About Us
Outsourced.ph is a leading ISO-certified Philippines offshore outsourcing company that provides dedicated remote staff to some of the world's leading international companies. Outsourced is recognized as one of the Best Places to Work and has achieved Great Place to Work Certification.
We are committed to providing a positive and supportive work environment where all staff can thrive. As an Outsourced staff member, you will enjoy a collaborative working environment, competitive compensation, opportunities for growth and development, work-life balance, and the chance to work alongside talented professionals.
About the Role
We are looking for an experienced Security Engineer to maintain and enhance enterprise cyber security capabilities across on-premises and cloud environments.
This role will focus on vulnerability management, security monitoring, incident response, penetration testing, Microsoft 365 and cloud security, security awareness, and compliance activities.
You will work closely with Infrastructure, Applications, DevOps, and Business teams to identify security risks, implement appropriate controls, and drive remediation across the organisation.
Key Responsibilities
- Review and interpret vulnerability assessment reports from internal and external scanning platforms.
- Prioritise vulnerabilities based on risk, exploitability, and business impact.
- Coordinate remediation activities with system owners and technical teams.
- Track remediation progress and provide regular reporting on outstanding risks and compliance metrics.
- Support continuous improvement of vulnerability management processes and controls.
- Develop and maintain the annual penetration testing programme.
- Coordinate internal and external penetration testing activities.
- Review and analyse penetration test findings and risk ratings.
- Work with stakeholders to develop remediation plans and validate closure of findings.
- Monitor security alerts and investigate suspicious activities.
- Act as a technical subject matter expert during cyber security incidents.
- Coordinate containment, eradication, recovery, and post-incident review activities.
- Support threat hunting and security investigations across cloud, endpoint, and identity platforms.
- Administer and optimise Microsoft Entra ID and Microsoft 365 security controls.
- Manage Conditional Access, Multi-Factor Authentication (MFA), Identity Protection, Privileged Identity Management (PIM), Access Reviews, and Identity Governance.
- Support Microsoft Defender, Purview, Intune, and cloud security posture management initiatives.
- Monitor and improve Microsoft Secure Score and overall security compliance posture.
- Plan and execute phishing simulation campaigns.
- Analyse security awareness campaign results and prepare management reports.
- Support security awareness and cyber education initiatives.
- Support operational readiness and continuous improvement activities for ISO 27001.
- Assist with audit preparation, evidence collection, and control validation.
- Participate in risk assessments, policy reviews, security compliance activities, and governance initiatives.
Qualifications and Experience
- Bachelor's degree in Information Technology, Cyber Security, Computer Science, or a related discipline.
- Minimum 5 years of experience in Cyber Security, Security Engineering, Security Operations, or a related technical security role.
- Experience in security operations, vulnerability management, incident response, and cloud security.
- Demonstrated experience working collaboratively across Infrastructure, Development, Cloud, DevOps, and Business teams.
- Strong hands‑on experience with Microsoft Entra ID / Azure AD, including Conditional Access, MFA, Identity Protection, Privileged Identity Management (PIM), Access Reviews, and Identity Governance.
- Experience with Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps.
- Experience with Microsoft Purview, Data Loss Prevention (DLP), Information Protection, Sensitivity Labels, Microsoft Secure Score, and Microsoft Intune.
- Experience with firewalls and IDS/IPS technologies.
- Working knowledge of Windows and Linux server operating systems.
- Experience with vulnerability management platforms such as Orca, Qualys, Tenable, Rapid7, or similar tools.
- Experience with Endpoint Detection and Response (EDR) solutions, including Sophos or similar technologies.
- Experience with Cloudflare security services, cloud security, and SaaS security controls.
- Knowledge of scripting and automation using PowerShell, Python, Bash, or similar languages is highly regarded.
- Experience with SIEM, SOAR, threat intelligence, and security monitoring platforms is advantageous.
- Experience supporting ISO 27001, NIST CSF, or similar security frameworks is preferred.
- Exposure to AWS and Azure cloud security services is advantageous.
- Security+, CISSP, or equivalent security certifications are highly regarded.
- Strong analytical, problem‑solving, communication, and stakeholder management skills.
- Demonstrated commitment to ongoing professional development and staying current with emerging cyber security threats and technologies.
Work Setup & Schedule
Work Setup: Home-based / Remote
Work Schedule: Monday to Friday, 7:00 AM – 4:00 PM Manila Time
Must have a reliable internet connection with a minimum speed of 20 Mbps.
Must be willing to undergo a background check as part of the recruitment process.
Recruitment Process
As part of our recruitment process, we conduct a background check on all hired candidates. Please ensure that all required documents are prepared and submitted promptly.