Senior Application Security Engineer

inRiver inc

Manila

On-site

PHP 900,000 - 1,800,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

inRiver inc. seeks a Senior Application Security Engineer to own security across the SDLC, hands-on and independent, reporting to the CISO. You will partner with engineering to find, fix, and prevent vulnerabilities in a .NET/Azure platform while enabling AI features securely.

You’ll drive threat modeling, code reviews, and secure coding standards, mentoring teams and ensuring risk is treated as self-service rather than a bottleneck. This is a hands-on security leadership role.

Qualifications

  • 8+ years of experience in application security or security-focused software engineering.
  • Experience integrating and operating security tooling within CI/CD pipelines.
  • Strong .NET (C#) knowledge; Python familiarity is a plus.
  • Fluency with OWASP Top 10 and API security risks; ability to translate findings into code fixes.

Responsibilities

  • Lead vulnerability management end-to-end with Azure DevOps backlogs and SLAs.
  • Build, integrate, and operate SAST, SCA, and DAST in CI/CD pipelines and gate PRs.
  • Secure Azure cloud estate including IAM, networking, secrets management, and posture.
  • Conduct threat modeling, designs reviews, and code reviews for new services.

Skills

Application security
CI/CD tooling
C#/.NET
Python basics
Azure
Auth0
OWASP Top 10
Threat modeling
Communication

Job description

About the role

We’re looking for a Senior Application Security Engineer. You own security in the software development lifecycle (SDLC) — end to end, hands-on, and independently. You report to the CISO. The CISO sets direction, risk appetite, and handles executive escalation; you run application security day to day without needing constant support. You’ll partner with engineering teams to find, fix, and prevent vulnerabilities in a platform built primarily on .NET and hosted in Azure, while helping us secure the next generation of AI-powered features. This is a hands-on role for someone who wants to make secure development the path of least resistance for our engineers.

What you’ll do
  • Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs. Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs.
  • Security tooling in CI/CD. Build, integrate, and operate SAST, SCA, and DAST in Azure DevOps pipelines, including PR gating on new critical and high findings, secret scanning, and automated routing of findings to tickets.
  • Azure security. Secure our cloud estate across identity and access management (Entra ID, Auth0), network configuration, secrets management, and workload protection, working with Defender for Cloud policy and posture.
  • Threat modeling and reviews. Conduct threat models, design reviews, and code reviews for new and existing services — with a threat model in place before any new service reaches production.
  • AI feature security. Evaluate security and privacy implications of our AI functionality, including LLM-specific risks such as prompt injection, data leakage, and model misuse, and define controls for them.
  • Standards and enablement. Define and uphold secure coding standards, train engineers, and build a security champion in each product team so risk assessment becomes self-service rather than a security-team bottleneck.
  • Pen tests and scans. Coordinate penetration tests and application vulnerability scanning, review the findings, identify fixes, and implement them hands-on when needed.
  • Incident response. Support security incident investigation and response as the application subject-matter expert, working with our 24/7 managed detection and response partner.
What you’ll bring
  • 8+ years of experience in application security, or in software engineering with a strong security focus.
  • Experience integrating and operating security tooling within CI/CD pipelines.
  • Strong .NET (C#) working knowledge; ability to read and reason about Python is a plus.
  • Fluency in common vulnerability classes (OWASP Top 10, API security risks) and how they manifest in real code — not just in scanner output.
  • Hands-on Azure experience: creating resources, securing applications, Azure networking, and secrets management.
  • Hands-on experience with Auth0 in production environments.
  • Strong communication skills and the ability to influence engineers without owning their backlog.
  • A pragmatic, risk-based mindset that balances security with delivery — you know which findings matter and which are noise
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)

Recruitify_HR • Quezon City

Hybrid
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)
Application Security Engineer, Application Security Lead (DevSecOps / Azure DevOps)

Recruitify_HR • Quezon City

Hybrid
Application Security Engineer, Application Security Lead- 80K SOB
Application Security Engineer, Application Security Lead- 80K SOB

Bravissimo Resourcing Inc. • Quezon City

On-site
PHP 800,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Comrise • Taguig

Hybrid
PHP 1,800,000 - 3,200,000
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000
Application Security Engineer / Application Security Lead
Application Security Engineer / Application Security Lead

Recruitify_HR • Taguig

Hybrid
PHP 800,000 - 1,000,000
Application Security Engineer
Application Security Engineer

Trinity Workforce Solutions, Inc. • Makati

On-site
PHP 800,000 - 1,200,000
Collaborate with talented teams
Work on real-world security challenges
Career growth in a security-first culture
Full-Stack .Net, Cloud, and AI Engineer (.NET, Python, Azure, Agentic AI)
Full-Stack .Net, Cloud, and AI Engineer (.NET, Python, Azure, Agentic AI)

Risewave Consulting, Inc. • Manila

Hybrid
PHP 800,000 - 1,200,000
Senior DevSec Engineer: Azure/.NET & AI Security
Senior DevSec Engineer: Azure/.NET & AI Security

inRiver inc • Manila

On-site
PHP 900,000 - 1,800,000
Remote AppSec Engineer — AI-Driven SaaS Security
Remote AppSec Engineer — AI-Driven SaaS Security

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000