Senior AppSec Engineer: CI/CD Security Builder (Hybrid)

ConnectOS

Philippines

Hybrid

PHP 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work
Medical & dental
Life insurance
Paid time off
Annual appraisal
Financial assistance
13th month pay
Sleeping quarters
Office fitness

Job summary

ConnectOS is seeking a Senior Application Security Engineer to blend application security, DevSecOps, and cloud security engineering. This hands-on role embeds security into how software is built, deployed, and operated across Flybuys' technology estate.

The role works horizontally across CI/CD pipelines, cloud infrastructure, containers, APIs, and identity systems, and vertically through the stack from source code to runtime.

Qualifications

  • 5+ years in security engineering or application security roles, or equivalent software/platform engineering experience with a strong security focus.
  • Deep hands-on experience building, securing, and integrating security tooling into CI/CD pipelines.
  • Strong AWS knowledge across IAM, networking, compute, storage, and native security services.
  • Practical experience with vulnerability management at scale, including triage, prioritisation, and remediation across diverse technology environments.
  • Experience with application security tooling such as SAST, DAST, SCA, IaC scanning, container image scanning, and secrets detection.
  • Understanding of OWASP Top 10, common web application vulnerabilities, and secure development principles.
  • Demonstrated experience building custom tools, scripts, or automation rather than only configuring vendor products.
  • Practical experience applying AI/ML or LLMs to security or engineering workflows, such as automated triage, code analysis, data enrichment, or agent-based automation.
  • Strong communication skills, with the ability to explain technical risk to both engineers and non-technical stakeholders.

Responsibilities

  • Design, build, and maintain security controls embedded in CI/CD pipelines.
  • Build quality gates that provide fast, actionable feedback to developers without blocking delivery unnecessarily.
  • Own the security tooling pipeline, including selection, integration, tuning, false-positive reduction, and developer experience.
  • Develop and maintain security-as-code artefacts, including policies, rulesets, and custom checks that scale across repositories and teams.
  • Work with engineering teams to shift vulnerability detection left, catching issues at commit and build rather than in production.
  • Define and maintain API security standards, particularly for externally facing and partner-integrated services.
  • Own the technical execution of vulnerability management across application, container, and cloud layers.
  • Triage, prioritise, and drive remediation of vulnerabilities from sources such as Wiz, AWS Inspector, Defender, SAST, and DAST tools.
  • Correlate vulnerability findings with asset context, including internet exposure, data sensitivity, identity permissions, and business criticality.
  • Build and improve vulnerability reporting, metrics, and observability.
  • Identify systemic root causes such as stale AMIs, unpatched base images, and outdated dependencies, and drive permanent fixes over one-off patches.
  • Review and harden Infrastructure-as-Code, including Terraform and CloudFormation, for security misconfigurations before deployment.
  • Contribute to AWS account baselining, onboarding, and security architecture patterns.
  • Support penetration testing coordination, including scoping, remediation tracking, and retest validation.
  • Provide practical security guidance to delivery teams during design, development, deployment, and operational support.

Skills

Security engineering
CI/CD security
AWS security
Vulnerability mgmt
App security tooling
OWASP Top 10
Automation scripting
AI in security
Communication skills

Tools

Terraform
CloudFormation
Docker
Kubernetes/EKS
OAuth 2.0 / OIDC

Job description

ConnectOS is seeking a Senior Application Security Engineer to blend application security, DevSecOps, and cloud security engineering. This hands-on role embeds security into how software is built, deployed, and operated across Flybuys' technology estate.

The role works horizontally across CI/CD pipelines, cloud infrastructure, containers, APIs, and identity systems, and vertically through the stack from source code to runtime.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer - Hybrid DevSecOps
Senior Application Security Engineer - Hybrid DevSecOps

ConnectOS • Metro Manila

Hybrid
PHP 1,400,000 - 2,100,000
Hybrid work arrangement
Medical and dental coverage from day 1
Paid vacation and sick leave
+4
Senior AppSec Engineer - Build Secure DevOps (Hybrid)
Senior AppSec Engineer - Build Secure DevOps (Hybrid)

ConnectOS • Mandaluyong

Hybrid
PHP 1,200,000 - 2,400,000
Hybrid work arrangement
Medical and dental coverage
Life insurance
+4
Senior AppSec Engineer - Hybrid, DevSecOps & Cloud
Senior AppSec Engineer - Hybrid, DevSecOps & Cloud

ConnectOS • Mandaluyong

Hybrid
Hybrid Work Arrangement
Medical, Dental Coverage
Paid Vacation and Sick Leave
+6
Application Security Engineer - Build Secure Delivery
Application Security Engineer - Build Secure Delivery

Financial Times • Taguig

On-site
PHP 900,000 - 1,500,000
Senior Security Engineer - Platforms & AI Enablement
Senior Security Engineer - Platforms & AI Enablement

ConnectOS • Mandaluyong

Hybrid
PHP 893,000 - 1,339,000
Hybrid Work Arrangement
Medical and Dental Coverage
Paid Vacation and Sick Leave
+2
Senior Application Security Engineer (AU Retail, Hybrid)
Senior Application Security Engineer (AU Retail, Hybrid)

ConnectOS • Philippines

Hybrid
PHP 1,200,000 - 1,800,000
Hybrid work
Medical & dental
Life insurance
+6
Senior Application Security Engineer (AU Retail, Hybrid)
Senior Application Security Engineer (AU Retail, Hybrid)

ConnectOS • Mandaluyong

Hybrid
Hybrid Work Arrangement
Medical, Dental Coverage
Paid Vacation and Sick Leave
+6
Senior Application Security Engineer (AU Retail, Hybrid)
Senior Application Security Engineer (AU Retail, Hybrid)

ConnectOS • Metro Manila

Hybrid
PHP 1,400,000 - 2,100,000
Hybrid work arrangement
Medical and dental coverage from day 1
Paid vacation and sick leave
+4
Senior AppSec & Cloud Security Engineer — AWS
Senior AppSec & Cloud Security Engineer — AWS

Financial Times • Taguig

On-site
PHP 7,304,000 - 10,956,000
Senior Application Security Engineer (AU, Retail, Hybrid)
Senior Application Security Engineer (AU, Retail, Hybrid)

ConnectOS • Mandaluyong

On-site
PHP 1,200,000 - 2,400,000
Hybrid work arrangement
Medical and dental coverage
Life insurance
+4