Security Vulnerability Engineer
3 days ago
The Tech Security Engineer – VAPT is responsible for assessing and strengthening the organization's security
posture by conducting vulnerability assessments and penetration testing (VAPT) across infrastructure, networks,
and applications (Web, Mobile, Client-Server). This role involves identifying, analyzing, and mitigating security
vulnerabilities, ensuring compliance with security standards, and proactively reducing risks. The engineer will utilize
security tools and methodologies, collaborate with stakeholders, and drive remediation efforts to enhance the
organization's overall security resilience.
- Conduct regular vulnerability assessments for infrastructure, network, and application (Web, Mobile, Client-
Server) environments. - Perform black-box, white-box, and gray-box penetration testing to uncover security flaws.
- Perform application security testing using methodologies to identify application/software vulnerabilities such as:
- Static Application Security Testing (SAST) for code vulnerabilities.
- Dynamic Application Security Testing (DAST) for runtime vulnerabilities.
- Software Composition Analysis (SCA) for open-source dependency risks.
- Interactive Application Security Testing (IAST) combining SAST and DAST for CI/CD pipeline.
- Assess wireless networks, APIs, databases, and IoT devices for security weaknesses.
- Execute penetration testing activities to uncover exploitable vulnerabilities.
- Point person for external security testing (VAPT) to be performed by a 3rd party vendor or group-initiated
security testing.
- Conduct Red Team engagements to simulate real-world cyber threats and evaluate an organization's
detection and response capabilities. - Perform attack simulations using techniques from MITRE ATT&CK, TTPs, and APT methodologies.
- Develop and execute custom exploits, lateral movement tactics, and privilege escalation techniques.
- Collaborate with the Blue Team/SOC to assess Threat Detection, Incident Response, and Cyber Resilience.
- Utilize security tools (e.g., Burp Suite, Kali, Frida, Rapid7, Nessus, Qualys, Metasploit, OWASP ZAP, Nmap,
Wireshark, Checkmarx, Fortify, Acunetix). - Automate security testing in CI/CD pipelines (DevSecOps).
- Maintain penetration testing frameworks and develop custom security scripts and exploits.
- Participate in incident response activities by analyzing vulnerabilities exploited in real-time attacks.
- Support forensic analysis, malware reverse engineering, and threat hunting.
- Work with SOC, IT, and Security Operations teams to contain, eradicate, and recover from security incidents.
- Provide security recommendations and lessons learned post-incident to improve overall security posture.
- Identify and prioritize security vulnerabilities based on risk impact and exploitability.
- Develop detailed assessment reports, outlining findings, risk ratings, and remediation plans.
- Ensure security testing aligns with industry frameworks and regulatory standards (e.g., ISO 27001, NIST,
PCI-DSS, GDPR, MAS TRM, CIS Benchmarks). - Conduct third-party security assessments and validate vendor security compliance.
- Assist in audit and compliance efforts by providing security assessment reports and mitigation evidence.
- Develop and deliver security awareness programs to educate employees on cybersecurity best practices.
- Conduct simulated phishing campaigns and social engineering tests to assess awareness levels.
- Train development and IT teams on secure coding practices, vulnerability mitigation, and security
operations. - Create and distribute security bulletins, newsletters, and case studies to highlight emerging threats.
- Develop and maintain security assessment methodologies, playbooks, and Red Team strategies.
- Prepare technical and executive reports on security findings, recommendations, and mitigation strategies.
- Present assessment results for senior management, security teams, and business units.
REQUIREMENTS:
Proven experience (5+ years) in a VAPT role or similar position.
Advance penetration testing, bypassing security controls.
Experience in reverse engineering, exploitation, malware analysis, threat
emulation, persistence techniques, and lateral movement.
Hands-on experience techniques, tools, and process for exploitation.
Excellent problem-solving and analytical skills.
Strong communication and collaboration abilities.
-
Vulnerability Remediation Specialist
15 hours ago
Manila, National Capital Region, Philippines Private Advertiser Full timeThe Private Advertiser team is seeking a highly skilled vulnerability remediation specialist to help us strengthen our security posture. In this role, you will be responsible for identifying and exploiting vulnerabilities in our systems, infrastructure, and applications, and providing actionable recommendations for remediation.Essential Skills and...
-
Vulnerability Remediation Specialist
3 days ago
Manila, National Capital Region, Philippines Copeland Philippines, Inc. Full timeCybersecurity Threat Analyst Job DescriptionCopeland Philippines, Inc. is looking for a skilled Cybersecurity Threat Analyst to help strengthen its cybersecurity posture.The ideal candidate will have experience with threat analysis, incident response, and security information and event management (SIEM) systems.Key Responsibilities:Monitor security tools and...
-
Vulnerability Assessment Expert
3 days ago
Manila, National Capital Region, Philippines YONDU INC. Full timeAbout YONDU INC.YONDU INC. is a pioneering technology company that delivers innovative cybersecurity solutions to protect businesses and organizations from emerging threats.Job DescriptionWe are seeking a skilled Vulnerability Assessment Expert to join our team as a Security Vulnerability Engineer. The ideal candidate will have a strong background in...
-
Cyber Security Engineer
3 days ago
Manila, National Capital Region, Philippines Sysgen RPO, Inc. Full timeJOB DESCRIPTIONPosition Title: Cybersecurity EngineerReporting Relationships: Reports to IT Operations Head / Security Operations Center HeadJob Summary: The Cybersecurity Engineer will be responsible for designing, implementing, and maintaining security measures to protect our network, systems, and data. This role involves collaborating with other IT teams,...
-
Network Vulnerability Consultant
4 days ago
Manila, National Capital Region, Philippines Razr Corp Full timeWe're seeking a Network Vulnerability Consultant to join our team at Razr Corp. As a key member, you'll play a crucial role in identifying and addressing potential security vulnerabilities within our systems and networks.Your responsibilities will include conducting thorough vulnerability assessments, simulating real-world cyber-attacks, and providing...
-
Cloud Security Engineer
4 days ago
Manila, National Capital Region, Philippines Avature Full timeAbout the Role: We are seeking a skilled Cloud Security Engineer to join our team. As an IAM Engineer, you will play a crucial role in ensuring the security and integrity of our clients' cloud-based systems.Your Responsibilities: Collaborate with Technical Resources, IT, and business teams to analyze security risks, define requirements, and ensure compliance...
-
Information Security Engineer
4 days ago
Manila, National Capital Region, Philippines Metacom Careers Full timeDirect message the job poster from Metacom CareersSourcing Specialist Team Lead | Proficient in Candidate Sourcing & ScreeningUrgent Hiring: Information Security Engineer (Mid-Senior) | Hybrid (Makati)Level: Mid-SeniorSalary Range:Mid-Level: PHP 50K - 70KSenior-Level: PHP 70K - 100KAbout the RoleMetacom Solutions is seeking a highly skilled Information...
-
Information Security Engineer
4 days ago
Manila, National Capital Region, Philippines Metacom Careers Full timeUrgent Hiring: Information Security Engineer (Mid-Senior) | Hybrid (Makati)Level: Mid-SeniorSalary Range:Mid-Level: PHP 50K - 70KSenior-Level: PHP 70K - 100KAbout the RoleMetacom Solutions is seeking a highly skilled Information Security Engineer to strengthen security measures, ensure compliance, and lead vulnerability management efforts. This role is ideal...
-
Application Security Engineer
5 hours ago
Manila, National Capital Region, Philippines Alchemy Insights, LLC Full timeThe Role As an Application Security Engineer at Alchemy, you'll be responsible for building and maintaining the security of our web applications and APIs. You'll work closely with development teams to ensure security is built into our products from the ground up while developing tools and automation to scale our security efforts.What You'll DoLead security...
-
Security Analyst
3 days ago
Manila, National Capital Region, Philippines Copeland Philippines, Inc. Full timeJob PurposeAs a Security Analyst, you will be a key member of our Global Cybersecurity Team, helping to strengthen Copeland's cybersecurity posture. This role involves monitoring tools and dashboards, identifying and mitigating security vulnerabilities, and collaborating with teams to address risks effectively. You will also contribute to continuously...
-
Vulnerability Management Expert
1 day ago
Manila, National Capital Region, Philippines Monroe Consulting Group Full timeWe are seeking a highly skilled Digital Security Specialist to join our client's dynamic team in Ortigas, Pasig.About the Job:The Digital Security Specialist will play a critical role in safeguarding the organization's digital assets by proactively identifying and mitigating potential vulnerabilities.Key Responsibilities:Cybersecurity Threat...
-
Vulnerability Assessment Expert
3 days ago
Manila, National Capital Region, Philippines Pointwest Innovations Corp. Full timeVulnerability Assessment and Penetration TestingWe are seeking an experienced Cybersecurity Specialist 2 to join our team at Pointwest Innovations Corp. The ideal candidate will have a strong background in vulnerability assessment and penetration testing, with experience working with various audit tools and technologies. The successful candidate will be...
-
Application Vulnerability Assessor
7 days ago
Manila, National Capital Region, Philippines YONDU INC. Full timeSecurity Testing RoleAs a seasoned Application Vulnerability Assessor, you will be responsible for identifying and remediating vulnerabilities in application source code. Your expertise in SAST and DAST tools will enable you to design and implement effective security testing processes, ensuring the integrity of our applications.About the RoleYou will work...
-
Vulnerability Assessment Expert
2 hours ago
Manila, National Capital Region, Philippines TGI Full timeJob Summary:Trends Group Inc. is looking for a highly skilled Vulnerability Assessment Expert to join our team. In this role, you will be responsible for simulating real-world cyber-attacks to identify potential weaknesses.Key Responsibilities:Deliver high-quality services to clients with the goal of ensuring customer satisfaction.Plan and execute...
-
Malware Security Engineer
1 week ago
Manila, National Capital Region, Philippines JK Network Services Full timeSecurity Malware Engineer COMPANY PROFILE: An IT Consultancy company that is renowned worldwide professional services organization that assists the world's top businesses, governments, and other organizations construct and optimize their digital cores.Position: Security Malware EngineerCompany Industry: IT CompanyWork Location: Taguig/Quezon City Work...
-
IT Security Threat Analyst
3 days ago
Manila, National Capital Region, Philippines Copeland Philippines, Inc. Full timeJob SummaryCopeland Philippines, Inc. is seeking a skilled IT Security Threat Analyst to help strengthen its cybersecurity posture.The ideal candidate will have experience with threat analysis, incident response, and security information and event management (SIEM) systems.Key Responsibilities:Monitor security tools and dashboards to identify...
-
Cloud Security Test Engineer
7 days ago
Manila, National Capital Region, Philippines YONDU INC. Full timeJob SummaryWe are seeking an experienced Cloud Security Test Engineer to join our team. In this role, you will be responsible for designing and implementing cloud-based security testing processes to identify vulnerabilities in application source code.About the RoleYour primary focus will be on leveraging automated dynamic application security testing (DAST)...
-
Senior Information Security Engineer
4 days ago
Manila, National Capital Region, Philippines Metropolitan Bank & Trust Company Full timeMetrobank seeks a highly skilled cybersecurity professional to join our teamWe are a leading financial institution that prides itself on being at the forefront of innovation and technology. Our commitment to excellence and customer satisfaction drives us to continuously improve our services and processes. As a result, we seek a dedicated and experienced...
-
Malware Security Engineer
4 weeks ago
Manila, National Capital Region, Philippines JK Network Services Full timeSecurity Malware Engineer COMPANY PROFILE: An IT Consultancy company that is renowned worldwide professional services organization that assists the world's top businesses, governments, and other organizations construct and optimize their digital cores.Position: Security Malware EngineerCompany Industry: IT CompanyWork Location: Taguig/Quezon City Work...
-
Secure Software Developer
7 days ago
Manila, National Capital Region, Philippines Manpower Philippines Full timeAbout Our Ideal CandidateWe are looking for a Secure Software Developer with a strong background in application security and software engineering.The successful candidate will be responsible for:Secure Development Practices: Conducting security testing, developing secure coding standards, and performing manual code reviewsTooling and Automation: Configuring...