Application Security Enablement Engineer

Manulife/John Hancock

Makati

Presencial

PHP 1 200 000 - 1 800 000

Tempo integral

Há 4 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Transforma esta função numa entrevista — um currículo e uma carta de apresentação criados à volta do que este empregador procura.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Hybrid work
Equal opportunity employer

Resumo da oferta

Manulife/John Hancock is seeking an experienced Application Security Expert in a hybrid role in Metro Manila. The candidate will promote secure coding practices, guide DevSecOps workflows, and integrate security into CI/CD pipelines across enterprise applications and cloud environments.

Responsibilities include threat modeling, security testing (SAST/DAST), and providing actionable guidance to development teams to reduce risk and improve security posture.

Qualificações

  • Minimum 5+ years in application security or secure software development.
  • Strong knowledge of SDLC, CI/CD, and secure coding practices.
  • Experience with application penetration testing and OWASP guidance.

Responsabilidades

  • Drive adoption of enterprise app security standards across apps, platforms, and cloud.
  • Enable automation for vulnerability detection, remediation, and reporting.
  • Provide risk-based guidance and training to developers on secure design.
  • Embed secure-by-design principles with architects and product teams.
  • Conduct and validate app security testing including external findings.

Conhecimentos

Application security
DevSecOps
Secure coding
OWASP Top 10
CI/CD pipelines
Threat modeling

Formação académica

Bachelor's degree in CS/IS

Ferramentas

SAST
DAST
SCA
Secrets management
Container security
Kubernetes
IaC tooling

Descrição da oferta de emprego

Position Responsibilities:
  • Help drive adoption of enterprise application security standards across applications, platforms, and cloud environments
  • Enable automation for vulnerability detection, remediation, exception review and reporting to improve efficiency and consistency.
  • Provide actionable, risk-based technical guidance and training to developers on secure design and coding standards (e.g., OWASP).
  • Partner with architects, product owners, and development teams during design and planning phases to embed secure-by-design principles.
  • Conduct and validate application security testing (automated and manual), including intake and validation of findings from external penetration tests and bug bounty programs.
Accountabilities:
Individual Accountabilities:
  • Support vulnerability management processes, including triage, exception review, remediation, and reporting.
  • Conduct application and architecture-level Threat Modeling for new applications, major enhancements, and high-risk changes.
  • Support uplift of Threat Modeling maturity by defining templates, playbooks, and reusable threat libraries for common platforms and patterns.
  • Support to scale workstreams such as secrets, SCA, SAST, DAST vulnerability remediation.
  • Partner with development teams to integrate security expectations into CI/CD pipelines and DevSecOps workflows.
  • Validate and contextualize findings from automated tools, penetration tests, and external assessments where design-level issues are identified.
Key Shared Accountabilities:
  • Partner with Global Application Security on standards, tooling and continuous improvement
  • Collaborate with CIO, engineering, and architecture teams to ensure consistent adoption and accountability
  • Align with Vulnerability Management function on remediation prioritization and risk treatment
  • Support audit, regulatory, and control assurance activities
Required Qualifications:
  • Minimum 5+ years in application security or software development roles with a focus on secure coding and DevSecOps.
  • Strong understanding of application security principles, SDLC, and CI/CD pipelines.
  • Strong understanding of application penetration testing.
  • Knowledge of secure coding standards and frameworks (e.g., OWASP Top 10, NIST).
  • Excellent collaboration and communication skills to engage developers and stakeholders.
Preferred Qualifications:
  • Hands‑on experience with security tools (e.g., Secrets, SCA, SAST, Container security, DAST) and automation frameworks.
  • Familiarity with cloud‑native application security concepts.
  • Certifications: OSCP, CISSP or preferred equivalent.
  • Additional certifications such as Advanced application testing certifications (OSWP, GIAC GWAPT, INE eWPTX) are considered an advantage.
Tooling and Technology Coverage:
  • In addition to SAST, DAST, and SCA, familiarity with complementary controls such as WAF and NAC were relevant to application-layer protection.
  • Practical exposure to API security, Kubernetes and container platforms, Infrastructure as Code (IaC), hybrid cloud environments, and penetration testing or vulnerability scanning toolchains.
When you join our team:

We’ll empower you to learn and grow the career you want.

We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.

As part of our global team, we’ll support you in shaping the future you want to see.

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better.

To learn more about us, visit https://www.manulife.com/en/about/our-story.html.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals.

We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies.

To request a reasonable accommodation in the application process, contact hr@manulife.com.

Working Arrangement Hybrid

We’re Manulife. And we’re on a mission to make decisions easier and lives better.

Better is what drives us. It’s what inspires us to find new ways to support customers and colleagues in living longer and healthier lives. It’s the reason we’re dedicated to investing in digital innovation and industry-leading AI, and accelerating a sustainable and economically inclusive future. Joining us means you’ll be empowered to learn and grow your career. We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words. And as part of our global team, you’ll help shape the future you want to see – and discover that better can take you anywhere you want to go.

We’re proud of our accomplishments and recognition. Recent awards include: 2026 Gallup Exceptional Workplace Award Winner Manulife Named one of Forbes World’s Best Employers 2025 Financial Times World’s Best Employers Asia-Pacific 2026 We’ve been recognized as one of Canada’s Top 100 Employers 2026 #1 Life Insurer for AI Maturity by Evident 2026.

Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Platform Engineer
Platform Engineer

Manulife/John Hancock • Makati

Híbrido
PHP 900 000 - 1 400 000
Hybrid work arrangement
Equal opportunity employer
Risk and Controls Manager
Risk and Controls Manager

Manulife/John Hancock • Manila

Presencial
PHP 900 000 - 1 500 000
Full Stack Software Engineer
Full Stack Software Engineer

Manulife/John Hancock • Makati

Híbrido
PHP 1 339 000 - 2 009 000
Business Analytics Specialist
Business Analytics Specialist

Manulife/John Hancock • Manila

Híbrido
PHP 600 000 - 900 000
Hybrid work arrangement
Director, Reporting, Advanced Analytics and Automation (RAA)
Director, Reporting, Advanced Analytics and Automation (RAA)

Manulife/John Hancock • Manila

Híbrido
PHP 7 514 000 - 11 271 000
Application Security Enablement Engineer
Application Security Enablement Engineer

Manulife • Makati

Híbrido
PHP 2 000 000 - 3 200 000
Lead Data Analyst
Lead Data Analyst

Manulife/John Hancock • Manila

Híbrido
PHP 1 200 000 - 1 800 000
Hybrid work arrangement
Inclusive culture
Equal opportunity employer
Plan Member Administrator I
Plan Member Administrator I

Manulife/John Hancock • Manila

Híbrido
PHP 360 000 - 480 000
Lead Full Stack Software Engineer
Lead Full Stack Software Engineer

Manulife/John Hancock • Makati

Híbrido
PHP 2 400 000 - 3 600 000
Administrative Assistant
Administrative Assistant

Manulife/John Hancock • Manila

Presencial
PHP 420 000 - 600 000