Application Security Manager

PwC

Makati

On-site

PHP 1,200,000 - 1,600,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PwC is looking for a Manager in Security Architecture to join their Cybersecurity and Privacy services. In this role, you'll manage cyber-attack simulations and deliver comprehensive security assessments, working closely with clients to enhance their security posture.

The ideal candidate will have significant experience in conducting security reviews and managing teams. A Bachelor's degree in Computer Science or related field along with relevant certifications is required. Join us to help design and implement effective cybersecurity programs.

Qualifications

  • Minimum of 5-7 years in managing security tests.
  • Certifications in Offensive Security and others required.
  • Practical experience in auditing various security technologies.

Responsibilities

  • Manage cyber-attack simulations and VA/PT.
  • Deliver source-code reviews and configuration assessments.
  • Provide technical guidance for application security offerings.
  • Conduct risk assessments for applications.

Skills

Project management
Technical guidance in application security
VAPT skills
Knowledge of security tools
Understanding of software development lifecycle
Penetration testing

Education

Bachelor's in Computer Science/IT/Electronics Engineering

Tools

Nmap
BurpSuite
Kali
Metasploit
Nessus
Fortify/Checkmarx

Job description

Job Description & Summary

A career in our Security Architecture practice, within Cybersecurity and Privacy services, will provide you with the opportunity to help our clients implement an effective cybersecurity programme that protects against threats, propels transformation, and drives growth. As companies pivot toward a digital business model, exponentially more data is generated and shared among organisations, partners and customers. You’ll play an integral role in helping our clients ensure they are protected by developing transformation strategies focused on security, efficiently integrating and managing new or existing technology systems to deliver continuous operational improvements and increase their cybersecurity investment, and detect, respond, and remediate threats.

In joining, you’ll be a part of a team that helps organisations design and create sustainable security solutions to provide foundational capabilities and operational discipline through a focus on enterprise requirements and prioritisation, Information Technology security architecture, and the software development lifecycle.

Line of Service

Advisory

Industry/Sector

Not Applicable

Specialism

Cybersecurity & Privacy

Management Level

Manager

Job Responsibilities
  • Manage, direct and deliver cyber-attack simulations as part of the RED team activity
  • Manage, direct and deliver Vulnerability Assessment (VA) and Penetration Testing (PT) and configuration review for network, web, mobile and thick-client applications, APIs, POS etc.
  • Manage, direct and deliver source-code review using automated and manual approaches, review results to eliminate false positives
  • Manage, direct and deliver configuration reviews for OS, DB, Firewall, routers, switches and other security devices/components
  • Perform and deliver gap analysis and assessments based on standards, guidelines, notices, circulars (e.g., ISO27K1, MAS TRM, HKMA etc.)
  • Prepare and review detailed reports and ensure timely delivery of status updates and final reports to clients
  • Provide technical guidance with respect to the development and execution of key application security service offerings, including conducting assessments of applications (web, cloud, mobile, API) using a range of manual and automated source code review techniques; performing security architecture reviews and risk assessments for applications in design and production phases; identifying potential threats and attacks to application systems through threat modeling; identifying security recommendations and aligning them to appropriate risk ranking systems; integrating application security tools and process in pipeline; agile penetration testing; evaluating, developing, enhancing and/or running application security programs for our clients; conducting these with a specific focus on DevSecOps.
  • Manage client stakeholders, provide project status updates, discuss findings and explain recommendations
  • Work with clients to analyze, evaluate, and enhance the effectiveness of their application/product security posture at procedural and technological levels from design to deployment
  • Keep abreast of the latest IT Security news, exploits, hacks
Essential Skills
  • Manage projects, team members and client stakeholders for successful delivery
  • Manage project economics
  • Thorough and practical knowledge of OWASP, network protocols, data on the wire, and covert channels
  • Hands-on experience with popular security tools – Nmap, Nessus, Kali, Metasploit, BurpSuite, Netsparker, OWASP CSRF Tester, Fortify/Checkmarx, SonarQube, Synopsys, SQLite browser, Drozer
  • Working knowledge of manual testing of web applications
  • Understands Software Development Life Cycle and SOAP, REST and GraphQL APIs
  • Skills in performing VAPT for Web applications, Mobile applications, APIs, Network infrastructure, Thick client applications
  • Good knowledge of modifying and compiling exploit code
  • Good understanding and knowledge of code languages
  • Has practical experience in auditing various OS, DB, Network and Security technologies
  • Strong understanding Unix/Linux/Mac/Windows, operating systems, including bash and Powershell
Experience Requirements
  • Set up and operate red team infrastructure
  • Perform targeted, covert penetration tests with vulnerability identification, exploitation, and post-exploitation activities
  • Email, phone, or physical social-engineering assessments
  • Developing, extending, or modifying exploits, shellcode or exploit tools
  • Reverse engineering malware, data obfuscators, or ciphers
  • Strong credentials in wireless, web application, and network security testing
  • Familiar with MITRE ATT&CK framework and D3FEND matrix
Educational Requirements & Experience
  • Bachelor's in Computer Science/IT/Electronics Engineering or equivalent University degree.
  • Minimum of 5-7 years of experience in managing and delivering security tests and compliance review projects.
  • Certifications: CREST CRT, CREST CPSA, Offensive Security Certified Professional (OSCP), GIAC Certified Web Application Defender (GWEB).
  • Other Certifications: OSWP, BSCP, Certified Red Team Professional.
Education

Bachelor of Science - Information Technology

Certifications
  • CREST CRT, CREST CPSA, Offensive Security Certified Professional (OSCP), GIAC Certified Web Application Defender (GWEB)
  • Other Certifications: OSWP, BSCP, Certified Red Team Professional
Travel Requirements

Not Specified

Work Visa Sponsorship

No

Government Clearance Required

Yes

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Red Team Operator (Offensive Security Analyst)
Senior Red Team Operator (Offensive Security Analyst)

Sun Life Global Solutions – Philippines • Taguig

Hybrid
PHP 1,200,000 - 2,400,000
Security Engineer
Security Engineer

Azeus Systems Limited • Pasig

Hybrid
Senior Red Team Operator
Senior Red Team Operator

Sun Life • Taguig

On-site
PHP 1,800,000 - 3,000,000
Security Engineer
Security Engineer

Azeus Group • Pasig

On-site
PHP 900,000 - 1,300,000
Application Security Engineer
Application Security Engineer

Interact Software • Metro Manila

On-site
PHP 700,000 - 1,200,000
Security Consulting Engineer (Offensive)
Security Consulting Engineer (Offensive)

Novare Philippines Inc. • Taguig

Hybrid
PHP 1,000,000 - 1,800,000
Security Engineer
Security Engineer

Azeus Systems Limited • Cebu City

On-site
PHP 1,200,000 - 1,800,000
Security Engineer - Red Team
Security Engineer - Red Team

Coberon Chronos • España

On-site
EUR 60,000 - 90,000
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Thrive • Tarlac City

On-site
PHP 900,000 - 1,500,000
Application Security Engineer
Application Security Engineer

Sideways 6 • Philippines

On-site
PHP 1,200,000 - 1,900,000