Offensive Security

Metrobank

Philippines

On-site

PHP 900,000 - 1,300,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Metrobank seeks an Offensive Security Engineer to lead penetration testing, red team activities, and security assessments across networks, web and mobile apps, and critical systems. You will collaborate with IT and development teams to identify vulnerabilities, validate remediation, and strengthen cybersecurity controls.

The role requires hands-on testing experience, knowledge of OWASP Top 10, and relevant certifications.

Qualifications

  • Bachelor's degree in CS/InfoSec/Cybersecurity or related field.
  • Knowledge of OWASP Top 10 and security testing best practices.
  • Hands-on experience in penetration testing and ethical hacking.
  • Certifications such as OSCP/GPEN/GWAP/CEH are advantageous.
  • Ability to plan, execute, and document security assessments.

Responsibilities

  • Plan, develop, and execute penetration testing engagements and red team exercises across networks and applications.
  • Conduct threat analysis and simulate real-world attack scenarios.
  • Identify vulnerabilities and attack paths using manual and automated methods.
  • Assess effectiveness of security controls such as firewalls and IDS/IPS.
  • Develop testing methodologies, abuse cases, and custom scripts to enhance testing.
  • Document findings and communicate remediation recommendations to stakeholders.
  • Partner with IT and development teams to validate fixes and drive remediation.
  • Review security configurations and procedures to strengthen security posture.
  • Support cybersecurity investigations and risk assessments as needed.
  • Stay current with emerging threats and tools; contribute to security governance.

Skills

Penetration testing
Ethical hacking
Threat analysis
Attack techniques
Security testing
Documentation
Communication skills
Analytical mindset
Team collaboration
Remediation guidance

Education

Bachelor's degree in computer science, Information Security, Cybersecurity, or related field

Tools

OSCP
GPEN
GWAP
CEH

Job description

Job Description:

Here at Metrobank, we don't simply hire employees - hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development. With Metrobank, a meaningful life is within your reach!

Offensive Security Engineer

Lead and perform penetration testing, ethical hacking, and red team exercises across network infrastructure, web and mobile applications, and other critical systems to identify security vulnerabilities and potential attack paths. Collaborate with IT and development teams to recommend and validate remediation measures, strengthen security controls, and enhance the bank's overall cybersecurity posture through proactive security assessments and continuous improvement initiatives.

Key Responsibilities
  • Plan, develop, and execute penetration testing engagements, red team exercises, and security assessments across networks, systems, web applications, mobile applications, and wireless environments.
  • Conduct threat analysis and simulate real-world attack scenarios, including social engineering and physical security assessments.
  • Identify vulnerabilities, attack paths, and security weaknesses using both manual and automated testing techniques.
  • Assess the effectiveness of security controls such as firewalls, intrusion detection/prevention systems, and other defensive technologies.
  • Develop testing methodologies, abuse cases, and custom scripts or tools to enhance security testing capabilities.
  • Document findings, prepare comprehensive technical and executive reports, and communicate remediation recommendations to stakeholders.
  • Partner with IT and development teams to validate security fixes and drive timely remediation of identified vulnerabilities.
  • Review security configurations, policies, and procedures, providing recommendations to strengthen the organization's security posture.
  • Support cybersecurity investigations and security-related risk assessments as required.
  • Stay current with emerging cyber threats, attack techniques, vulnerability trends, and penetration testing tools.
  • Contribute to the continuous improvement of the bank's information security strategies, programs, and governance initiatives while ensuring minimal disruption to business operations.
Qualifications
  • Bachelor's degree in computer science, Information Security, Cybersecurity, or a related technical field.
  • Strong understanding of security vulnerabilities, common attack techniques, and an attacker mindset to identify and assess potential threats.
  • Solid knowledge of OWASP Top 10 Application Security risks and best practices.
  • Relevant cybersecurity certifications such as OSCP, GPEN, GWAP, CEH, or equivalent are an advantage.
  • Hands-on experience in penetration testing and ethical hacking.
  • Strong technical background in networking, digital forensics, reverse engineering, web applications, databases, and wireless technologies.
  • Proficiency in scripting and programming for security testing and automation.
  • Good understanding of the business and financial impact of cybersecurity incidents and breaches.
  • Highly analytical with strong problem-solving and critical-thinking abilities.
  • Results-driven with a focus on identifying risks and driving effective remediation efforts.
  • Strong collaboration and teamwork skills, with the ability to contribute to and lead security initiatives.
  • Excellent written and verbal communication skills, with the ability to explain complex technical concepts to both technical and non-technical audiences.
  • Effective time management skills and the ability to perform in a fast-paced, dynamic environment.
  • Self-motivated, proactive, and highly organized with the ability to work independently.
Requirements:
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

OFFENSIVE SECURITY OFFICER
OFFENSIVE SECURITY OFFICER

Metrobank • Philippines

On-site
PHP 600,000 - 1,000,000
Network Security Engineer
Network Security Engineer

Metrobank • Metro Manila

On-site
PHP 900,000 - 1,300,000
NETWORK SECURITY ENGINEER
NETWORK SECURITY ENGINEER

Metrobank • Taguig

On-site
Offensive Security Engineer: Penetration & Red Team
Offensive Security Engineer: Penetration & Red Team

Metrobank • Philippines

On-site
PHP 900,000 - 1,300,000
HEAD SECURITY ARCHITECTURE AND INNOVATIONS DEPARTMENT
HEAD SECURITY ARCHITECTURE AND INNOVATIONS DEPARTMENT

Metrobank • Philippines

On-site
PHP 900,000 - 1,300,000
HEAD, SECURITY ARCHITECTURE AND INNOVATIONS DEPARTMENT
HEAD, SECURITY ARCHITECTURE AND INNOVATIONS DEPARTMENT

Metrobank • Taguig

On-site
Vulnerability Assessment & Management Analyst (Officer)
Vulnerability Assessment & Management Analyst (Officer)

EastWest Bank • Makati

Hybrid
PHP 1,000,000 - 1,500,000
Vulnerability Assessment & Management Analyst
Vulnerability Assessment & Management Analyst

EastWest Bank • Makati

Hybrid
PHP 1,200,000 - 2,000,000
Senior Red Team Operator
Senior Red Team Operator

Sun Life Financial • Taguig

On-site
PHP 1,200,000 - 2,400,000
SECURITY ASSURANCE AND ASSESSMENT OFFICER
SECURITY ASSURANCE AND ASSESSMENT OFFICER

Metrobank • Taguig

On-site
PHP 600,000 - 800,000
Opportunities for professional development
Community contribution initiatives