Application Security Engineer

Manulife Global Solutions (MGS)

Philippines

Hybrid

PHP 1,200,000 - 2,400,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Manulife Global Solutions (MGS) is seeking an Application Security Engineer to join the GCS – Application Security Rapid Lab Team. You will collaborate with security and development teams to remediate secrets and strengthen secure software development across enterprise platforms.

The role requires deep hands-on security experience, practical knowledge of Azure Key Vault/HashiCorp Vault, and the ability to communicate technical risk and remediation strategies across global teams.

Qualifications

  • Bachelor’s degree in Computer Science, Software Engineering, or related discipline.
  • 5+ years of software engineering with secure development and remediation experience.
  • Proven backend development experience with secure patterns and APIs.
  • Hands-on Secure SDLC implementation and secure coding practices.
  • Experience triaging findings from SAST, DAST, SCA, and pentesting.
  • Knowledge of secrets management and enterprise vault platforms.

Responsibilities

  • Assess applications for hard-coded secrets and remediation risks.
  • Design secure migration approaches using Azure Key Vault or HashiCorp Vault.
  • Develop secure backend services, APIs, and reusable components.
  • Integrate security controls into CI/CD pipelines and automation.
  • Analyze findings from security assessments and prioritize remediations.
  • Participate in architecture reviews and communicate security trade-offs to stakeholders.

Skills

Secure development
Vulnerability remediation
Secrets management
Backend security
CI/CD security
Cloud security
Security testing
Automation
Stakeholder communication

Education

Bachelor’s degree in Computer Science or related field

Tools

Azure Key Vault
HashiCorp Vault
GitHub
GitHub Actions
GitGuardian
Snyk
CI/CD pipelines

Job description

We are looking for an Application Security Engineer (Secure Development and Secrets Management) to join the Global Cybersecurity Services (GCS) – Application Security Rapid Lab Team. In this role, you will partner with Application Security teams, developers, and business stakeholders to advance enterprise secrets remediation and secure software development initiatives. The candidate should have working knowledge of designing and implementing secure solutions that eliminate hard-coded secrets, strengthen application security controls, and integrate applications with approved enterprise platforms such as Azure Key Vault and HashiCorp Vault. The candidate may support these activities based on business and project needs. The ideal candidate combines strong software engineering fundamentals with hands‑on application security experience and can clearly communicate remediation strategies, architecture decisions, and technical contributions.

Position Responsibilities:
  • Application Security and Secrets Remediation: Assess applications for hard-coded secrets, credentials, certificates, API keys, and configuration risks; support the definition and implementation of secure migration approaches using Azure Key Vault, HashiCorp Vault, or equivalent approved platforms.

  • Secure Software Development: Design, develop, and maintain secure backend services, APIs, reusable components, libraries, and utilities using Java, Python, C#, or equivalent technologies, applying secure-by-design and Secure SDLC principles.

  • Automation and Integration: Contribute to the development of scalable automation and automated remediation capabilities, integrate security controls into CI/CD pipelines, and help reduce manual remediation effort across multiple applications.

  • Security Assessment and Remediation: Analyze and prioritize findings from SAST, DAST, SCA, secrets scanning, penetration testing, code reviews, and other assessments; support risk-based remediation with minimal business impact.

  • Architecture and Preventive Controls: Participate in solution and architecture reviews, recommend secure patterns, and address root causes to reduce recurring security risks.

  • Stakeholder Engagement: Participate in discovery, requirements gathering, solution design, and technical reviews. Communicate security risks, trade-offs, remediation plans, and implementation guidance to technical and non-technical stakeholders across global teams.

Required Qualifications:
  • Bachelor’s degree in Computer Science, Software Engineering, Computer Engineering, Information Technology, Cybersecurity, or a related technical discipline.

  • Minimum of five years of software engineering experience, including secure application development and vulnerability remediation using Java, Python, C#, or equivalent technologies.

  • Proven experience developing backend applications, APIs, reusable components, automation utilities, and security-focused tools or frameworks.

  • Hands‑on experience applying Secure SDLC principles and secure coding practices across design, development, testing, deployment, and maintenance.

  • Experience triaging and remediating findings from SAST, DAST, SCA, secrets scanning, penetration testing, code reviews, and vulnerability assessments.

  • Working knowledge of secrets management, credential lifecycle management, and application integration using Azure Key Vault, HashiCorp Vault, or equivalent enterprise platforms.

  • Knowledge of securely managing API keys, tokens, certificates, database credentials, and other application secrets, including remediation and rotation practices.

  • Strong understanding of application security, OWASP Top 10, vulnerability management, API security, backend architecture, object‑oriented programming, design patterns, and reusable component design.

  • Hands‑on experience with GitHub, GitHub Actions, GitGuardian, Snyk, CI/CD pipelines, modern development environments, and security testing or vulnerability management platforms.

  • Demonstrated ability to explain technical designs, architecture decisions, security trade‑offs, remediation approaches, and individual project contributions.

  • Ability to work independently, manage complex technical challenges, and collaborate effectively with developers, architects, executives, and business stakeholders.

  • Excellent verbal and written communication, problem‑solving, customer focus, and stakeholder management skills.

  • Amenable to work at UP Ayala Technohub, Quezon City under a hybrid setup (three days a week).

  • Amenable to work on a fixed late mid‑shift or night‑shift schedule based on business requirements.

Preferred Qualifications:
  • Experience supporting enterprise Application Security, Secrets Management, DevSecOps, or Platform Security programs.

  • Experience in financial services, insurance, or another regulated industry, including work with globally distributed and multicultural teams.

  • Knowledge of Microsoft Azure, cloud‑native security controls, workload identity, identity integration, certificate management, secrets rotation, and CI/CD security controls.

  • Relevant certifications such as ISC2 CSSLP, CompTIA Security+, GIAC GSEC, GIAC GWEB, GIAC GWAPT, HashiCorp Certified: Vault Associate, GitHub Advanced Security, GitHub Actions, or an equivalent industry credential.

  • Relevant training in secure coding, Secure SDLC, OWASP Top 10, threat modeling, application security architecture, vulnerability remediation, and defensive web application security.

  • Product or platform training in Azure Key Vault, HashiCorp Vault, GitHub Advanced Security, GitHub Actions, GitGuardian, Snyk, secrets detection and remediation, and CI/CD security.

  • Exposure to or hands‑on experience with AI‑assisted software development, security automation, or the responsible use of generative AI to support secure coding, vulnerability analysis, remediation, testing, and developer workflows.

  • Experience contributing to process improvement initiatives, including identifying automation opportunities, simplifying workflows, addressing root causes, defining measurable outcomes, and improving the efficiency and scalability of Application Security services.

When you join our team:
  • We’ll empower you to learn and grow the career you want.

  • We’ll recognize and support you in a flexible environment where well‑being and inclusion are more than just words.

  • As part of our global team, we’ll support you in shaping the future you want to see.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Manulife • Philippines

Hybrid
PHP 1,000,000 - 1,400,000
Application Security Engineer
Application Security Engineer

Recruitify_HR • Quezon City

Hybrid
Up to 80k joining bonus
Hybrid work model
Competitive salary
Application Security Engineer / Application Security Lead
Application Security Engineer / Application Security Lead

Recruitify_HR • Taguig

Hybrid
PHP 800,000 - 1,000,000
APPLICATION SECURITY LEAD
APPLICATION SECURITY LEAD

City Government of Muntinlupa - Government • Muntinlupa

On-site
PHP 1,000,000 - 1,500,000
Application Security Engineer: Secrets & Vaults
Application Security Engineer: Secrets & Vaults

Manulife • Philippines

Hybrid
PHP 1,000,000 - 1,400,000
Application Security Engineer: Secrets & Secure SDLC
Application Security Engineer: Secrets & Secure SDLC

Manulife Global Solutions (MGS) • Philippines

Hybrid
PHP 1,200,000 - 2,400,000
Product Security Engineer
Product Security Engineer

GoMining • España

On-site
USD 120,000 - 180,000
Professional growth support
Remote or hybrid format
Flexible hours
+2
Senior Application Security Engineer
Senior Application Security Engineer

Inriver • Davao City

On-site
PHP 2,500,000 - 3,500,000
Application Security Engineer
Application Security Engineer

Trinity Workforce Solutions, Inc. • Makati

On-site
PHP 800,000 - 1,200,000
Collaborate with talented teams
Work on real-world security challenges
Career growth in a security-first culture
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000