Threat Modeling Engineer – Application Security

Manulife/John Hancock

Manila

Hybrid

PHP 1,000,000 - 1,800,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Manulife/John Hancock is seeking an experienced Application Security Engineer specializing in threat modeling to partner with engineering, architecture, product and risk teams. You will lead threat modeling engagements, translate threats into practical security requirements, and drive mitigations through the SDLC in a hybrid Manila-based role.

The role requires strong technical judgment, facilitation, and the ability to explain complex risks to technical and business stakeholders.

Qualifications

  • Bachelor’s degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or related field.
  • At least five years of relevant experience across threat modeling, application security, security architecture, secure software development, cloud security, or a related discipline.
  • Demonstrated experience leading collaborative threat modeling or secure design reviews for applications, APIs, cloud-native systems, distributed architectures, or third-party integrations.
  • Ability to analyze architectures and data flows, identify trust boundaries and attack paths, prioritize material threats, and translate findings into testable requirements and practical mitigations.
  • Practical knowledge of at least one established threat modeling method, such as STRIDE, attack trees, abuse cases, PASTA, or LINDDUN, with the ability to select and adapt methods for different engagements.
  • Working knowledge of application and API security, identity and access management, data protection, cloud and network architecture, containers, distributed systems, and common attack techniques.
  • Familiarity with relevant standards and frameworks, including OWASP guidance, MITRE ATT&CK, and the NIST Secure Software Development Framework.
  • Amenable to work at UP Ayala Technohub, Quezon City, under a hybrid arrangement with three onsite days per week.

Responsibilities

  • Independently lead threat modeling engagements for applications, APIs, cloud services, third-party integrations, and significant technology changes from early design through implementation.
  • Work with engineering and architecture teams to define scope and document system components, assets, data flows, entry points, trust boundaries, dependencies, and key assumptions.
  • Apply an appropriate threat modeling approach, such as STRIDE, attack trees, abuse cases, PASTA, or LINDDUN, based on the system, risk, and business context.
  • Assess threats using likelihood, impact, exploitability, asset criticality, existing controls, and business context; document clear, defensible risk decisions.
  • Translate identified threats into practical security requirements, design recommendations, test criteria, and remediation actions, and track them through closure or formal risk acceptance.
  • Provide governance and quality oversight at key stages of the threat modeling process, confirming that scope, assets, threats, mitigations, and supporting evidence are complete and aligned with security standards.
  • Embed threat modeling into architecture reviews, agile delivery, change management, security testing, penetration testing, and other Secure SDLC activities.
  • Maintain and improve standards, templates, threat libraries, secure design patterns, and reusable mitigation guidance; identify opportunities for automation and self-service adoption.
  • Coach delivery teams, review the quality and coverage of threat models, identify recurring design risks, and communicate outcomes, exceptions, and trends to technical and business stakeholders.
  • Produce accurate service metrics and reporting that demonstrate delivery performance, adoption, quality, mitigation follow-through, and measurable risk reduction.

Skills

Threat modeling
Application security
Security architecture
Secure SDLC
Communication

Education

Bachelor's degree in Computer Science or related field

Tools

Microsoft Threat Modeling Tool
OWASP Threat Dragon
IriusRisk
pytm
Visio

Job description

Manulife/John Hancock is seeking an experienced Application Security Engineer specializing in threat modeling to partner with engineering, architecture, product and risk teams. You will lead threat modeling engagements, translate threats into practical security requirements, and drive mitigations through the SDLC in a hybrid Manila-based role.

The role requires strong technical judgment, facilitation, and the ability to explain complex risks to technical and business stakeholders.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Modeling Lead - Application Security (Hybrid)
Threat Modeling Lead - Application Security (Hybrid)

Manulife group • Quezon City

Hybrid
PHP 900,000 - 1,700,000
Hybrid work arrangement
Senior Threat Modeling Engineer — Application Security
Senior Threat Modeling Engineer — Application Security

Manulife • Manila

Hybrid
PHP 900,000 - 1,500,000
Application Security Engineer (Threat Modeling)
Application Security Engineer (Threat Modeling)

Manulife group • Quezon City

On-site
PHP 900,000 - 1,700,000
Hybrid work arrangement
Application Security Engineer Threat Modeling
Application Security Engineer Threat Modeling

Manulife • Manila

Hybrid
PHP 900,000 - 1,500,000
Lead AppSec Engineer: AI-Driven Security & Threat Modeling
Lead AppSec Engineer: AI-Driven Security & Threat Modeling

Manulife IT Delivery Center Asia Inc. • Philippines

On-site
PHP 1,200,000 - 1,800,000
Application Security QA Engineer — Pen Test Report Quality
Application Security QA Engineer — Pen Test Report Quality

Manulife/John Hancock • Manila

Hybrid
PHP 900,000 - 1,300,000
Hybrid work arrangement
Security Engineer
Security Engineer

Manulife IT Delivery Center Asia Inc. • Makati

On-site
PHP 1,200,000 - 1,800,000
Penetration Tester
Penetration Tester

Manulife group • Quezon City

Hybrid
PHP 900,000 - 1,500,000
Application Security QA Engineer for Risk & Remediation
Application Security QA Engineer for Risk & Remediation

Manulife group • Quezon City

Hybrid
PHP 900,000 - 1,500,000
Application Security QA Analyst – Penetration Testing
Application Security QA Analyst – Penetration Testing

Manulife • Manila

Hybrid
PHP 900,000 - 1,500,000