Senior Cyber Security Engineer

GoTyme

Quezon City

On-site

PHP 1,800,000 - 2,400,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

GoTyme, a bank-tech joint venture in the Philippines, seeks a Senior Cyber Security Engineer to lead security operations with an AI- and automation‑first mindset. You will guide complex investigations, design scalable controls across cloud, endpoints, and identity, and mentor junior engineers.

You will drive threat detection, incident response, and secure architecture, aligning with ISO 27001, SOC 2, and NIST frameworks while partnering with technology and business teams to strengthen the

Qualifications

  • Bachelor’s degree in cybersecurity or related field.
  • 7–10+ years in cybersecurity engineering, SOC, or security operations.
  • Experience leading complex security investigations and incident response.
  • Ability to design, tune, and maintain detections at scale; mentoring others.
  • Deep expertise in AWS security services and Azure security tooling.
  • Knowledge of EDR/XDR platforms and endpoint telemetry.
  • Proficiency in scripting for automation (Python/PowerShell/Bash).
  • Experience with SIEM, SOAR, and log analytics.
  • Familiarity with AI‑driven security tooling.

Responsibilities

  • Lead advanced monitoring and analysis across AWS, Azure, and endpoint platforms.
  • Design, enhance, and optimise detection logic using CloudTrail, GuardDuty, Security Hub, Azure Sentinel, Defender, and EDR/XDR tools.
  • Drive end‑to‑end incident response activities, including containment, eradication, and recovery.
  • Conduct host, cloud, and log‑based forensic analysis.
  • Produce executive‑level incident reports, root‑cause analyses, and post‑incident improvement plans.
  • Mentor junior engineers and analysts, providing technical guidance and review.

Skills

Security leadership
Threat hunting
Incident response
Forensics analysis
Cloud security (AWS/Azure)
IAM security
Security monitoring
Automation scripting (Python/PowerShel
Threat intelligence
Zero-trust / least privilege

Education

Bachelor’s degree in Cybersecurity or related field

Tools

CloudTrail
GuardDuty
Config
Security Hub
Azure Sentinel
Defender
Security Center
EDR/XDR
SIEM
SOAR
Python
PowerShell
Bash

Job description

About GoTyme

GoTyme is a joint venture between the Gokongwei Group, one of the biggest conglomerates in the Philippines, and the Singapore-headquartered digital banking group Tyme. This venture combines the trusted Gokongwei brand, customer base, and distribution ecosystem with Tyme’s globally proven digital banking technology and hands‑on experience building South Africa’s leading digital bank, TymeBank, one of the fastest‑growing digital banks in the world today.

At GoTyme, we have embarked on a journey to democratize financial services and bring next‑level banking to the Philippines. We seek individuals who share our belief that the game is worth changing, to join our growing team of GoTymers as we build, launch, and scale a bank that empowers all Filipinos to navigate a path to financial freedom.

About the role

We are seeking a Senior Cyber Security Engineer to join our cybersecurity team, operating with an AI- and automation-first mindset. This role goes beyond monitoring and response and requires technical leadership, deep investigative expertise, and the ability to design, improve, and scale security controls across cloud, endpoint, and identity environments.

The successful candidate will act as a subject-matter expert, leading complex investigations, driving proactive threat detection, mentoring junior engineers, and partnering with technology and business teams to continuously strengthen the organisation’s security posture.

Security Monitoring, Engineering & Analysis
  • Lead advanced monitoring and analysis of security events across AWS, Azure, and endpoint platforms
  • Design, enhance, and optimise detection logic using CloudTrail, GuardDuty, Security Hub, Azure Sentinel, Defender, and EDR/XDR tools
  • Proactively identify security gaps, misconfigurations, and control weaknesses across cloud and SaaS environments
  • Develop and maintain automated detection and response workflows using scripting and SOAR principles
  • Perform deep analysis of DLP alerts, ensuring protection of sensitive and regulated data
Incident Response, Forensics & Crisis Management
  • Act as a lead investigator for high‑severity security incidents
  • Drive end‑to‑end incident response activities, including containment, eradication, and recovery
  • Conduct advanced host, cloud, and log‑based forensic analysis
  • Produce executive‑level incident reports, root‑cause analyses, and post‑incident improvement plans
  • Support tabletop exercises, incident simulations, and continuous improvement of IR playbooks
Threat Detection, Hunting & Intelligence
  • Lead proactive threat hunting activities using behavioural analytics and threat intelligence
  • Map detections to MITRE ATT&CK and continuously improve coverage
  • Perform advanced malware analysis and support reverse‑engineering efforts when required
  • Translate threat intelligence into actionable detections and preventive controls
  • Stay ahead of emerging attack techniques, cloud‑native threats, and identity‑based attacks
Identity, Access & Privileged Security
  • Oversee monitoring and investigation of privileged access and identity‑based threats
  • Lead IAM security reviews and contribute to least‑privilege and zero‑trust initiatives
  • Investigate anomalous authentication behaviour and insider‑risk indicators
  • Partner with IAM teams to strengthen identity security architecture and controls
Security Engineering, Architecture & Enablement
  • Contribute to the design and improvement of cloud and enterprise security architectures
  • Define security requirements for new platforms, services, and integrations
  • Support compliance initiatives aligned to ISO 27001, SOC 2, NIST, PCI DSS and internal risk frameworks
  • Mentor junior engineers and analysts, providing technical guidance and review
  • Influence security strategy through technical insight and data‑driven recommendations

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field
  • 7–10+ years of hands‑on experience in cybersecurity engineering, SOC, or security operations roles
  • Demonstrated experience leading complex security investigations and incident response
  • Proven ability to design, tune, and maintain security detections at scaleExperience mentoring or technically leading other security practitioners
  • Deep expertise in AWS security services (CloudTrail, GuardDuty, Config, Security Hub)
  • Strong experience with Azure security tooling (Sentinel, Defender, Security Center)
  • Advanced knowledge of EDR/XDR platforms and endpoint telemetry
  • Hands‑on experience with SIEM, SOAR, and log analytics platforms
  • Strong understanding of networking, IAM, authentication protocols, and attack vectors
  • Proficiency in Python, PowerShell, or Bash for automation and analysis
  • Experience applying threat hunting and detection engineering methodologies
  • Familiarity with AI-driven security tooling and prompt-based analysis
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Engineer
Senior Cyber Security Engineer

Internetwork Expert • Quezon City

On-site
PHP 1,200,000 - 2,400,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

GoTyme Bank • Quezon City

On-site
PHP 1,500,000 - 2,100,000
Senior Cybersecurity Engineer: AI-First Threat Hunting & IR Lead
Senior Cybersecurity Engineer: AI-First Threat Hunting & IR Lead

GoTyme • Quezon City

On-site
PHP 1,800,000 - 2,400,000
Senior Cybersecurity Engineer - AI-First Threat Detection
Senior Cybersecurity Engineer - AI-First Threat Detection

Internetwork Expert • Quezon City

On-site
PHP 1,200,000 - 2,400,000
Senior Cyber Security Engineer: AI-Driven Cloud & IR Lead
Senior Cyber Security Engineer: AI-Driven Cloud & IR Lead

GoTyme Bank • Quezon City

On-site
PHP 1,500,000 - 2,100,000
Cybersecurity Engineer
Cybersecurity Engineer

Hrtx • Philippines

Hybrid
PHP 1,000,000 - 1,800,000
Hybrid work setup
Head of Fraud
Head of Fraud

GoTyme • Philippines

On-site
PHP 3,000,000 - 8,000,000
Junior Cyber Security Engineer/Analyst
Junior Cyber Security Engineer/Analyst

PM Consulting • Philippines

On-site
PHP 600,000 - 900,000
Data Scientist
Data Scientist

GoTyme Bank • Quezon City

On-site
PHP 900,000 - 1,500,000
Application Security Engineer
Application Security Engineer

Sideways 6 • Philippines

On-site
PHP 1,200,000 - 1,900,000