach, and validate that fixes actually close the finding.
• Upskill the client's internal team on triage methodology and secure remediation practices.
• Integrate security validation and evidence capture into the client's existing delivery pipeline.
Requirements:
• Bachelor's degree in Computer Science, Information Technology, or a related field.
• Solid experience in application security, vulnerability management, or security engineering.
• Excellent English communication skills (reading, writing, and speaking) — this role leads calls with VP-level stakeholders.
• Proven ownership of a vulnerability remediation program or triage function at enterprise scale.
• Hands-on experience with secrets management and production credential rotation (AWS Secrets Manager, HashiCorp Vault, Parameter Store, or equivalent).
• Strong AWS security fundamentals: IAM, least privilege, network exposure, and logging.
• Ability to read and assess PHP code well enough to validate a remediation approach.
• Expertise in threat modeling and blast-radius analysis, with practical command of CVSS, CWE, and the OWASP Top 10.
• Proven track record of coordinating technical work across teams without formal authority.
Nice to Have:
• Experience in financial services, mortgage, or another regulated industry.
• Incident response experience — containment, investigation, and post-incident hardening.
• Familiarity with SAST, DAST, and SCA tooling (Snyk, Veracode, Checkmarx, Dependabot).
• Exposure to legacy stacks, particularly IBM i / RPG or mainframe-adjacent systems.
• Security certifications such as CISSP, OSCP, AWS Security Specialty, or GIAC.
• Experience working with international clients in an embedded consulting role.
Join CI&T and be a part of our mission to help global clients turn security risk into resolved risk. If you have a passion for vulnerability management and a track record of driving remediation programs at enterprise scale, we want to hear from you!
#LI-JM5
Our benefits: -Health and dental insurance-Meal and food allowance-Childcare assistance-Extended paternity leave-Partnership with gyms and health and wellness professionals via Wellhub (Gympass) TotalPass;-Profit Sharing and Results Participation (PLR);-Life insurance-Continuous learning platform (CI&T University);-Discount club-Free online platform dedicated to physical, mental, and overall well-being-Pregnancy and responsible parenting course-Partnerships with online learning platforms-Language learning platformAnd many more! More details about our benefits here: https://ciandt.com/br/pt-br/carreiras At CI&T, inclusion starts at the first contact. If you are a person with a disability, it is important to present your assessment during the selection process. See which data needs to be included in the report by clicking here.This way, we can ensure the support and accommodations that you deserve. If you do not yet have the assessment, don't worry: we can support you in obtaining it. We have a dedicated Health and Well-being team, inclusion specialists, and affinity groups who will be with you at every stage. Count on us to make this journey side by side.