At CI&T, our rapid growth is fueled by the innovative solutions we create for our global clients.
We are seekingtalented Security Remediation Developers to accelerate vulnerability remediation throughput for a large US mortgage lender. Their vulnerability management program is surfacing more fixes than the internal teams can execute, and you will close that gap - researching each finding, implementing the fix at code and configuration level, deploying it, and proving it is closed. This is hands-on engineering work, not advisory work: you will spend your days in the codebase and in AWS.
Responsibilities:
- Take prioritized remediation items from the backlog and drive them to deployed, validated completion.
- Research assigned vulnerabilities: reproduce where possible, identify root cause, and determine the correct fix rather than the fastest one.
- Implement code-level remediation in PHP: refactor vulnerable patterns, fix injection, authentication, deserialization, and exposure defects, and remove hardcoded credentials.
- Perform dependency and package upgrades, resolving breaking changes and transitive conflicts.
- Perform AWS-side remediation and deployment, including configuration hardening and IAM adjustments.
- Execute secret rotation tasks in coordination with the Remediation Lead, updating consumers and migrating credentials to a managed secrets store.
- Validate every fix: write or extend automated tests, confirm the finding no longer reproduces, and document closure evidence the client's risk program can report on.
- Work embedded with the client's engineering team, following their branching, code review, CI/CD, and definition of done.
- Identify recurring patterns that warrant a systemic fix rather than repeated one-off remediation, and contribute them to the remediation playbook.
- Support the client's engineers in adopting secure coding practices.
Requirements:
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- Professional PHP development experience, including work on legacy or inherited codebases.
- Good English communication skills (reading, writing, and speaking) - daily collaboration with a US-based engineering team.
- Demonstrated secure coding practice, with the OWASP Top 10 as vulnerabilities you have personally remediated.
- Practical AWS experience
- Strong dependency management with Composer, including resolving upgrade conflicts.
- Proficiency with Git, code review discipline, and CI/CD pipelines.
- Experience writing automated tests with PHPUnit or an equivalent framework.
Nice to Have:
- Experience remediating scanner findings at volume (Snyk, Veracode, Dependabot, Checkmarx).
- Prior experience burning down a security or technical debt backlog against throughput targets.
- Modern PHP frameworks such as Laravel or Symfony, alongside legacy pre-framework PHP.
- Infrastructure as Code with Terraform or CloudFormation.
- AWS experience deploying and operating PHP applications, covering compute (EC2, ECS, Elastic Beanstalk, or Lambda), IAM, S3, RDS, CloudWatch, and Secrets Manager or Parameter Store.
- Containerization experience with Docker and ECS or EKS.
- Experience integrating with legacy systems such as IBM i / RPG or SOAP services.
- Experience in mortgage, lending, or financial services.
- Experience working with international clients.
Join CI&T and be a part of our mission to build secure, resilient software for our global clients. If you have a passion for PHP and AWS engineering and take satisfaction in closing security findings for good, we want to hear from you!

