Security Consulting Engineer (Offensive)

Novare Philippines Inc.

Taguig

On-site

PHP 1,000,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Novare Philippines Inc. is seeking an experienced Offensive Security Consultant to lead VAPT engagements across networks, web, and mobile apps. You will design phishing simulations, analyze root causes, and craft strategic reports that reveal business risks beyond the bugs found.

You will mentor junior analysts, optimize reporting with AI tools, and strive for high billable utilization while delivering high-quality security assessments for clients.

Qualifications

  • 3-5 years of hands-on information security consulting experience focusing on VAPT or Red Teaming.
  • Proven experience writing technical reports for external clients.
  • Must possess or be actively pursuing OSCP; CEH, GPEN, GWAPT also valued.

Responsibilities

  • Perform comprehensive Network, Web Application, and Mobile Application penetration testing, beyond automated scanners.
  • Design and execute Phishing Simulation campaigns with realistic scenarios.
  • Ensure activities adhere to global standards (OWASP, PTES) and quality requirements.
  • Author detailed technical reports highlighting business risks and gaps.
  • Analyze root causes to propose advisory services or training opportunities.
  • Actively utilize AI tools to optimize reporting and data analysis.
  • Script routine scanning tasks and automate report generation to boost efficiency.
  • Generate dynamic phishing scenarios using AI tools to stay ahead of testing methods.
  • Mentor Junior Analysts, reviewing code and reports for quality control.
  • Maintain high billable utilization by delivering projects efficiently.

Skills

VAPT
Red Teaming
Technical reporting
AI tooling
Security consulting

Tools

Burp Suite
Metasploit
Nmap
Cobalt Strike

Job description

Key Responsibilities:

1. Offensive Security Delivery (Execution)

Aligns with Manager’s responsibility for Offensive Security

  • VAPT Execution: Perform comprehensive Network, Web Application, and Mobile Application penetration testing. You will go beyond automated scanners to identify critical logic flaws and business risks.
  • Phishing Simulations: Design and execute \"Phishing Simulation\" campaigns, crafting realistic scenarios to test client human defenses.
  • Technical Depth: Ensure all technical activities maintain \"adherence to global standards\" (e.g., OWASP, PTES) and meet the quality requirements set by the Consulting Manager.
2. Reporting & Commercial Awareness

Aligns with Manager’s responsibility for Account Mining & Reviews

  1. Strategic Reporting: Author detailed technical reports that do not just list bugs, but \"spot business risks in technical findings\". Your reports must be written in a way that allows the Manager to \"review deliverables with customers... to identify gaps that lead to new opportunities\".
  2. Root Cause Analysis: Instead of just reporting a vulnerability, analyze the systemic failure (e.g., poor coding practices) to help the Manager propose broader \"Advisory services\" or \"Training Academy\" solutions.
3. AI Integration & Process Modernization

Aligns with Manager’s responsibility for Innovation & AI Integration

  1. AI-Assisted Workflow: Actively utilize the AI/LLM tools implemented by the Manager to \"optimize reporting and data analysis\".
  2. Automation: Contribute to \"Methodology Enhancement\" by scripting routine scanning tasks or \"automating report generation\" to reduce non-billable hours and improve efficiency.
  3. Dynamic Scenarios: Assist in generating \"dynamic phishing scenarios\" using AI tools to keep testing methodologies ahead of the curve.
4. Mentorship & Utilization

Aligns with Manager’s responsibility for Resource Management & Team Motivation

  1. Tier 1 Mentorship: Act as a technical mentor for Junior (Tier 1) Analysts, reviewing their code and reports to ensure quality control before deliverables reach the Manager.
  2. Billable Efficiency: Maintain a high personal \"Billable Utilization\" rate by executing projects efficiently and minimizing idle time.

Qualifications:

  • 3-5 years of hands-on experience in Information Security Consulting, specifically focused on VAPT or Red Teaming (Aligns with Manager's requirement for 8+ years, scaled for Tier 2).
  • Proven experience writing technical reports for external clients.
  • Technical Competencies:
    • Offensive Mastery: Deep proficiency in Burp Suite, Metasploit, Nmap, and Cobalt Strike. Strong understanding of \"Offensive Security (Red Teaming)\" methodologies.
    • Frameworks: Working knowledge of OWASP (Top 10/API), NIST, and GDPR as they relate to vulnerability management.
    • AI Adaptability: \"Understanding of how to leverage AI tools\" (e.g., ChatGPT, Copilot for Security) to assist in code review or payload generation.
  • Certifications:
    • Must possess or be actively pursuing OSCP (Offensive Security Certified Professional).
    • Other relevant certifications: CEH, GPEN, or GWAPT.
  • Success Metrics (KPIs)
    • Billable Utilization: Maintaining a target utilization rate (e.g., 75%+) on assigned projects.
    • Time-to-Report: Successfully using AI tools to reduce the time spent on report writing, contributing to the Manager's \"Delivery Innovation\" target.
    • Deliverable Quality: Low rejection rate of reports during the Manager’s review, supporting high \"Customer Satisfaction\" and NPS scores.
    • Upsell Identification: Number of projects where technical findings successfully highlighted a gap that resulted in a \"follow‑on work\".
Data Privacy Notice

Novare values your privacy. By submitting your application, you hereby authorize Novare and its Affiliates to collect and process your Personal Information and Sensitive Personal Information (as defined under R.A. No. 10173 or the Data Privacy Act) contained in your resume and other documents and information provided to the Company for the processing of your job application. Your data is stored in Novare’s secure databases and retained until the expiration of the retention limit provided by law or when you revoke your consent.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Manager
Application Security Manager

PwC • Makati

On-site
PHP 1,200,000 - 1,600,000
Security Engineer, Offensive Security
Security Engineer, Offensive Security

InfoHedge Technologies LLC • Morong

On-site
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Thrive • Tarlac City

On-site
PHP 900,000 - 1,500,000
Offensive Security Consultant & Penetration Engineer
Offensive Security Consultant & Penetration Engineer

Novare Philippines Inc. • Taguig

Hybrid
PHP 1,000,000 - 1,800,000
Application Security Engineer
Application Security Engineer

Sideways 6 • Philippines

On-site
PHP 1,200,000 - 1,900,000
Senior Red Team Operator
Senior Red Team Operator

Sun Life • Taguig

On-site
PHP 1,800,000 - 3,000,000
Application Security Engineer
Application Security Engineer

Interact Software • Metro Manila

On-site
PHP 700,000 - 1,200,000
Security Analyst (Remote)
Security Analyst (Remote)

Prime System Solutions • Philippines

On-site
PHP 1,200,000 - 1,600,000
HMO coverage
Paid time off
Career development and certification
+2
Security Engineer - Red Team
Security Engineer - Red Team

Coberon Chronos • España

On-site
EUR 60,000 - 90,000
Security Engineer
Security Engineer

Azeus Systems Limited • Cebu City

On-site
PHP 1,200,000 - 1,800,000