Manulife’s Global Cybersecurity Services - Application Security is building up a penetration testing Centre of Excellence (COE) to deliver penetration test-related capabilities for all segments in Manulife. As a Penetration Tester, you will be working closely with our business team and the second line of defense to assess the scope and level of effort based on identified areas of risk and execute assigned engagements in alignment with common penetration testing industry frameworks.
Have the skills and experience for the job? Learn more about it below!
Note: Designation will be finalized after completion of the recruitment processes.
Position Responsibilities:
- Evaluates the security posture of the organization, assessing potential threats and vulnerabilities in any of the following:
- Web Applications and/or Network Security
- Microservices
- Mobile Applications
- Develops and communicates the understanding of the potential impacts of a cyber attack to all relevant stakeholders.
- Evaluates different security solutions and provides advice on how to best protect the organization from cyber threats.
- Ensures alignment with corporate and regulatory requirements for the management of information security program.
- Performs security assessments to identify possible security vulnerabilities within the organization and develops security controls, policies, and procedures to address any issues that may exist.
- Conducts comprehensive network scans and manual network assessments, including penetration testing and vulnerability scans.
- Write reports including technical details, risk analysis, and providing remediation recommendations for identified issues.
Required Qualifications:
- At least 2 years of IT experience with a demonstrated passion for performing hands-on penetration tests on external and internal networks, operating systems, web applications, etc.
- Has technical knowledge of current vulnerabilities, exploits and tools (VAPT, DAST, SAST, and other similar tools).
- Bachelor’s degree holder in Computer Science, Information Technology, Cybersecurity, Information Systems, or any related discipline.
- Must be willing to work on mid-shift and night-shift schedule on a hybrid setup in Quezon City, Philippines.
Preferred Qualifications:
- Holds an Information Security certification or is at least currently undergoing security certification/training such as OSCP, OSCE, CEH, GWAPT, GPEN, or eWPT is preferred.
- Has technical knowledge of current vulnerabilities, exploits and tools.
- Understand the concepts of different VAPT capabilities and methods.
- Ability to adopt the security industry best practices and immerse in procedures.
- Exposure with various security assessment frameworks and procedures, and the ability to perform both manual and automated testing.
- Interest in researching evolving exploits, techniques, and tools in support of penetration testing efforts.
- Good verbal and written communication skills including the ability to write clear and concise assessment reports.
- Good stakeholder management and interpersonal skills.
- Ability to communicate with team, peers and employees.
- Good time management and organizational skills.
- Experience working in an international environment with people from multiple cultures is preferred.
- Beginner / Fundamental Knowledge in the following:
- Vulnerability Assessment
- Penetration Testing
- Security Risk Assessment
- Risk Management
- Security Testing
- Cyber Threat Intelligence
- Fresh graduates of relevant courses are encouraged to apply.
When you join our team:
- We’ll empower you to learn and grow the career you want.
- We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
- As part of our global team, we’ll support you in shaping the future you want to see.
Join our team as an Application Security Engineer, where you will independently review and validate penetration test reports, ensuring technical accuracy and risk-based remediation. Collaborate with cross-functional teams to maintain high-quality standards. Ideal for candidates with strong experience in application security and penetration testing.
Join our team as a Security Engineer to lead application security assessments and drive remediation efforts across Manulife's digital platforms. Take ownership of security programs, mentor peers, and contribute to the development of security standards. Ideal for candidates with strong hands-on experience in secure software development and leadership within financial services.
We are expanding our team: As an Application Security Engineer specializing in Threat Modeling, you will lead security engagements, identify design risks, and translate them into actionable security requirements. Ideal candidates bring significant experience in application security and threat modeling within technical or business environments.
We believe that embracing inclusion is the key to creating a stronger, more resilient organization. It's not just a value - it’s a strategic advantage that sets us apart.