Application Security Engineer - Penetration Testing Quality Assurance

manulife

Quezon City

Hybrid

PHP 1,200,000 - 2,000,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Manulife is seeking an experienced security tester to review penetration test reports, validate evidence, and calibrate severity for web applications and APIs. The role requires hands-on testing, strong knowledge of OWASP practices, and the ability to communicate risk to technical and business stakeholders.

The ideal candidate has 3+ years in security QA, experience with Burp Suite and Snyk, and will operate in a hybrid arrangement with onsite days in Quezon City, Philippines.

Qualifications

  • 3+ years in penetration testing or security QA.
  • Review reports, validate evidence and assess impact.
  • Knowledge of OWASP testing practices and CVSS.
  • Hybrid work requirements with onsite days in Quezon City.

Responsibilities

  • Perform final quality reviews of penetration test reports for accuracy and evidence.
  • Validate assets, exploitation paths, business impact, and false positives.
  • Calibrate severity using CVSS, asset criticality, and controls.
  • Ensure scope, methodology, and conclusions are clear and complete.
  • Provide remediation guidance and evidence for closure.
  • Track findings, remediation dates, and retesting outcomes.
  • Triage new vulnerabilities for relevance and escalation.
  • Support Burp Suite and Snyk operations and coordination.
  • Maintain quality templates and report standards; suggest improvements.
  • Produce status updates and raise material risks to stakeholders.

Skills

Penetration testing
Web security
Burp Suite
SAST/DAST
Threat assessment

Education

Bachelor's degree or equivalent practical experience
Related field or experience

Tools

Burp Suite Professional
Snyk

Job description

Key Responsibilities:
  • Perform final quality reviews of penetration test reports before release, ensuring findings are technically accurate, reproducible, supported by sufficient evidence, within the approved scope, and written for both technical and business audiences.
  • Validate affected assets, exploitation paths, business impact, duplicate findings, and false positives; challenge conclusions when the evidence does not support the stated risk.
  • Review and calibrate severity ratings using CVSS, exploitability, asset criticality, business impact, environmental context, and existing compensating controls.
  • Confirm that test scope, methodology, coverage, assumptions, limitations, and conclusions are complete and clearly documented; work with testers to address gaps before reports are issued.
  • Provide practical, risk-based remediation guidance and help application teams understand the issue, expected corrective action, and evidence required for closure.
  • Track open findings and agreed remediation dates, coordinate retesting, validate corrective actions, and document closure decisions or residual risks.
  • Triage newly disclosed or emerging vulnerabilities to determine relevance, potential exposure, required validation, and appropriate escalation.
  • Support day-to-day Burp Suite and Snyk operations, including access requests, scan configuration, issue triage, troubleshooting, scheduling, reporting, and coordination with platform owners.
  • Maintain quality standards, review checklists, reporting templates, and operating procedures; identify recurring defects and recommend improvements to testing, reporting, and aftercare processes.
  • Produce accurate status updates and quality metrics, and elevate material risks, overdue actions, or delivery concerns to the appropriate stakeholders.
Required Qualifications:
  • Bachelor's degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.
  • At least three years of relevant experience in penetration testing, application security, vulnerability assessment, vulnerability management, or security quality assurance.
  • Hands-on experience reviewing penetration test reports, validating technical evidence, assessing exploitability and business impact, assigning or challenging severity ratings, and confirming remediation through retesting.
  • Strong knowledge of web application and API security, common attack techniques, authentication and authorization weaknesses, OWASP testing practices, CVSS, CWE, and vulnerability classification.
  • Practical experience with Burp Suite Professional or comparable web and API security testing tools.
  • Working knowledge of SAST, DAST, SCA, open-source vulnerability management, DevSecOps pipelines, and the end-to-end vulnerability management lifecycle.
  • Strong analytical judgment and attention to detail, with the ability to distinguish material risk from low-value noise and make defensible, evidence-based decisions.
  • Clear written and verbal communication skills, including the ability to explain technical risk and remediation expectations to technical and non-technical stakeholders.
  • Ability to manage competing priorities, follow through on commitments, and work effectively with globally distributed teams.
  • Amenable to a hybrid work arrangement at UP Ayala Technohub, Quezon City, with three onsite days per week.
  • Amenable to a fixed late mid-shift or night-shift schedule based on business requirements.
Preferred Qualifications:
  • Experience performing or reviewing penetration tests for web applications, APIs, mobile applications, cloud environments, or networks, including assessments delivered by third-party providers.
  • Experience in enterprise application security or vulnerability management within financial services, insurance, or another regulated industry.
  • Familiarity with OWASP WSTG, PTES, NIST SP 800-115, or comparable penetration testing and reporting standards.
  • Experience using vulnerability management or issue-tracking platforms to manage evidence, ownership, remediation dates, exceptions, retesting, and closure.
  • Experience with Snyk administration or enterprise application security tooling, including onboarding, scan configuration, troubleshooting, reporting, and stakeholder support.
  • Ability to automate data processing, quality checks, workflow updates, dashboards, or repo
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer - Penetration Testing Quality Assurance
Application Security Engineer - Penetration Testing Quality Assurance

Manulife/John Hancock • Manila

On-site
PHP 900,000 - 1,300,000
Hybrid work arrangement
Security Penetration Tester
Security Penetration Tester

Gratitude Philippines • Manila

Hybrid
PHP 1,200,000 - 2,400,000
Competitive salary package
Performance bonus
Day 1 HMO and Life Insurance
+2
Application Security QA Engineer — Penetration Testing
Application Security QA Engineer — Penetration Testing

manulife • Quezon City

Hybrid
PHP 1,200,000 - 2,000,000
Penetration Tester
Penetration Tester

Manulife Insurance Malaysia • Quezon City

On-site
PHP 669,600 - 892,800
Application Security Engineer - Penetration Testing Quality Assurance
Application Security Engineer - Penetration Testing Quality Assurance

Manulife • Manila

Hybrid
PHP 900,000 - 1,500,000
IT Security QA
IT Security QA

Questronix Corporation • Pasig

On-site
PHP 800,000 - 1,200,000
Penetration Tester
Penetration Tester

Manulife group • Quezon City

Hybrid
PHP 900,000 - 1,500,000
OFFENSIVE SECURITY OFFICER
OFFENSIVE SECURITY OFFICER

Metrobank • Hinoba-an

On-site
PHP 600,000 - 1,000,000
Application Security QA Engineer for Risk & Remediation
Application Security QA Engineer for Risk & Remediation

Manulife group • Quezon City

Hybrid
PHP 900,000 - 1,500,000
Offensive Security Engineer
Offensive Security Engineer

Metrobank • Taguig

On-site
PHP 1,200,000 - 2,400,000