Skip to content

CI&T

[Job - 31026] Senior PHP Developer (Security Remediation), Brazil

Location
Brazil, BR
Arrangement
Remote
Employment type
Other
Level
Senior
Posted
14 August 2026 (about a month ago)

Checked 27 days agoApplications go to the employer, never to RoleSprint

About this role

At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions. With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy. We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.

At CI&T, we help large enterprises transform the potential of AI into real business impact with AI Deployment, AI-native execution, and tech-integrated business solutions. With 30 years of experience in technological transformation, we accelerate innovation with expertise in Agentic SDLC, Application modernization, Data & AI, Martech and Business strategy. We are 8,000 CI&Ters across more than 25 countries, collaborating to build solutions with real impact. AI is already part of how we work, evolve, and innovate every day.

We are looking for a PHP Security Remediation Developer to join the vulnerability remediation program of one of our clients. Their security scanning tooling is surfacing more findings than the internal team can close — your job is to close that gap. This is not advisory work and it is not a pure security analyst role: you will spend your days in the PHP codebase and in AWS, implementing fixes, validating closures, and driving remediation throughput at scale.The ideal candidate has worked extensively with PHP and has hands-on experience remediating security vulnerabilities, not just identifying them. What You Will Do Take prioritized findings from the security backlog and drive each one to deployed, validated completion — researching root cause, implementing the correct fix, deploying it, and producing closure evidence for the client's risk program. Remediate PHP vulnerabilities hands-on: fix injection, authentication, deserialization, and credential exposure defects; refactor vulnerable patterns; and remove hardcoded secrets. Perform dependency and package upgrades using Composer, resolving breaking changes and transitive conflicts. Execute AWS-side remediation: configuration hardening, IAM adjustments, and secret rotation — migrating credentials to a managed secrets store in coordination with the Remediation Lead. Validate every fix through automated tests and confirm the finding no longer reproduces. Identify recurring patterns that warrant a systemic fix rather than repeated one-off remediation, and contribute them to the team playbook. Work embedded with the client's engineering team, following their branching, code review, CI/CD, and definition of done. Support client engineers in adopting secure coding practices. What We Require Professional PHP development experience — including work on legacy or inherited codebases. Recent, active PHP work is required; Hands-on security remediation experience — you must have personally fixed OWASP Top 10 class vulnerabilities at code level. Understanding them conceptually is not enough. Excellent English communication skills — daily written and spoken collaboration with a US-based engineering team. Senior or above seniority level Experience writing automated tests with PHPUnit or equivalent. Bachelor's degree in Computer Science, Information Technology, or a related field. Nice to Have Proficiency with Git, code review discipline, and CI/CD pipelines. Experience working with security scanners at volume: Snyk, Veracode, Dependabot, or Checkmarx. Prior experience burning down a security or technical debt backlog against throughput targets. Modern PHP frameworks (Laravel, Symfony) alongside legacy pre-framework PHP. AWS experience specifically with PHP applications: EC2, ECS, Elastic Beanstalk, Lambda, IAM, S3, RDS, CloudWatch, Secrets Manager, or Parameter Store. Infrastructure as Code with Terraform or CloudFormation. Containerization with Docker and ECS or EKS. Experience integrating with legacy systems #LI-JM5

Our benefits:

-Health and dental insurance -Meal and food allowance -Childcare assistance -Extended paternity leave -Partnership with gyms and health and wellness professionals via Wellhub (Gympass) TotalPass; -Profit Sharing and Results Participation (PLR); -Life insurance -Continuous learning platform (CI&T University); -Discount club -Free online platform dedicated to physical, mental, and overall well-being -Pregnancy and responsible parenting course -Partnerships with online learning platforms -Language learning platform And many more!

More details about our benefits here: https://ciandt.com/br/pt-br/carreiras

At CI&T, inclusion starts at the first contact. If you are a person with a disability, it is important to present your assessment during the selection process. See which data needs to be included in the report by clicking here.This way, we can ensure the support and accommodations that you deserve. If you do not yet have the assessment, don't worry: we can support you in obtaining it.

We have a dedicated Health and Well-being team, inclusion specialists, and affinity groups who will be with you at every stage. Count on us to make this journey side by side.

Work location

  • BR

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Lever under the board identifier Ciandt, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 14 August 2026, last checked 27 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

Browse all current openings

No credit card requiredStart free