Group Overview
TP ICAP Group is a leading provider of market infrastructure, offering global financial and commodities market access, price discovery, liquidity, and data solutions.
Role Overview
Senior Security Engineer within the Information Security function, responsible for developing cyber security capabilities across TPICAP. Key areas include vulnerability management, access control, platform engineering, detection and response, and coordination with offensive security.
Role Responsibilities
- Security platform engineering and projects
- Vulnerability identification and remediation
- Privileged access management
- Maintain current tooling operating effectiveness
- Identify areas for improvement within current tooling
- Proactively identify opportunities for control improvements
- Develop strong relationships with stakeholders across the business
- Provide security tooling metrics
- Review and provide security input on architecture design briefs and technical solution documents
- Collaborate with solution architects to ensure security is embedded in system and cloud designs
- Penetration test report remediation
- Define and validate security controls across cloud environments, particularly AWS
- Maintain awareness of cloud security architecture best practices and emerging technologies
- Support the development and implementation of secure‑by‑design principles across projects
- Maintain knowledge of current ATP TTPs
- Maintain knowledge of security tool landscape
Experience / Competences
- Essential: Experience implementing vulnerability management, SIEM, PAM, IDS/IPS, EDR, DLP, CNAPP, and AV platforms.
- Intermediate knowledge of incident response processes for OS and network level events.
- Comfortable with Windows and Linux operating systems.
- Solid knowledge of networking, active directory and web applications.
- Comfortable with at least one scripting or programming language such as Python, PowerShell, Bash, or Go.
- Experience with reviewing and implementing Cloud security controls.
- Experience reviewing architecture design documents and identifying security risks.
- Strong understanding of AWS security services and controls (IAM, GuardDuty, SCPs, KMS).
- Familiarity with cloud‑native security frameworks and reference architectures.
Desired
- Incident response and forensics experience.
- Offensive security experience.
- Degree level accreditation or equivalent experience.
- OSCP, CEH or SANS certification.
- Experience with threat modelling and secure design principles.
Location
Philippines – Ecoprime Building, Taguig City