Application Security Engineer (OWASP, SAST, DAST, SCA)

Comrise

Taguig

On-site

PHP 1,200,000 - 2,400,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Comrise in Manila seeks an Application Security Engineer to embed security in the SDLC and drive DevSecOps, automation, code scanning, and cloud security.

You will design and maintain secure CI/CD pipelines with SAST/DAST/SCA, and work with tools like GitHub Advanced Security, Checkmarx, Snyk, Trivy, and OWASP ZAP to improve security posture.

Collaborate with security, architecture, and cloud teams to shift left through scalable, self-service controls and robust secure coding practices.

Qualifications

  • Minimum 8-12 years in technology with 5+ years in Application Security.
  • Hands-on DevSecOps with SAST, DAST, SCA, and SBOM.
  • Experience with Azure cloud security and IaC.
  • Strong knowledge of OWASP Top 10, NIST, secure coding.

Responsibilities

  • Lead secure SDLC practices and embed security in CI/CD pipelines.
  • Perform security testing including SAST/DAST and API security testing.
  • Triage vulnerabilities and provide remediation guidance to engineers.
  • Collaborate with engineering to implement guardrails and standards.
  • Conduct threat modeling and security reviews.
  • Maintain secure coding standards and IaC security reviews.

Skills

DevSecOps pipelines
Security engineering
Threat modeling
Secure coding practices
Cloud security

Tools

GitHub Advanced Security
Checkmarx
Snyk
Trivy
OWASP ZAP
Terraform
Bicep

Job description

The Application Security Engineer is a hands-on technical role responsible for embedding security engineering practices throughout the Software Development Life Cycle (SDLC). The role focuses on DevSecOps, security automation, code scanning, security testing, and cloud security, translating security assessments and architectural recommendations into practical engineering controls. The role partners with security, architecture, and engineering teams to shift security left through repeatable, scalable, and self-service practices aligned with DORA, NIST, OWASP, and InfoSec standards.

Key Responsibilities
  • Design, build, and maintain secure CI/CD pipelines integrating SAST, DAST, SCA, secrets detection, container scanning, and SBOM generation.
  • Implement and optimize security tools such as GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP, or equivalent.
  • Develop security standards, guardrails, and reusable pipeline templates for engineering teams.
Security Testing & Vulnerability Management
  • Lead security testing for applications, including SAST, DAST, API security testing, and penetration testing support.
  • Triage, prioritize, and track vulnerabilities while providing clear remediation guidance to engineering teams.
  • Monitor recurring vulnerabilities and security risks and recommend systemic improvements.
  • Partner with developers on secure code reviews, remediation, and security best practices.
  • Maintain secure coding standards covering OWASP, authentication, authorization, secrets management, and cryptography.
  • Conduct security awareness sessions, code review workshops, and threat modeling walkthroughs.
Software Supply Chain Security
  • Implement software integrity, dependency, artifact, and license controls within CI/CD pipelines.
  • Manage SCA and SBOM processes and monitor emerging CVEs and vulnerabilities affecting technology stacks.
  • Coordinate remediation and response with engineering and platform teams.
AI & Digital Security Automation
  • Apply GenAI, GitHub Copilot, and agentic/AI frameworks to security tasks such as vulnerability triage, remediation recommendations, and security automation.
  • Identify opportunities to automate manual security processes and improve engineering efficiency.
  • Implement and validate Azure security controls, including IAM, Key Vault, network security, containers/Kubernetes, and encryption.
  • Conduct Infrastructure-as-Code (IaC) security reviews using Terraform, Bicep, or equivalent.
  • Support Cloud Security Posture Management (CSPM) and security alert triage.
  • Work with security, architecture, and engineering teams to translate risk assessments and security recommendations into practical controls.
  • Partner with engineering leaders and security champions to embed security practices into development workflows.
  • Monitor security tooling coverage and effectiveness and continuously improve security processes, controls, and developer guidance.
  • Support security governance, audit, and compliance activities with appropriate documentation and evidence.
Requirements
Minimum Qualifications
  • 8-12 years of overall technology experience, with 5+ years in Application Security, DevSecOps, or Security Engineering.
  • Hands-on experience designing and operating DevSecOps pipelines with SAST, DAST, SCA, secrets detection, container scanning, and SBOM.
  • Experience with enterprise security tools such as GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP, or equivalent.
  • Strong knowledge of Azure cloud security, including IAM, Key Vault, network security, containers/Kubernetes, and IaC.
  • Strong understanding of OWASP Top 10, NIST, secure coding, and vulnerability management.
Preferred Qualifications
  • Experience in financial services, insurance, or other highly regulated industries.
  • Security certifications such as CSSLP, CEH, OSCP, GWEB, and/or Azure security certifications such as AZ-500 or SC-100.
  • Experience applying AI, GenAI, automation, GitHub Copilot, or agentic technologies to security engineering.
  • Experience supporting distributed engineering teams and security champions at scale.
  • Familiarity with threat modeling and security architecture review.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer (OWASP, SAST, DAST, SCA)
Application Security Engineer (OWASP, SAST, DAST, SCA)

Hammerjack Pty Ltd • Philippines

On-site
PHP 1,500,000 - 2,300,000
Application Security Engineer
Application Security Engineer

Ascendion • Taguig

On-site
PHP 1,200,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Trinity Workforce Solutions, Inc. • Makati

On-site
PHP 800,000 - 1,200,000
Collaborate with talented teams
Work on real-world security challenges
Career growth in a security-first culture
Application Security Engineer
Application Security Engineer

Career Connect • Philippines

On-site
PHP 600,000 - 1,200,000
APPLICATION SECURITY LEAD
APPLICATION SECURITY LEAD

City Government of Muntinlupa - Government • Muntinlupa

On-site
PHP 1,000,000 - 1,500,000
Senior Application Security Engineer
Senior Application Security Engineer

inRiver inc • Manila

On-site
PHP 900,000 - 1,800,000
Application Security Engineer, Application Security Lead- 80K SOB
Application Security Engineer, Application Security Lead- 80K SOB

Bravissimo Resourcing Inc. • Quezon City

On-site
PHP 800,000 - 1,200,000
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)

Recruitify_HR • Quezon City

On-site
PHP 558,000 - 781,200
DevSecOps Engineer
DevSecOps Engineer

Helius Technologies Pte Ltd • Santo Niño 1st

On-site
PHP 800,000 - 1,200,000