Security Vulnerability And Penetration Testing Engineer

Baker McKenzie

Manila

Hybrid

PHP 900,000 - 1,500,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Baker McKenzie is seeking a Security Vulnerability and Penetration Testing (VAPT) Engineer to lead penetration testing across firm systems and apps. You will manage VAPT tools, deliver technical assessment reports, and provide practical, risk-based recommendations to enhance security posture.

The role requires deep VAPT expertise, strong English communication, and the ability to translate complex findings for non-technical audiences. Hybrid arrangement in Manila area is expected.

Qualifications

  • Knowledge of VAPT concepts and ethical hacking standards.
  • Differentiate vulnerability assessment vs penetration testing deliverables.
  • Hands-on with common VAPT tools (Nessus, AppScan, Burp Suite).
  • Experience with attack tools/frameworks (Wireshark, Kali, Metasploit).
  • Mobile security testing knowledge and best practices.
  • Ability to validate vulnerabilities accurately.
  • Understanding of OWASP, CVE, security controls, exploits.
  • Programming/scripting knowledge advantageous.
  • Experience with API testing methods is desirable.
  • Experience applying AI to security testing of AI-enabled apps.

Responsibilities

  • Lead security pen-testing across firm systems and apps.
  • Own and manage core VAPT tools, platforms, and processes.
  • Deliver clear assessment reports with actionable recommendations.
  • Convey complex concepts to non-technical stakeholders.

Skills

VAPT concepts
WhiteHat/ethical hacking
Vulnerability assessment vs. pen test
Nessus
AppScan
Burp Suite
Nipper
Trustwave
Wireshark
Kali
Metasploit
Mobile platform security
OWASP
CVE knowledge
Scripting languages
API testing
AI in security testing

Education

Computer Science Bachelor's Degree
CISSP certification
GIAC GPEN/GAIPT/GWAPT (preferred)
Offensive Security OSCP

Tools

Nessus
AppScan
Burp Suite
Nipper
Trustwave
Wireshark
Kali
Metasploit

Job description

Job Description:

Description & Requirements

The Security Vulnerability and Penetration Testing (VAPT) Engineer oversees and serves as technical resource for all assessment activity related to the security posture of existing and proposed firm systems, platforms, and processes to protect and continually improve the confidentiality, integrity, and availability of information systems in accordance with the firms business objectives, regulatory requirements, and strategic goals.

Main responsibilities:

As the VAPT Engineer, you will lead security penetration testing activities across the firms systems, platforms, and applications. Acting as the Subject Matter Expert (SME) for the VAPT function, you will own and manage core VAPT tools, platforms, and processes. You will deliver clear, audience-appropriate technical assessment reports and provide practical, actionable recommendations based on sound cybersecurity and risk management principles.

Skills and experience:

  • Commanding knowledge of VAPT concepts and best practices, including the requirements for WhiteHat/ethical hacking.
  • Expert understanding of the difference between a vulnerability assessment and a penetration test in the context of assessment scope, objectives, and deliverables.
  • Extensive experience with common automated VAPT tools such as Nessus, Appscan, Burp Suite, Nipper, and Trustwave.
  • Expertise with common attack tools and frameworks such as Wireshark, Kali, and Metasploit, etc.
  • Expertise with mobile platform security technology, including vulnerability identification and exploitation tools as well as mobile platform security best practices, frameworks, etc.
  • Ability to validate the presence of identified vulnerabilities with accuracy.
  • Mastery of common application platforms and technologies in order to effectively understand and evaluate complex application assessments via the use of manual techniques and simple tools such as proxies and browser plugins.
  • Authoritative mastery of OWASP, CVE, general security controls, and other foundational topics such as the latest application and operating system exploits.
  • Expert knowledge of common scripting and programming languages is advantageous.
  • Experience of in API testing methodologies highly desirable.
  • Demonstratable experience of using AI to enhance the penetration testing and risk assessment of AI-enabled applications and agents
  • Ongoing commitment to understanding the threat landscape and common adversary motivations/practices. Ability to quickly adapt practices to evolving circumstances.
  • Ability to maintain critical thinking and composure under pressure.
  • Strong written and oral communication skills. Ability to convey complex concepts to non-technical constituents. Proficiency in oral and written English.
  • Capable of providing assistance with the preparation of internal training materials and documentation.
  • Ability to be productive and maintain focus without direct supervision.
  • Understands VAPT in the context of risk management and organizational priorities.
  • Passionate in the practice and pursuit of VAPT excellence.

Qualifications:

  • Possess a Computer Science Bachelor’s Degree or substantial equivalent experience
  • CISSP required
  • GIAC GPEN, GAIPT or GWAPT preferred
  • Offensive Security OSCP required

Reports to: Manager, Vulnerability & Penetration testing team

Position Type:In Market & Centre Services

Development Framework: Specialist

About us

Baker McKenzie empowers clients to compete in the global economy. We provide comprehensive and practical legal advice that cuts through complexity with clear, actionable guidance. Our people represent diverse cultures and jurisdictions, combining local know-how with international expertise to ensure your business thrives across borders.

Additional Information

Baker McKenzie is an Equal Opportunity Employer. We are committed to promoting diversity and inclusion for all. Our unique international culture is reflected in the drawing together of a worldwide family of individuals from diverse cultures and backgrounds in all of our offices. We encourage the best people - regardless of race, religion or belief if any, gender, gender identity, disability, sexual orientation or age - to fulfill their professional aspirations with us. We are committed to ensuring an inclusive and accessible experience for all candidates.

Job Information

Posting Date: 23-Sep-2026

Requisition ID: 3587

States/Provinces/Cities: Belfast, Chicago, Manila

Location Type: Hybrid

Business Unit: Business Professionals

Function: Technology

Full Time or Part Time: Full Time

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead VAPT Engineer: Offensive Security & Risk Assessments
Lead VAPT Engineer: Offensive Security & Risk Assessments

Baker McKenzie • Manila

Hybrid
PHP 900,000 - 1,500,000
VAPT Specialist
VAPT Specialist

PM Consulting • Pasig

On-site
PHP 700,000 - 1,100,000
VAPT Analyst
VAPT Analyst

PM Consulting • Pasig

On-site
PHP 600,000 - 1,000,000
Penetration Tester - Hybrid - BGC - up to 100K
Penetration Tester - Hybrid - BGC - up to 100K

weSource Management Consultancy Firm • Taguig

On-site
PHP 892,800 - 1,116,000
Vulnerability Consultant
Vulnerability Consultant

HRTX • Taguig

On-site
PHP 900,000 - 1,300,000
Senior Cybersecurity Specialist (VAPT)
Senior Cybersecurity Specialist (VAPT)

Likha Careers • Pasig

On-site
PHP 669,600 - 892,800
Paid training
Health Insurance
Life Insurance
+2
Penetration Tester - Up to 100K - Hybrid BGC - Midshift
Penetration Tester - Up to 100K - Hybrid BGC - Midshift

weSource Management Consultancy Firm • Metro Manila

On-site
PHP 90,000 - 110,000
Security Architect For Network And Cloud
Security Architect For Network And Cloud

Baker McKenzie • Manila

Hybrid
PHP 1,200,000 - 1,800,000
Health benefits
Penetration Tester
Penetration Tester

Accenture • Metro Manila

Hybrid
PHP 900,000 - 1,500,000
Performance bonus
13th Month Pay
Day 1 HMO & Life Insurance Coverage
+2
Cyber Security -Senior Penetration Tester
Cyber Security -Senior Penetration Tester

Radii Global • Quezon City

On-site
PHP 1,200,000 - 1,800,000