Application Security Research Engineer

CommIT

España

On-site

PHP 4,884,004 - 7,326,007

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CommIT in Philippines is seeking an experienced Application Security Research Engineer to lead a team focused on advanced security research and penetration testing. The role emphasizes offensive security, automation, and innovation, shaping product security and collaborating with engineering teams. Candidates should have over 7 years of experience in research and penetration testing, strong coding skills, and familiarity with modern architectures and security tools. This is a hands-on role with opportunities for building security testing tools.

Qualifications

  • 2+ years of experience in leading application security research teams.
  • 7+ years experience in research and penetration testing.
  • Strong coding skills with deep technical understanding of various technologies.
  • Experience with developing custom security tools.
  • Knowledge of SSDLC tools and CI/CD pipelines.

Responsibilities

  • Build and lead a team of security researchers and penetration testers.
  • Plan and execute advanced penetration testing campaigns.
  • Analyze vulnerabilities and perform root cause analysis.
  • Collaborate with engineering teams to fix vulnerabilities.
  • Contribute to security research publications and industry sharing.

Skills

Application security research team leadership
Penetration testing
Strong coding skills
Knowledge of AI and LLM penetration testing
Experience with Burp Suite and Metasploit
Familiarity with microservices and Kubernetes
Ability to lead security testing engagements

Tools

Burp Suite
Metasploit
Security testing tools

Job description

Description

Company is seeking an Application Security Research Engineer. In this role, you will lead a team of researchers and ethical hackers focused on offensive security testing, automated exploit discovery, and advanced application security research. Your work will directly influence the security posture of company products and help scale secure-by-design principles. This is a hands‑on technical role with a strong emphasis on offensive security, code exploitation, automation, and innovation.

What You Will Do
  • Build and lead a team of security researchers and penetration testers.
  • Help to reshape company Product Security
  • Plan and execute advanced penetration testing campaigns.
  • Develop tools and frameworks for scalable security testing and fuzzing.
  • Lead Security innovation by building and managing penetration testing tools AI Agents
  • Analyze vulnerabilities, perform root cause analysis, and develop proofs of concept.
  • Identify systemic product weaknesses and help define long‑term mitigations.
  • Collaborate with engineering teams to reproduce, triage, and fix vulnerabilities.
  • Contribute to security research publications, CVE submissions, and industry knowledge sharing.
  • Continuously evolve internal testing capabilities using modern tooling and AI‑assisted approaches.
Requirements
  • Proven 2+ years of experience in leading application security research Teams (SAAS or software company).
  • 7+ year experience in Research and penetration testing.
  • Strong coding skills and deep technical understanding of web, API, cloud‑native, and backend technologies.
  • AI and LLM Penetration testing knowledge and Experience
  • Experience with penetration testing tools (Burp Suite, Metasploit, etc.) and Custom Security Tools development.
  • Familiarity with modern architectures (e.g., Cloud, microservices, containers, Kubernetes).
  • Familiarity with secure software architecture and typical attack vectors.
  • Demonstrated ability to lead security testing engagements and report technical findings effectively.
  • Experience building or integrating automated PT or fuzzing pipelines is a strong advantage.
  • Knowledge and hands‑on experience with SSDLC tools and CI/CD pipelines,
  • Publications or open‑source contributions in the security domain are a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Trinity Workforce Solutions, Inc. • Makati

On-site
PHP 800,000 - 1,200,000
Collaborate with talented teams
Work on real-world security challenges
Career growth in a security-first culture
Application Security Engineer
Application Security Engineer

Interact Software • Metro Manila

On-site
PHP 700,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Sideways 6 • Philippines

On-site
PHP 1,200,000 - 1,900,000
Application Security Engineer (relocation to Barcelona)
Application Security Engineer (relocation to Barcelona)

CommIT • España

On-site
Application Security Engineer
Application Security Engineer

Career Connect • Makati

On-site
PHP 700,000 - 1,100,000
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Thrive • Tarlac City

On-site
PHP 900,000 - 1,500,000
Security Engineer - Red Team
Security Engineer - Red Team

Coberon Chronos • España

On-site
EUR 60,000 - 90,000
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000
Security Engineer
Security Engineer

Azeus Systems Limited • Pasig

Hybrid
Application Security Manager
Application Security Manager

PwC • Makati

On-site
PHP 1,200,000 - 1,600,000