Security Engineer - Offensive Security

Thrive

Tarlac City

On-site

PHP 900,000 - 1,500,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Thrive in the Philippines seeks a Security Engineer to join our Offensive Security team. This role will own the delivery of vulnerability management and pentesting services, communicating findings and remediation steps to clients while coordinating with Thrive’s internal teams to ensure high-quality services and client satisfaction.

The ideal candidate has 3–5 years of pentesting experience, strong knowledge of security best practices, and familiarity with Burp Suite, Metasploit, and Caido.

Qualifications

  • 3-5 years of experience executing penetration tests and delivering reports to clients.
  • Strong knowledge of TCP/IP, OS internals, and security best practices.
  • Ability to communicate security concepts to non-technical stakeholders.
  • Proactive in threat modeling and remediation guidance.
  • Familiarity with vulnerability management and pen-testing tools.

Responsibilities

  • Execute vulnerability scans and determine remediation steps.
  • Perform penetration tests (manual and automated) and deliver client reports and debriefs.
  • Lead client meetings, offering expert advice and guidance as needed.
  • Collaborate with clients to understand business needs and align remediation with outcomes.
  • Create and maintain materials documenting security processes and technologies, plus automated reports.
  • Update client security presentations and discuss findings.
  • Stay ahead of new threats and attack techniques to inform clients.
  • Other duties as required.

Skills

Vulnerability Scans
Penetration Testing
Report Writing
Client Engagement
Security Analytics
Team Collaboration
Threat Intelligence

Education

eJPT
OSCP
CEH
GPEN
PNPT
PJPT
PenTest+
Security+

Tools

Burp Suite
Metasploit Framework
Caido

Job description

About Us

Thrive is a rapidly growing technology solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services. Our corporate culture, engineering talent, customer-centric approach, and focus upon “next generation” services help us stand out amongst our peers. Thrive is on the look-out for individuals who don’t view their weekdays spent at “a job”, but rather look to develop valuable skills that ignite their passion and lead to a CAREER. If you’re attracted to a “work hard, play hard” environment, seeking the guidance, training and experience necessary to build a lucrative career, then welcome to THRIVE!!

Position Overview

Thrive is looking for a security engineer to join our Offensive Security team. This team focuses on advanced vulnerability management and Pentesting as a service and delivers strategic security insights to clients based on the findings of these services. This role will own the delivery of these services ensuring client satisfaction, timely and complete service delivery. The Security Engineer will work closely with the team to ensure the services are being delivered to clients effectively, and stay on top of industry's best practices as well as new features available from the tools. Additionally, the Security Engineer will coordinate with internal teams at Thrive and the primary contact for these services for clients. This role will meet with customers and explain the vulnerabilities found and/or exploited, and assist with steps for remediation. This Engineering position requires attention to detail and a commitment to maintaining high security standards and fostering client trust in our cybersecurity capabilities.

Primary Responsibilities
  • Execution and analysis of vulnerability scans and determining remediation steps
  • Execution and analysis of Penetration Tests (manual and autonomous), writing reports, and delivery of reports to client stake holders.
  • Lead client meetings, offering expert advice and guidance as needed.
  • Collaborate with clients to understand their business needs and requirements to best align remediation requirements to business outcomes.
  • Creation and ongoing upkeep of materials documenting our security processes, procedures, and technologies, along with the generation of automated reports for relevant stakeholders.
  • Update client Security presentations and discuss findings with our clients.
  • Maintain a leading edge on security events and techniques to keep our clients aware of new threats and attack techniques.
  • Other duties as required.
Requirements
  • Solid understanding of network protocols, operating systems, application layer protocols, and security best practices.
  • Understanding cybersecurity threats, and experience with incident response standards and procedures.
  • Ability to communicate security information to non-technical people.
  • Has a passion for Cyber Security.
  • Demonstrates comprehension of good security practices
  • Knowledge of risk assessment tools, technologies and methods
  • Knowledge of penetration testing methodologies, frameworks, and toolsAbility to analyze a large amount of data from various sources and use this information to solve complex problems and make good decisions. Must be able to work effectively in a team environment and collaborate within the team and other stakeholders.
  • Excellent Written and Verbal Communication Skills
  • Computer Networking & Security
  • Vulnerability Discovery and Analysis
  • Operating System Internals
  • Familiarity with TCP/IP network protocols, application layer protocols (e.g., HTTP, SMTP, DNS, etc.).
  • 3-5 years of experience executing penetration tests, writing reports and delivering report debriefs to clients
  • Knowledge of common Windows and Linux/Unix system calls and APIs
  • Working knowledge of pentesting tools, such as Burpsuite, Metaspliot framework, Caido
  • Knowledge of programming and/or scripting languages (i.e. Python)
  • One or more of the following certifications or other relevant certifications: eJPT, PJPT, PenTest+, OSCP, GPEN, PNPT, CEH, Security+
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Offensive Security
Security Engineer, Offensive Security

InfoHedge Technologies LLC • Morong

On-site
Security Engineer - Remediation
Security Engineer - Remediation

Thrive • Capas

Hybrid
PHP 700,000 - 1,100,000
Offensive Security Engineer: PenTest Lead & Client Advisory
Offensive Security Engineer: PenTest Lead & Client Advisory

Thrive • Tarlac City

On-site
PHP 900,000 - 1,500,000
Security Engineer
Security Engineer

Azeus Systems Limited • Pasig

On-site
PHP 558,000 - 781,200
Staff Security Engineer
Staff Security Engineer

Koine Ventures Inc. • Manila

On-site
PHP 1,200,000 - 1,800,000
Security Engineer
Security Engineer

Azeus Systems Limited • Cebu City

On-site
PHP 1,200,000 - 1,800,000
VAPT Engineer
VAPT Engineer

Hitachi Digital Payment Solutions Philippines Inc. • Philippines

On-site
PHP 800,000 - 1,500,000
Vulnerability and Penetration Tester
Vulnerability and Penetration Tester

Total Information Management Corp. • Philippines

On-site
PHP 600,000 - 1,000,000
Security Engineer - Remediation (Vulnerability Response)
Security Engineer - Remediation (Vulnerability Response)

Thrive • Capas

Hybrid
PHP 700,000 - 1,100,000
SOC Analyst
SOC Analyst

Thrive • Capas

Hybrid
PHP 300,000 - 540,000