application security engineer

3 days ago


Taguig, National Capital Region, Philippines Metrobank Full time

Press Tab to Move to Skip to Content Link

Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development. With Metrobank, a meaningful life is within your reach

Job Summary

Develop and enforce security plans and standards; ensures that application security best practices are executed and implemented. Prepare the plans to deliver/implement the application security strategy prepared by the Security Architect. Provide support to the Security Architect in enterprise security projects including defining configuration standards, testing and implementation. Lead the research, evaluation and implementation of ISD security tools and small projects. Provide risk assessments support to CPSD and SQRD related to architecture for security concerns and/or security controls to be architected. Maintain and mature the security tools to ensure effective prevention and detection of incidents. Prepare the necessary documentation for project approval and implementation. Act as the subject matter expert on security of assigned technology domain/area (i.e., mobile application, web application, etc.).

Role Exposure

  1. Based on the approved IT security systems and application security architecture, develop detailed designs for implementation.
  2. Formulate, review and maintain IT security policies, technical standards, internal ISD procedures and guidelines related to securing the information processing environment, IT facilities and connected third party services/providers of the Bank.
  3. Provide support to CPSD and SQRD, serve as the security subject matter expert related to application security. Identify security design gaps in existing application systems and proposed architectures and recommend changes or enhancements.
  4. Evaluate cost-effective solutions and prepare the business case for IT security projects.
  5. Manage the testing of technical controls and monitor its implementation.
  6. Define and document security tool/device standard configuration parameters. Ensure that application security tools are securely configured and function effectively and efficiently.
  7. Perform regular security configuration reviews, ensure efficacy of controls and use is optimized.
  8. Monitor and if necessary, assist ITG administrators in ensuring problems of security devices/systems are timely resolved.
  9. Review and/or evaluate vendor performance as part of VPRC process.
  10. Review installation and changes to CI/CD pipeline.
  11. Manage the implementation of baseline system security standards for application development.
  12. Collaborate and coordinate with other ISD Departments to ensure that holistic ISD service is provided to internal customers.
  13. Establish disaster recovery strategy of security tools implemented and ensure it is regularly tested for effectiveness.
  14. Stay up to date with latest security technology and trends, vulnerabilities and threats.
  15. Guide Infrastructure Security Specialists; review their work.
  16. Proactively work with the SAID Head in implementing programs for the continuous improvement of the bank's information security plans and strategies.
  17. Perform other information security governance, risk and compliance related duties and responsibilities as directed by the SAID Head.

Qualification

  1. Graduate of any college degree in Computer Science or Information Security, or related technical field of expertise.
  2. Extensive/in-depth knowledge and understanding of secure coding principles and OWASP Top 10.
  3. Working experiences with designing/architecting CI/CD pipeline.
  4. Certification may include SANS GIAC, CISSP, CISM, GWAPT, or equivalent.
  5. At least 3+ years' experience in designing, implementing and maintaining application security solutions such as SAST, DAST, IAST, etc.
  6. Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action.
  7. Scripting and programming – computer programming and scripting skills is an advantage.
  8. Strong written and oral communication skills to write technical reports on their assessments and communicate potential security weaknesses.
  9. Should also be abreast with security best practices and knowledge of common and emerging security threats.
  10. Self-starter, result-oriented in terms of disposition for corrective action to drive the remediation to reduce the risk exposure of the bank.
  11. Have good teamwork and collaboration skills: good team players with the ability to lead security initiatives.
  12. Good project management skills to lead and manage accomplishments of assigned tasks/projects within the predetermined time-frame.
  13. Good communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.
#J-18808-Ljbffr

  • Taguig, National Capital Region, Philippines Asurion Full time

    The Application Security Engineer will assist Asurion in developing secure products by providing best-in-class application security services to the product development organization. This role is responsible for proactively working with our product team to build secure software, validating code level compliance with security standards, assessing applications...


  • Taguig, National Capital Region, Philippines GCash Full time

    Head of Application Security EngineeringGCashNegotiableOn-site - Taguig 1-3 Yrs Exp Diploma Full-timeJob DescriptionDo you want to take the first step in making Filipinos' lives better every day? Here in GCash, we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation G ka...


  • Taguig, National Capital Region, Philippines Manpower (Philippines) Full time

    Head of Application Security EngineeringBe among the first 25 applicantsWorking set-up: Hybrid (2x WFH per week)Working schedule: Monday to Friday (Dayshift)Required Qualifications:Technical Expertise:Proven experience in application security, secure software development, or a related field.Hands-on experience with security tools (e.g., SAST/DAST, IAST,...


  • Taguig, National Capital Region, Philippines GCash Full time

    On-site - Taguig Fresh Graduate/Student Bachelor Full-timeJob DescriptionDo you want to take the first step in making Filipinos' lives better every day? Here in GCash, we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation G ka ba? Join the G Nation todayKey...


  • Taguig, National Capital Region, Philippines Nityo Infotech Full time

    Nityo Infotech is seeking an experienced Advanced Web Application Security Engineer to join our team. In this role, you will be responsible for designing and implementing secure web applications.About the Role:You will work closely with our development team to design and implement secure web applications that meet the highest standards of...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    At Metrobank, we believe in empowering our employees to become future leaders. As an Application Security Engineer, you will play a vital role in enhancing our information processing environment, IT facilities, and connected third-party services/providers.About the RoleWe are seeking a skilled individual to develop and enforce security plans and standards....


  • Taguig, National Capital Region, Philippines Asurion Full time

    Job DescriptionWe're looking for an experienced Application Penetration Tester to join our team at Asurion. In this role, you will be responsible for performing comprehensive application and system penetration tests to identify vulnerabilities and risks within our products and enterprise systems.About YouYou have a strong background in computer science or...


  • Taguig, National Capital Region, Philippines Manpower (Philippines) Full time

    Strategic Security Engineering DirectorWe are seeking a Strategic Security Engineering Director to lead our application security efforts. The successful candidate will have extensive experience in application security, secure software development, and related fields.The ideal candidate will have a strong understanding of security tools such as SAST/DAST,...


  • Taguig, National Capital Region, Philippines GCash Full time

    Head of Security Intelligence and EngineeringGCashNegotiableOn-site - Taguig 3-5 Yrs Exp Bachelor Full-timeJob DescriptionDo you want to take the first step in making Filipinos' lives better every day? Here in GCash, we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation...


  • Taguig, National Capital Region, Philippines Metrobank Full time

    What We OfferWe offer a range of benefits to our employees, including opportunities for growth and development, competitive salaries, and a comprehensive benefits package.As an Application Security Engineer, you will have the opportunity to work on exciting projects, collaborate with other departments, and contribute to the continuous improvement of our...


  • Taguig, National Capital Region, Philippines Manpower (Philippines) Full time

    Director of Application Security and ComplianceWe are seeking a seasoned professional to lead our application security engineering team as a Director of Application Security and Compliance. The successful candidate will have a proven track record in application security, secure software development, and related fields.The ideal candidate will have hands-on...


  • Taguig, National Capital Region, Philippines Manpower (Philippines) Full time

    Chief Information Security Officer for ApplicationsWe are seeking a skilled Chief Information Security Officer (CISO) to lead our application security efforts. The successful candidate will have extensive experience in application security, secure software development, and related fields.The ideal candidate will have a strong understanding of security tools...


  • Taguig, National Capital Region, Philippines Asurion Full time

    About the RoleThis position is responsible for assisting Asurion in developing secure products by providing best-in-class application security services to the product development organization. The successful candidate will collaborate with product teams to build secure software solutions, analyze code level compliance with security standards, and identify...


  • Taguig, National Capital Region, Philippines Willis Towers Watson Full time

    ResponsibilitiesThe Penetration Tester will be responsible for conducting vulnerability assessments, penetration testing, security analysis, reporting and documentation, remediation support, and maintaining an ethical approach.Vulnerability Assessment: Identifying security vulnerabilities in web applications and infrastructure.Penetration Testing: Performing...


  • Taguig, National Capital Region, Philippines Willis Towers Watson Full time

    ResponsibilitiesThe End User Computing Security Operations Engineer is responsible for:Providing Operational Engineering and support against global End User Computing platforms with a specific slant towards security solutions.Maintaining and administering endpoint security controls and policies, focusing on day-to-day operations, troubleshooting, and...


  • Taguig, National Capital Region, Philippines BCS Technology International Pty Ltd Full time

    Web Application Security Expert JobBCS Technology International is seeking a Web Application Security Expert to join our team.The ideal candidate will have a strong background in web security, threat modeling, and security operations, with deep knowledge of both Linux systems and AWS networking. Key responsibilities include securing web applications,...


  • Taguig, National Capital Region, Philippines Asurion Full time

    Job SummaryThe Application Security Engineer will play a critical role in developing secure products at Asurion. This position is responsible for providing best-in-class application security services to the product development organization, ensuring that software applications are built with robust security measures.Key Responsibilities:Collaborate with...


  • Taguig, National Capital Region, Philippines Asurion Full time

    Join Our TeamWe're looking for an experienced Application Penetration Tester to join our team at Asurion. In this role, you will be responsible for performing comprehensive application and system penetration tests to identify vulnerabilities and risks within our products and enterprise systems.About YouYou have a strong background in computer science or...


  • Taguig, National Capital Region, Philippines Universal Access and Systems Solutions Inc. Full time

    **Job Description**Universal Access and Systems Solutions Inc. is hiring a skilled Cyber Security Engineer to help us maintain the security and integrity of our network. In this role, you will be responsible for ensuring compliance with network standards and best practices.Key Responsibilities:Evaluate and recommend network security protocols and...

  • Chief Risk Officer

    2 hours ago


    Taguig, National Capital Region, Philippines Nityo Infotech Full time

    Nityo Infotech is currently looking for a Chief Risk Officer - Application Security to play a key role in ensuring the security and integrity of our systems. If you have a passion for information security and are looking for a challenging opportunity, please consider applying for this position.About the Role:The successful candidate will be responsible for...