Application Security Enablement Engineer

Manulife group

Makati

On-site

PHP 1,800,000 - 2,400,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Manulife group in the Asia region is seeking an Application Security Enablement Engineer to drive secure development practices across the SDLC in Asia markets. You will bridge global security strategy with regional execution, partnering with application development, engineering, and architecture teams to strengthen the security posture.

You will lead vulnerability assessment, threat modeling, and remediation prioritization, automate detection and reporting, and provide practical guidance to

Qualifications

  • Minimum 5+ years in application security or secure development roles.
  • Strong understanding of SDLC, CI/CD pipelines and app security principles.
  • Experience with penetration testing and secure coding standards.

Responsibilities

  • Drive enterprise application security standards across apps, platforms and cloud environments.
  • Enable automation for vulnerability detection, remediation, exception review and reporting.
  • Provide risk-based technical guidance and training to developers on secure design and coding standards (OWASP).
  • Partner with architects, product owners, and development teams to embed secure-by-design principles.
  • Conduct and validate application security testing and review external findings.

Skills

Application security
Secure coding
DevSecOps
CI/CD pipelines
Team collaboration

Tools

SAST
DAST
SCA
Container security
WAF
NAC

Job description

Application Security Enablement Engineer

The Asia CISO function is responsible for ensuring effective cybersecurity risk management, regulatory compliance, and secure technology enablement across all Asia markets. This role sits within the regional cybersecurity leadership team and is accountable for application security enablement across the software development lifecycle. It serves as the bridge between global application security strategy and regional execution, driving outcomes through strong partnership and influence across application development, engineering, and architecture teams in both regional and market environments.

Deliver application security engineering and enablement capabilities across Asia, embedding secure development practices into the software development lifecycle (SDLC) and enabling adoption of enterprise security standards. This role focuses on driving vulnerability assessment, prioritization and remediation, centralized exception review, threat modeling, and SME support to strengthen application security posture.

Position Responsibilities:
  • Help drive adoption of enterprise application security standards across applications, platforms, and cloud environments
  • Enable automation for vulnerability detection, remediation, exception review and reporting to improve efficiency and consistency.
  • Provide actionable, risk-based technical guidance and training to developers on secure design and coding standards (e.g., OWASP).
  • Partner with architects, product owners, and development teams during design and planning phases to embed secure-by-design principles.
  • Conduct and validate application security testing (automated and manual), including intake and validation of findings from external penetration tests and bug bounty programs.
Accountabilities:
Individual Accountabilities:
  • Support vulnerability management processes, including triage, exception review, remediation, and reporting.
  • Conduct application and architecture-level Threat Modeling for new applications, major enhancements, and high-risk changes.
  • Support uplift of Threat Modeling maturity by defining templates, playbooks, and reusable threat libraries for common platforms and patterns.
  • Support to scale workstreams such as secrets, SCA, SAST, DAST vulnerability remediation.
  • Partner with development teams to integrate security expectations into CI/CD pipelines and DevSecOps workflows.
  • Validate and contextualize findings from automated tools, penetration tests, and external assessments where design-level issues are identified.
Key Shared Accountabilities:
  • Partner with Global Application Security on standards, tooling and continuous improvement
  • Collaborate with CIO, engineering, and architecture teams to ensure consistent adoption and accountability
  • Align with Vulnerability Management function on remediation prioritization and risk treatment
  • Support audit, regulatory, and control assurance activities
Required Qualifications:
  • Minimum 5+ years in application security or software development roles with a focus on secure coding and DevSecOps.
  • Strong understanding of application security principles, SDLC, and CI/CD pipelines.
  • Strong understanding of application penetration testing
  • Knowledge of secure coding standards and frameworks (e.g., OWASP Top 10, NIST).
  • Excellent collaboration and communication skills to engage developers and stakeholders.
Preferred Qualifications:
  • Hands-on experience with security tools (e.g., Secrets, SCA, SAST, Container security, DAST) and automation frameworks.
  • Familiarity with cloud-native application security concepts.
  • Certifications: OSCP, CISSP or preferred equivalent.
  • Additional certifications such as Advanced application testing certifications (OSWP, GIAC GWAPT, INE eWPTX) are considered an advantage.
Tooling and Technology Coverage:
  • In addition to SAST, DAST, and SCA, familiarity with complementary controls such as WAF and NAC were relevant to application-layer protection.
  • Practical exposure to API security, Kubernetes and container platforms, Infrastructure as Code (IaC), hybrid cloud environments, and penetration testing or vulnerability scanning toolchains.
When you join our team:
  • We’ll empower you to learn and grow the career you want.
  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we’ll support you in shaping the future you want to see.
Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact hr@manulife.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Enablement Engineer
Application Security Enablement Engineer

Manulife John Hancock • Makati

On-site
PHP 1,800,000 - 3,200,000
Application Security Enablement Engineer
Application Security Enablement Engineer

Manulife • Makati

Hybrid
PHP 2,000,000 - 3,200,000
Security Engineer
Security Engineer

Manulife IT Delivery Center Asia Inc. • Makati

On-site
PHP 1,200,000 - 1,800,000
Penetration Tester
Penetration Tester

Manulife IT Delivery Center Asia Inc. • Makati

On-site
PHP 1,200,000 - 1,900,000
Application Security Intern
Application Security Intern

Manulife • Philippines

On-site
PHP 167,000 - 234,000
Lead Full Stack Software Engineer
Lead Full Stack Software Engineer

Manulife group • Makati

Hybrid
PHP 1,800,000 - 3,000,000
Application Security Enablement Engineer
Application Security Enablement Engineer

Manulife/John Hancock • Makati

On-site
PHP 1,200,000 - 1,800,000
Hybrid work
Equal opportunity employer
Cybersecurity Manager
Cybersecurity Manager

Manulife Financial • Quezon City

On-site
PHP 1,400,000 - 2,100,000
Hybrid work arrangement
Global exposure
Application Security Engineer (Threat Modeling)
Application Security Engineer (Threat Modeling)

Manulife • Quezon City

Hybrid
PHP 1,200,000 - 2,400,000
Cybersecurity Manager
Cybersecurity Manager

Manulife/John Hancock • Manila

On-site
PHP 1,200,000 - 1,800,000