Application Security Engineer

Comrise

Taguig

Hybrid

PHP 1,800,000 - 3,200,000

Full time

13 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Comprise security engineering role focusing on DevSecOps across CI/CD pipelines. Lead SAST/DAST, SBOM, and container scanning, with hands‑on improvements to secure the software supply chain.

You'll guide teams on secure coding, threat modelling, and vulnerability remediation, while steering AI-assisted security tooling initiatives and cloud security controls in Azure.

Qualifications

  • 8-12 years in technology with 5+ years in application security engineering or DevSecOps.
  • Hands-on experience designing and operating DevSecOps pipelines with CI/CD gates.
  • Experience with enterprise security tooling in large engineering environments.
  • Azure cloud security engineering knowledge and IaC security reviews.

Responsibilities

  • Own security testing for in-scope applications: plan SAST/DAST, support penetration testing and API security testing.
  • Triage findings from automated tooling and provide remediation guidance for engineers.
  • Review PRs for security weaknesses and mentor engineers on secure coding.
  • Build and maintain secure coding standards library aligned with OWASP and best practices.
  • Lead secure coding enablement sessions and threat modelling walkthroughs.
  • Implement build-integrity controls and SBOM generation across pipelines.

Skills

DevSecOps
CI/CD pipelines
SAST/DAST
SBOM

Tools

GitHub Advanced Security
Checkmarx
Snyk
Trivy
OWASP ZAP
IriusRisk

Job description

  • Design, build and maintain secure CI/CD pipelines integrating SAST, DAST, SCA, secrets detection, container scanning and SBOM generation as automated, non-blocking gates that shift security feedback to the point of code commit.
  • Implement and tune security tooling (GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP, IriusRisk or equivalent) in collaboration with IC S and the COE, balancing coverage against pipeline velocity.
  • Define pipeline security standards, guardrails and paved-road templates that delivery teams can adopt without bespoke configuration, and maintain them as the threat landscape and tooling evolve.
Security Testing & Vulnerability Management
  • Own the security testing practice for in-scope applications: plan and execute SAST, DAST, penetration testing support and API security testing, and validate remediation of findings through to closure.
  • Triage and prioritise vulnerability findings from automated tooling and manual review, producing clear, risk-rated remediation guidance that engineering teams can act on without specialist interpretation.
  • Track finding closure rates across the top platforms, reporting on open risk and recurring weakness themes to the CoE Lead, and escalating blockers where remediation is stalling.
  • Act as the primary hands‑on security engineering resource for delivery teams: review pull requests for security weaknesses, pair with engineers on remediation, and provide just‑in‑time secure coding guidance.
  • Build and maintain a secure coding standards library, covering OWASP, injection, authentication, authorisation, secrets management and cryptographic hygiene, mapped to the technology stacks in use across HWC.
  • Run developer‑facing security enablement sessions — secure code reviews, threat modelling walkthroughs, hands‑on labs — to build security awareness at the point where vulnerabilities are introduced.
Build Integrity & Supply Chain Security
  • Implement and operate build‑integrity controls: artefact signing, provenance verification, dependency allow‑listing and licence compliance checks integrated into CI/CD pipelines.
  • Own software composition analysis (SCA) and SBOM generation across in‑scope platforms, ensuring dependency and licence risk feeds directly into the technical risk profiling practice.
  • Monitor for new CVEs and zero‑day disclosures affecting in‑scope technology stacks, assess impact, and coordinate rapid response with platform owners and IC S.
AI‑Assisted Security Engineering
  • Apply AI and automation (GenAI, GitHub Copilot, agent frameworks) to security engineering tasks — automated triage, finding summarisation, remediation suggestion, pipeline policy generation — with human‑in‑the‑loop validation on outputs.
  • Evaluate and pilot emerging AI‑assisted security tooling in coordination with IC S and the CoE Lead, identifying where automation creates genuine capacity rather than adding cost or noise.
Cloud Security Engineering
  • Implement and validate Azure cloud security controls — identity and access management, network segmentation, secrets management (Key Vault), container and Kubernetes security, storage and data encryption — aligned to InfoSec and IC S standards.
  • Conduct infrastructure‑as‑code (IaC) security reviews (Terraform, Bicep or equivalent), identifying misconfiguration risks before they reach production.
Qualification:
  • 8-12 years in technology, with 5+ years in application security engineering, DevSecOps or a security‑engineering role with hands‑on pipeline and tooling ownership.
  • Demonstrable experience designing and operating DevSecOps pipelines: SAST, DAST, SCA, secrets detection, container scanning and SBOM generation integrated into CI/CD.
  • Hands‑on experience with security tooling (GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP or equivalent) in enterprise engineering environments.
  • Azure cloud security engineering knowledge: IAM, Key Vault, network controls, container/Kubernetes security, IaC scanning.
  • Working knowledge of OWASP Top 10, NIST, secure coding principles and vulnerability management, with ability to translate findings into engineer‑ready remediation guidance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

inRiver inc • Manila

On-site
PHP 900,000 - 1,800,000
DevSecOps Engineer
DevSecOps Engineer

Helius Technologies Pte Ltd • Santo Niño 1st

On-site
PHP 800,000 - 1,200,000
APPLICATION SECURITY LEAD
APPLICATION SECURITY LEAD

City Government of Muntinlupa - Government • Muntinlupa

On-site
PHP 1,000,000 - 1,500,000
DevSecOps Manager
DevSecOps Manager

Socium - Teams Done Differently • Pasay

On-site
PHP 1,200,000 - 2,400,000
Application Security Engineer
Application Security Engineer

Recruitify_HR • Quezon City

Hybrid
Up to 80k joining bonus
Hybrid work model
Competitive salary
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000
Sr. Devsecops Security Engineer
Sr. Devsecops Security Engineer

Atos SE • Hinoba-an

On-site
PHP 1,000,000 - 2,000,000
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)

Recruitify_HR • Quezon City

Hybrid
Application Security Engineer
Application Security Engineer

Manulife Global Solutions (MGS) • Philippines

Hybrid
PHP 1,200,000 - 2,400,000
Remote AppSec Engineer — AI-Driven SaaS Security
Remote AppSec Engineer — AI-Driven SaaS Security

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000