1 день назад
Security Triage & Remediation Lead (AWS)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Triage & Remediation Lead (AWS): Owning enterprise vulnerability triage and remediation strategy for a large US mortgage lender with an accent on exploitability analysis, secrets rotation, and cross-team coordination. Focus on analyzing blast radius, sequencing production credential rotations, validating remediation approaches, and reporting risk posture to VP-level stakeholders.
Location: Brazil; remote home office
Company
CI&T delivers AI deployment, application modernization, data and AI, martech, and technology-integrated business solutions for global enterprise clients.
What you will do
- Own vulnerability intake, validation, classification, prioritization, and remediation strategy based on exploitability and business impact.
- Perform blast-radius and impact analysis across systems, services, and downstream consumers.
- Define and lead secrets inventory, ownership mapping, and safe production credential rotation.
- Coordinate remediation across client delivery teams and maintain playbooks, SLAs, escalation paths, and closure criteria.
- Direct remediation engineers, validate fixes, and integrate security evidence into the delivery pipeline.
- Report risk posture and backlog reduction to VP-level stakeholders and upskill the client engineering team.
Requirements
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- Strong experience in application security, vulnerability management, or security engineering, including ownership of an enterprise-scale triage or remediation program.
- Excellent English communication skills required for leading calls with VP-level stakeholders.
- Hands-on experience with secrets management and production credential rotation using AWS Secrets Manager, HashiCorp Vault, Parameter Store, or equivalent.
- Strong AWS security fundamentals covering IAM, least privilege, network exposure, and logging.
- Ability to assess PHP code and apply threat modeling, blast-radius analysis, CVSS, CWE, and the OWASP Top 10.
Nice to have
- Experience in financial services, mortgage, or another regulated industry.
- Incident response experience, including containment, investigation, and post-incident hardening.
- Familiarity with SAST, DAST, and SCA tools such as Snyk, Veracode, Checkmarx, and Dependabot.
- Experience with legacy stacks, including IBM i, RPG, or mainframe-adjacent systems.
- Security certifications such as CISSP, OSCP, AWS Security Specialty, or GIAC.
Culture & Benefits
- Remote home-office work in Brazil.
- Work with global enterprise clients and international delivery teams.
- Company benefits are provided through CI&T's Brazil careers program.
Hiring process
- Present an assessment during the selection process.
- Support is available for obtaining the assessment if needed.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Staff Security Engineer (AppSec)
2 дня назад
Senior Security Engineer | AppSec
5 дней назад
Senior Security Architect Vulnerability Management (AWS)
2 дня назад
DevSecOps Engineer / Security Solutions Lead (AI Security)
2 дня назад
Product Security Incident Response Team (PSIRT) Vulnerability Analyst (Cybersecurity)
5 дней назад