Security Engineer
On-sitePasig City, Metro Manila, Philippines
Job Summary
Conduct penetration testing of Web and Mobile applications and own the vulnerability management lifecycle from identification through remediation. Perform active monitoring of operational security risks, conduct technical investigations on incidents, and liaise with users on security enquiries during pre-sales and support. Collaborate with engineering and DevOps teams to implement security best practices, automate vulnerability detection, and facilitate threat modelling within the software development lifecycle. Work with certification bodies for ISO 27001 and SOC Type 2 controls while delivering security awareness training. Requires five years of application security experience, proficiency with tools like Burpsuite and AWS, and a strong sense of ownership.
Required Qualifications
- At least 5 years of experience in application security testing and assessments
- Solid understanding of cybersecurity principles, standards and protocols such as OWASP Top 10 and SANS Critical Security Controls
- Experience with application security tools as Burpsuite, OWASP ZAP, Metasploit, Sonarqube
- Experience with programming languages such as Java, JavaScript, C/C++
- Experience with scripting languages such as bash or Powershell
- Experience and knowledge of cloud solutions and architectures such as AWS
- Experience and knowledge of Security information and event management (SIEM) technologies
- Good analytical skills
- Strong sense of ownership
- Successful completion of background check
- NBI clearance
Desired Qualifications
- experience with Ghidra or IDA
- Technical and industry certifications such as CISA, CISM, CISSP
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.