Senior Application Security Engineer

Inriver

Davao City

On-site

PHP 2,500,000 - 3,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Inriver in Davao City is seeking a Senior Application Security Engineer to own security across the software development lifecycle. You will work hands-on with engineering teams to find, fix, and prevent vulnerabilities in a .NET/Azure‑based platform while focusing on secure AI features.

You will implement SAST/DAST in CI/CD, perform threat modeling and code reviews, and drive secure coding practices across product squads.

Qualifications

  • 8+ years of experience in application security or security-focused software engineering.
  • Experience integrating security tooling within CI/CD pipelines.
  • Strong .NET (C#) skills; reading Python helpful.
  • Fluent in OWASP Top 10 and API security risks.
  • Hands-on Azure experience including identity, networking, and secrets management.
  • Hands-on experience with Auth0 in production.
  • Excellent communication and ability to influence engineers.
  • Pragmatic, risk-based mindset balancing security with delivery.

Responsibilities

  • Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs.
  • Build, integrate, and operate SAST, SCA, and DAST in Azure DevOps pipelines, including PR gating on new critical and high findings, secret scanning, and automated routing of findings to tickets.
  • Secure our cloud estate across identity and access management, network configuration, secrets management, and workload protection, using Defender for Cloud policies.
  • Conduct threat models, design reviews, and code reviews for new and existing services with a threat model in place before production.
  • Evaluate security and privacy implications of AI features, including prompt injection, data leakage, and model misuse, and define controls.
  • Define and uphold secure coding standards, train engineers, and build a security champion in each product team.
  • Coordinate penetration tests and application vulnerability scanning, review findings, and implement fixes hands-on.
  • Support security incident investigation and response as the application SME with our MDR partner.

Skills

Application security
CI/CD security tooling
Azure security
Auth0
Communication

Tools

.NET (C#)
Azure DevOps
SAST/DAST tooling
Entra ID
Secret management tooling

Job description

About the role

We're looking for a Senior Application Security Engineer. You own security in the software development lifecycle (SDLC) — end to end, hands-on, and independently. You report to the CISO. The CISO sets direction, risk appetite, and handles executive escalation; you run application security day to day without needing constant support. You'll partner with engineering teams to find, fix, and prevent vulnerabilities in a platform built primarily on .NET and hosted in Azure, while helping us secure the next generation of AI-powered features. This is a hands‑on role for someone who wants to make secure development the path of least resistance for our engineers.

What you’ll do
  • Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs.
  • Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs.
  • Security tooling in CI/CD. Build, integrate, and operate SAST, SCA, and DAST in Azure DevOps pipelines, including PR gating on new critical and high findings, secret scanning, and automated routing of findings to tickets.
  • Azure security. Secure our cloud estate across identity and access management (Entra ID, Auth0), network configuration, secrets management, and workload protection, working with Defender for Cloud policy and posture.
  • Threat modeling and reviews. Conduct threat models, design reviews, and code reviews for new and existing services — with a threat model in place before any new service reaches production.
  • AI feature security. Evaluate security and privacy implications of our AI functionality, including LLM-specific risks such as prompt injection, data leakage, and model misuse, and define controls for them.
  • Standards and enablement. Define and uphold secure coding standards, train engineers, and build a security champion in each product team so risk assessment becomes self-service rather than a security-team bottleneck.
  • Pen tests and scans. Coordinate penetration tests and application vulnerability scanning, review the findings, identify fixes, and implement them hands‑on when needed.
  • Incident response. Support security incident investigation and response as the application subject‑matter expert, working with our 24/7 managed detection and response partner.
What you’ll bring
  • 8+ years of experience in application security, or in software engineering with a strong security focus.
  • Experience integrating and operating security tooling within CI/CD pipelines.
  • Strong .NET (C#) working knowledge; ability to read and reason about Python is a plus.
  • Fluency in common vulnerability classes (OWASP Top 10, API security risks) and how they manifest in real code — not just in scanner output.
  • Hands‑on Azure experience: creating resources, securing applications, Azure networking, and secrets management.
  • Hands‑on experience with Auth0 in production environments.
  • Strong communication skills and the ability to influence engineers without owning their backlog.
  • A pragmatic, risk‑based mindset that balances security with delivery — you know which findings matter and which are noise.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Interact Software • Metro Manila

On-site
PHP 700,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Sideways 6 • Philippines

On-site
PHP 1,200,000 - 1,900,000
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)

Recruitify_HR • Quezon City

Hybrid
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)

Recruitify_HR • Quezon City

Hybrid
Azure Security Engineer
Azure Security Engineer

AXOS BUSINESS CENTER CORP. • Taguig

Hybrid
PHP 1,300,000 - 2,400,000
Application Security Engineer
Application Security Engineer

Recruitify_HR • Quezon City

Hybrid
Up to 80k joining bonus
Hybrid work model
Competitive salary
Remote AppSec Engineer — AI-Driven SaaS Security
Remote AppSec Engineer — AI-Driven SaaS Security

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000
Application Security Engineer
Application Security Engineer

Trinity Workforce Solutions, Inc. • Makati

On-site
PHP 800,000 - 1,200,000
Collaborate with talented teams
Work on real-world security challenges
Career growth in a security-first culture
Application Security Engineer / Application Security Lead
Application Security Engineer / Application Security Lead

Recruitify_HR • Taguig

Hybrid
PHP 800,000 - 1,000,000
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000