Application Security Engineer

Manulife

Philippines

Hybrid

PHP 1,000,000 - 1,400,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Manulife is seeking a Security Engineer with a secured Application Development background to join the Global Cybersecurity Services – Application Security Rapid Lab team in Quezon City. The role focuses on remediation of secrets and credentials in source code and building secured modules to help business units avoid secrets in code repositories.

You will work with the Application Security core team to design and implement remediation strategies, APIs, and reusable libraries, while ensuring

Qualifications

  • Bachelor’s degree in computer science or related discipline.
  • Minimum 3 years of hands-on application development experience, preferably using Java/Python/C#.
  • At least 3 years of experience in software secrets management, credentials, and secret lifecycle in application development.
  • Demonstrated knowledge of secure SDLC and security testing (SCA, SAST, DAST, Secrets scans).
  • Familiarity with security assessment frameworks and best practices.

Responsibilities

  • Work with Application Security team to drive secrets remediation initiatives.
  • Contribute to building internal reusable libraries for remediation of secrets/credentials in source code.
  • Evaluate security requirements and migrate secrets to vaults (AKV, Hashicorp).
  • Design secure code and ensure it passes Application Security gates.
  • Develop utilities to resolve hard-coded secrets in configuration files and migrate to vaults.
  • Participate in project meetings and organize solution design, checkpoints.
  • Promote automation and self-healing approaches in remediation efforts.

Skills

Application development
Java/Python/C#
Secrets management
Secure SDLC
Security assessment
GitHub
Snyk
GitGuardian

Education

Bachelor’s degree in computer science

Tools

GitHub
Snyk
GitGuardian

Job description

We’re looking for a Security Engineer with secured Application Development background to join our Global Cybersecurity Services – Application Security Rapid Lab team. In this role, you are expected to work directly with the Application Security core team to build and support the remediation of security vulnerabilities. The team is focusing on building the secured modules to help the business units to avoid any secrets on the source code repositories.

Have the skills and knowledge for the job?

Position Responsibilities:
  • Work closely with Application Security team to drive the initiative of secrets remediation program
  • Part of Cyber Assessment team, to build internal reusable libraries as a standalone component in remediation of secrets/credentials in the source code
  • Evaluating and attempting to understand organization security requirements and secrets/credentials to be moved to vaults specifically to AKV and Hashicorp
  • Understanding secure design to ensure newly built codes are secured and pass through the Application security gates
  • Independently design and develop utilities to resolve the larger problem of hard coded secrets in the configuration files to be migrated to the vaults
  • Participate in project related meetings: information gathering, solution design, project checkpoints
  • Keeping automation in mind while developing the solution for remediation to self-heal solutions
  • Propose, examine and assist in the solution design to adequately resolve or remediate the hard coded secrets from source code while keeping away any impact to the system
  • Evaluate business needs while solving the problem, design thinking and effective communication with stakeholders
  • Apply creative problem solving throughout the secure software development life cycle to continuously improve the effectiveness of the end-to-end process.
  • Ideate. Test. Learn. Iterate. Bring a flexible, adaptive mindset, comfortable with ambiguity in a rapidly changing technology environment.
  • Be a continuous learner, not only for your own career, but from teams’ successes and failures.
  • Embrace open-source communities, both internally and externally, sharing your knowledge across your team and peers.
Required qualifications:
  • Education: Bachelor’s degree in computer science or related discipline
  • Experience: Minimum 3 years of experience in performing hands-on application development preferably using Java/Python/C# programming languages
  • Software design and development experience, especially in building backend systems.
  • At least 3 years of experience in software secrets management, credentials, and secret life cycle in application development
  • Demonstrated technical knowledge of secure SDLC, understanding GitHub, SCA, SAST, DAST, and Secrets scans are a must
  • Demonstrated experience with security assessment frameworks and procedures, including following industry best practice methodologies to ensure business components are ready
  • Must be amenable to work in Quezon City on a hybrid setup on a mid- to night-shift schedule, depending on the business need.
Preferred qualifications:
  • Adequate knowledge on different types of Secrets used in Application, specific hands-on experience in dealing with API credentials are always plus point
  • Possess good holding on the SDLC tools like IDE, GitHub, Snyk, GitGuardian and the best programming practices
  • Extensive technical knowledge of security industry best practices and procedures.
  • Experience in developing security tools, using scripts and utilities to automate assessment and analysis activities
  • Excellent verbal and written communication skills including the ability to articulate the remediation steps back to the customers
  • Exceptional customer service, communication and interpersonal skills.
  • Ability to communicate and work closely with executives, peers and employees at all levels.
  • Strong time management and organizational discipline
  • High degree of integrity, competence, adaptability, resilience and initiative.
  • Experience working in an international environment with people from multiple cultures preferred.
When you join our team:
  • We’ll empower you to learn and grow the career you want.
  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we’ll support you in shaping the future you want to see.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer: Secrets & Vaults
Application Security Engineer: Secrets & Vaults

Manulife • Philippines

Hybrid
PHP 1,000,000 - 1,400,000
Application Security Engineer
Application Security Engineer

Sideways 6 • Philippines

On-site
PHP 1,200,000 - 1,900,000
Application Security Engineer
Application Security Engineer

Recruitify_HR • Quezon City

Hybrid
Up to 80k joining bonus
Hybrid work model
Competitive salary
VP Application Security
VP Application Security

Hrtx • Taguig

On-site
PHP 400,000 - 700,000
Application Security Engineer
Application Security Engineer

Career Connect • Makati

On-site
PHP 700,000 - 1,100,000
Application Security Engineer
Application Security Engineer

Interact Software • Metro Manila

On-site
PHP 700,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Trinity Workforce Solutions, Inc. • Makati

On-site
PHP 800,000 - 1,200,000
Collaborate with talented teams
Work on real-world security challenges
Career growth in a security-first culture
Application Security Engineer / Application Security Lead
Application Security Engineer / Application Security Lead

Recruitify_HR • Taguig

Hybrid
PHP 800,000 - 1,000,000
IT Service Delivery Lead
IT Service Delivery Lead

Manulife Business Processing Services (MBPS) • Quezon City

Hybrid
PHP 1,200,000 - 1,600,000
VP for Application Security
VP for Application Security

Hrtx • Taguig

Hybrid
PHP 5,000,000 - 9,000,000
Competitive executive-level compensation
Collaborative work culture
Opportunity to shape global security strategy