Security Engineer

Azeus Systems Limited

Cebu City

On-site

PHP 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Azeus Systems Limited is seeking an experienced Application Security professional in Cebu City to perform penetration testing across web and mobile platforms, manage the vulnerability lifecycle, and monitor risks throughout the organization. You will collaborate with engineering and DevOps to implement security best practices and automate detection within SDLC.

Required: 5+ years in app security, strong knowledge of OWASP Top 10, SANS Controls, and experience with tools like Burp Suite, ZAP,

Qualifications

  • 5+ years of experience in application security testing and assessments.
  • Strong understanding of cybersecurity principles, standards and protocols such as OWASP Top 10 and SANS Critical Security Controls.
  • Experience with application security tools such as Burpsuite, OWASP ZAP, Metasploit, Sonarqube (experience with Ghidra or IDA is a plus).
  • Experience with programming languages such as Java, JavaScript, C/C++
  • Experience with scripting languages such as bash or Powershell
  • Experience and knowledge of cloud solutions and architectures such as AWS
  • Experience and knowledge of Security information and event management (SIEM) technologies
  • Good analytical skills
  • Strong sense of ownership
  • Technical and industry certifications such as CISA, CISM, CISSP are a plus

Responsibilities

  • Perform penetration testing of Web and Mobile (iOS, Android, Windows and Mac) applications
  • Own the vulnerability management lifecycle from identification, remediation to reporting
  • Active monitoring and detection of operational security risks in the organization
  • Conduct technical investigations on security incidents and tools
  • Liaise directly with users on security enquiries and concerns during Pre-sales and Support
  • Work with engineering and DevOps teams to implement security best practices
  • Implement and improve workflows to automate vulnerability detection as part of the software development lifecycle
  • Review risks and patches of software components used in the applications
  • Facilitate threat modelling as part of the software development lifecycle
  • Help in security awareness training
  • Help in implementing the needed controls for different certification bodies such as ISO 27001 and SOC Type 2

Skills

Application security
OWASP Top 10
SANS Critical Security Controls
Java
JavaScript
C/C++
Bash
PowerShell
AWS
SIEM

Tools

Burp Suite
OWASP ZAP
Metasploit
SonarQube
Ghidra
IDA

Job description

Responsibilities
  • Perform penetration testing of Web and Mobile (iOS, Android, Windows and Mac) applications
  • Own the vulnerability management lifecycle from identification, remediation to reporting
  • Active monitoring and detection of operational security risks in the organization
  • Conduct technical investigations on security incidents and tools
  • Liaise directly with users on security enquiries and concerns during Pre-sales and Support
Conduct engagement with the Blue Team for the following
  • Work with engineering and DevOps teams to implement security best practices
  • Implement and improve workflows to automate vulnerability detection as part of the software development lifecycle
  • Review risks and patches of software components used in the applications
  • Facilitate threat modelling as part of the software development lifecycle
  • Help in security awareness training
  • Help in implementing the needed controls for different certification bodies such as ISO 27001 and SOC Type 2
Qualifications
  • At least 5 years of experience in application security testing and assessments
  • Solid understanding of cybersecurity principles, standards and protocols such as OWASP Top 10 and SANS Critical Security Controls
  • Experience with application security tools as Burpsuite, OWASP ZAP, Metasploit, Sonarqube (experience with Ghidra or IDA is a plus)
  • Experience with programming languages such as Java, JavaScript, C/C++
  • Experience with scripting languages such as bash or Powershell
  • Experience and knowledge of cloud solutions and architectures such as AWS
  • Experience and knowledge of Security information and event management (SIEM) technologies
  • Good analytical skills
  • Strong sense of ownership
  • Technical and industry certifications such as CISA, CISM, CISSP are a plus
Others
  • Successful completion of background check and NBI clearance will be required.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Azeus Group • Pasig

On-site
PHP 900,000 - 1,300,000
Security Engineer
Security Engineer

Azeus Systems Limited • Pasig

Hybrid
Application Security Manager
Application Security Manager

PwC • Makati

On-site
PHP 1,200,000 - 1,600,000
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Thrive • Tarlac City

On-site
PHP 900,000 - 1,500,000
Security Analyst
Security Analyst

Artech Technology Inc. • Quezon City

On-site
PHP 3,527,000 - 5,292,000
Application Security Engineer
Application Security Engineer

Interact Software • Metro Manila

On-site
PHP 700,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Sideways 6 • Philippines

On-site
PHP 1,200,000 - 1,900,000
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000
Application Security Engineer
Application Security Engineer

Career Connect • Makati

On-site
PHP 700,000 - 1,100,000
Security Engineer - Support
Security Engineer - Support

Thrive • Morong

On-site
PHP 400,000 - 700,000