Security Engineer

Convene

Manila

On-site

PHP 1,200,000 - 2,400,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Convene in Manila is seeking a Security Engineer to dive into application security testing across Web and mobile apps. You will own the vulnerability lifecycle, conduct security investigations, and collaborate with Blue Team and DevOps to embed controls throughout the SDLC.

The role requires hands-on experience with Burp Suite, OWASP ZAP, Metasploit, and cloud security (AWS), plus relevant certifications such as CISA/CISSP are a plus.

Qualifications

  • 5+ years of experience in application security testing and assessments.
  • Solid understanding of OWASP Top 10 and SANS Critical Security Controls.
  • Experience with security tools such as Burp Suite, ZAP, Metasploit, SonarQube.
  • Proficiency in Java, JavaScript, and C/C++; scripting with Bash or PowerShell.
  • Knowledge of AWS cloud and SIEM technologies; security certifications are a plus.

Responsibilities

  • Perform penetration testing of Web and Mobile applications across platforms.
  • Own vulnerability management lifecycle from identification to reporting.
  • Monitor and detect operational security risks in the organization.
  • Investigate security incidents and related tooling.
  • Engage with users during Pre-sales and Support on security queries.
  • Collaborate with Blue Team to implement security best practices in SDLC.
  • Support threat modelling and security controls for ISO 27001 and SOC 2.

Skills

Application security
Penetration testing
Vulnerability management
Incident investigation
Blue Team collaboration
Threat modelling
Security awareness training
ISO 27001
SOC 2
CISA
CISM
CISSP

Tools

Burp Suite
OWASP ZAP
Metasploit
SonarQube
Ghidra
IDA
Java
JavaScript
C/C++
Bash
PowerShell
AWS
SIEM

Job description

Job Description:

About the Security Engineer role:

Responsibilities

Involved in Red Team activities:

  • Perform penetration testing of Web and Mobile (iOS, Android, Windows, and Mac) applications
  • Own the vulnerability management lifecycle from identification, remediation to reporting
  • Active monitoring and detection of operational security risks in the organization
  • Conduct technical investigations on security incidents and tools
  • Liaise directly with users on security enquiries and concerns during Pre-sales and Support
Conduct engagement with the Blue Team for the following:
  • Work with engineering and DevOps teams to implement security best practices
  • Implement and improve workflows to automate vulnerability detection as part of the software development lifecycle
  • Review risks and patches of software components used in the applications
  • Facilitate threat modelling as part of the software development lifecycle
  • Help in security awareness training
  • Help in implementing the needed controls for different certification bodies such as ISO 27001 and SOC Type 2
Qualifications
  • At least 5 years of experience in application security testing and assessments
  • Solid understanding of cybersecurity principles, standards, and protocols such as OWASP Top 10 and SANS Critical Security Controls
  • Experience with application security tools such as Burpsuite, OWASP ZAP, Metasploit, SonarQube (experience with Ghidra or IDA is a plus)
  • Experience with programming languages such as Java, JavaScript, C/C++
  • Experience with scripting languages such as Bash or PowerShell
  • Experience and knowledge of cloud solutions and architectures such as AWS
  • Experience and knowledge of Security Information and Event Management (SIEM) technologies
  • Good analytical skills
  • Strong sense of ownership
  • Technical and industry certifications such as CISA, CISM, CISSP are a plus
Others
  • Successful completion of background check and NBI clearance will be required.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Azeus Convene • Pasig

On-site
PHP 900,000 - 1,800,000
Security Engineer
Security Engineer

Azeus Systems Limited • Cebu City

On-site
PHP 600,000 - 900,000
Security Engineer
Security Engineer

Azeus Convene • Cebu City

On-site
PHP 1,400,000 - 2,000,000
Security Engineer
Security Engineer

Azeus Group • Pasig

On-site
PHP 900,000 - 1,300,000
Security Engineer
Security Engineer

Azeus Systems Limited • Pasig

On-site
PHP 558,000 - 781,200
Security Engineer - Red Team
Security Engineer - Red Team

Coberon Chronos • España

On-site
EUR 60,000 - 90,000
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

On-site
PHP 4,972,000 - 7,813,000
Security Engineer - Offensive Security
Security Engineer - Offensive Security

Thrive • Quezon City

On-site
PHP 600,000 - 1,000,000
Security Analyst
Security Analyst

Artech Technology Inc. • Quezon City

On-site
PHP 3,527,337 - 5,291,005
Application Security Engineer
Application Security Engineer

Trinity Workforce Solutions, Inc. • Makati

On-site
PHP 800,000 - 1,200,000
Collaborate with talented teams
Work on real-world security challenges
Career growth in a security-first culture