Offensive Security Officer

2 weeks ago


Taguig, National Capital Region, Philippines Metrobank Full time
Metrobank Metrobank gives meaning to your financial journey with these broad range of products and services. Start your journey to meaningful banking now.

View company page

Plan, document test methodologies and perform penetration testing or ethical hacking of network infrastructure, application systems including mobile applications all in a stealthy operation without being detected, in order to identify potential security weaknesses in the system. Collaborate with ITG developers by communicating the back doors/security weaknesses identified and providing inputs in correcting the security flaws. Establish red team procedures in conducting red team exercises.

Specific Duties & Responsibilities:

  • Perform threat analysis, wireless network assessments, and social-engineering assessments including physical security assessments to develop test scenarios.
  • Conduct network and system security scans. Perform manual and automated hacking techniques on network infrastructure, computer systems, web and mobile applications. Search for weaknesses and recommend corrective measures to prevent potential attacks.
  • Evade intrusion prevention systems, intrusion detection systems, firewalls, and honeypots to ensure they are effective and reinforced when necessary.
  • Identify methods and entry points that attackers may use to exploit vulnerabilities or weaknesses
  • Develop abuse cases and testing methods to identify vulnerabilities in business logic. Develop/update scripts/tools to enhance penetration testing processes.
  • Research, evaluate, document and discuss findings with IT teams and management. Collaborate with IT teams to remediate the vulnerabilities.
  • Effectively communicate findings and remediation strategy to stakeholders. Develop comprehensive and accurate reports and presentations for both technical and executive audiences.
  • Review, verify and provide feedback on information security fixes.
  • Establish improvements for existing security services, including hardware, software, policies and procedures.
  • Observe business continuity and its operations when performing testing (i.e. minimize downtime and loss of employee productivity).
  • Stay updated on the latest malware and security threats.
  • Assist in cyber security investigations.
  • Recognize the safe utilization of attacker tools, tactics, and procedures.
  • Keep abreast with the latest attack vectors, hacking methods, ethical hacking/pen testing techniques and new penetration testing tools.
  • Analyze security policies and configurations for effectiveness against an attack and make necessary suggestions on security policy and configuration improvements.
  • Proactively works with the Department Head in implementing programs for the continuous improvement of the bank's information security plans and strategies.
  • Perform other information security governance, risk and compliance related duties and responsibilities as directed by the Department Head.

Job Summary:

Plan, document test methodologies and perform penetration testing or ethical hacking of network infrastructure, application systems including mobile applications all in a stealthy operation without being detected, in order to identify potential security weaknesses in the system. Collaborate with ITG developers by communicating the back doors/security weaknesses identified and providing inputs in correcting the security flaws. Establish red team procedures in conducting red team exercises.

Specific Duties & Responsibilities:

· Perform threat analysis, wireless network assessments, and social-engineering assessments including physical security assessments to develop test scenarios.

· Conduct network and system security scans. Perform manual and automated hacking techniques on network infrastructure, computer systems, web and mobile applications. Search for weaknesses and recommend corrective measures to prevent potential attacks.

· Evade intrusion prevention systems, intrusion detection systems, firewalls, and honeypots to ensure they are effective and reinforced when necessary.

· Identify methods and entry points that attackers may use to exploit vulnerabilities or weaknesses

· Develop abuse cases and testing methods to identify vulnerabilities in business logic. Develop/update scripts/tools to enhance penetration testing processes.

· Research, evaluate, document and discuss findings with IT teams and management. Collaborate with IT teams to remediate the vulnerabilities.

· Effectively communicate findings and remediation strategy to stakeholders. Develop comprehensive and accurate reports and presentations for both technical and executive audiences.

· Review, verify and provide feedback on information security fixes.

· Establish improvements for existing security services, including hardware, software, policies and procedures.

· Observe business continuity and its operations when performing testing (i.e. minimize downtime and loss of employee productivity).

· Stay updated on the latest malware and security threats.

· Assist in cyber security investigations.

· Recognize the safe utilization of attacker tools, tactics, and procedures.

· Keep abreast with the latest attack vectors, hacking methods, ethical hacking/pen testing techniques and new penetration testing tools.

· Analyze security policies and configurations for effectiveness against an attack and make necessary suggestions on security policy and configuration improvements.

· Proactively works with the Department Head in implementing programs for the continuous improvement of the bank's information security plans and strategies.

· Perform other information security governance, risk and compliance related duties and responsibilities as directed by the Department Head.

Job Specifications:

· Graduate of any college degree in Computer Science or Information Security, Cybersecurity or related technical field of expertise.

· Strong understanding of vulnerabilities, common attack vectors and has attacker mindset: ability to think about creative threats and attack vectors.

· Full knowledge and understanding of OWASP Top 10 Application Security best practices.

· Certification may include SANS GPEN, GWAP, OSCP, CEH or equivalent.

· Technical knowledge and experience in ethical hacking.

· Advanced computer skills – extensive computer skills and an understanding of networking fundamental, including forensics, reverse engineering, web applications, databases, and wireless technologies.

· Scripting and programming –scripting skills to infiltrate any system.

· Clear understanding of how computer security breaches can disrupt business, including the financial implications.

· Highly analytical with exceptional problem-solving skills.

· Result-orientated in terms of disposition for corrective action to drive the remediation to reduce the risk exposure of the bank.

· Have good teamwork and collaboration skills: a good team players with the ability to lead security initiatives

· Good written and verbal communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.

· Possess excellent time management skills, thrive in a fast paced demanding environment

· Be a self-managed, self-starter with good organizational skills.

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr

  • Taguig, National Capital Region, Philippines Apple Inc. Full time

    Software is often referred to as the "soul" of Apple's products. In this position you will play a critical role in ensuring the security of the systems and infrastructure used to manage, build, and distribute, Apple's software.We are looking for a proficient Embedded Security Engineer to join our team and contribute to the protection of our critical assets....


  • Taguig, National Capital Region, Philippines Cardinal Health Full time

    Security (Information & Communication Technology) What Information Security and Risk contributes to Cardinal HealthInformation Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    Metrobank Metrobank gives meaning to your financial journey with these broad range of products and services. Start your journey to meaningful banking now. View company page Formulate and recommend information security policies and procedures to meet the bank's information security objectives and ensure effective implementation. Monitor the accomplishments...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    Security Assurance and Assessment Officer Metrobank Metrobank gives meaning to your financial journey with these broad range of products and services. Start your journey to meaningful banking now. View company page Develop tactical plans and programs for the establishment and maintenance of the Bank's third party information security risk management...


  • Taguig, National Capital Region, Philippines Citigroup Inc. Full time

    Info Sec Analyst - Cyber SecurityAs a bank with a brain and a soul, Citi creates economic value that is systemically responsible and in our clients' best interests. As a financial institution that touches every region of the world and every sector that shapes your daily life, our Enterprise Operations & Technology teams are charged with a mission that rivals...

  • Penetration Tester

    2 weeks ago


    Taguig, National Capital Region, Philippines Nityo Infotech Full time

    The RequirementsMinimum Criteria:Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.Technical Knowledge: A strong understanding of web technologies, programming...


  • Taguig, National Capital Region, Philippines Eteam Workforce Full time

    Job Qualification:Bachelor's/College degree graduate.Background on quality Assurance or Administrative experience Technical Skills RequiredBasic proficiency with office software like Microsoft Office, Google Docs, and any relevant industry specific programs.Process excellence trainingCoaching experienceLaptop ProvidedHYBRID (1 Day office and 4 days WFH)Job...

  • Penetration Tester

    2 weeks ago


    Taguig, National Capital Region, Philippines Nityo Infotech Full time

    The RequirementsMinimum Criteria:Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education requirements.Technical Knowledge: A strong understanding of web technologies, programming...


  • Taguig, National Capital Region, Philippines ING Full time

    Title:FMSecurities Overview: You will work in the dynamic world of Financial Markets and will focus on Operations. The Global Service Organization Financial Markets is one of three locations globally responsible for the processing of all trades concluded by ING Front Office traders globally. Although you will need to complete daily tasks individually, the...


  • Taguig, National Capital Region, Philippines ING Full time

    Title:FMSecurities Overview: You will work in the dynamic world of Financial Markets and will focus on Operations. The Global Service Organization Financial Markets is one of three locations globally responsible for the processing of all trades concluded by ING Front Office traders globally. Although you will need to complete daily tasks individually, the...

  • Penetration Tester

    2 weeks ago


    Taguig, National Capital Region, Philippines Nityo Infotech Full time

    LOCATION:TaguigSCHEDULE:UK Shift 4pm to 1amWORK SETUP:Remote (will report to office as a needed basis only)QUALIFICATIONS: Education: A bachelor's degree in a related field such as computer science, information security, or cybersecurity is commonly preferred, but not always mandatory. Relevant industry experience can compensate for formal education...


  • Taguig, National Capital Region, Philippines Goodyear Dunlop Tires Germany GmbH Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: IAM / IT Risk and Security Senior Analyst Location: Taguig, 00, PH Company: Goodyear Location: PH - Philippines - A510 Goodyear Talent Acquisition Representative: Dan Dave Alberto Sponsorship Available: No Relocation Assistance Available: No Position...

  • Penetration Tester

    2 weeks ago


    Taguig, National Capital Region, Philippines weSource Management Consultancy Firm Full time

    The Role A penetration tester is responsible for assessing the security of web applications and its underlying infrastructure to identify vulnerabilities and weaknesses that could be exploited by attackers. Their role involves conducting thorough assessments and penetration tests to uncover potential security risks and provide recommendations for mitigation....

  • Penetration Tester

    2 weeks ago


    Taguig, National Capital Region, Philippines Nityo Infotech Services Philippines Inc. Full time

    Location: BGC, Taguig (WFH, will report onsite as needed only)Schedule: UK Shift - 4 pm - 1 amThe RoleA penetration tester is responsible for assessing the security of web applications and its underlying infrastructure to identify vulnerabilities and weaknesses that could be exploited by attackers. Their role involves conducting thorough assessments and...


  • Taguig, National Capital Region, Philippines foodpanda Full time

    Job DescriptionSupports the Workspace Manager in maintaining the overall appearance of the foodpanda office.Will serve as the company's Safety Officer, responsible for ensuring adherence to safety regulations and fostering a culture of safety throughout the organization.Coordinates with the third party service providers for housekeeping, security, and...


  • Taguig, National Capital Region, Philippines The Philippine Stock Exchange, Inc. Full time

    Compliance & Risk (Banking & Financial Services) The Risk Officer would primarily be responsible for assisting the Head of the Risk Management Office in the implementation of the Enterprise Risk Management Framework of the Exchange, as well as in the updating, review, and testing of the Business Continuity Management Policy and Plans of the Exchange. The...

  • Associate Director

    2 weeks ago


    Taguig, National Capital Region, Philippines NCC Group Philippines Full time

    Role: Associate Director, Cybersecurity, Offensive SecurityLocation: Taguig, City (Hybrid set up)Thanks for checking out our job opening; we are excited that you are interested in learning more about NCC Group.We are on a mission to make society a safer and more secure place. Our people are the ones who make that possible; a global community of talented...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    Press Tab to Move to Skip to Content Link Implementation Officer (Transaction Banking - Taguig) Be #InGoodHands with MetrobankHere at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the...

  • Senior HR Officer

    2 weeks ago


    Taguig, National Capital Region, Philippines Dreamspace Technology Solutions Inc. Full time

    Consulting & Generalist HR (Human Resources & Recruitment) Join Dreamscape, Inc., a start-up company that is revolutionizing the global payment platform with security, speed, cost-efficiency and innovation. We are looking for talented and driven Human Resources professionals who share our vision and passion.Position Overview:We are seeking a proactive and...


  • Taguig, National Capital Region, Philippines EastWest Bank Full time

    About the Job Location: Bonifacio Global City (BGC) Corporate Title: Investment Banking Officer Work Arrangement: Hybrid Our Financial Markets and Wealth Management Group is looking for experienced professionals to join us at our Bonifacio Global City (BGC) site in the role of Investment Banking Officer. As an Investment Banking Officer, you help manage...