Security Vulnerability Engineer

3 days ago


Manila, National Capital Region, Philippines YONDU INC. Full time

The Tech Security Engineer – VAPT is responsible for assessing and strengthening the organization's security
posture by conducting vulnerability assessments and penetration testing (VAPT) across infrastructure, networks,
and applications (Web, Mobile, Client-Server). This role involves identifying, analyzing, and mitigating security
vulnerabilities, ensuring compliance with security standards, and proactively reducing risks. The engineer will utilize
security tools and methodologies, collaborate with stakeholders, and drive remediation efforts to enhance the
organization's overall security resilience.

1. Security Testing and Vulnerability Assessment:
  1. Conduct regular vulnerability assessments for infrastructure, network, and application (Web, Mobile, Client-
    Server) environments.
  2. Perform black-box, white-box, and gray-box penetration testing to uncover security flaws.
  3. Perform application security testing using methodologies to identify application/software vulnerabilities such as:
    1. Static Application Security Testing (SAST) for code vulnerabilities.
    2. Dynamic Application Security Testing (DAST) for runtime vulnerabilities.
    3. Software Composition Analysis (SCA) for open-source dependency risks.
    4. Interactive Application Security Testing (IAST) combining SAST and DAST for CI/CD pipeline.
  4. Assess wireless networks, APIs, databases, and IoT devices for security weaknesses.
  5. Execute penetration testing activities to uncover exploitable vulnerabilities.
  6. Point person for external security testing (VAPT) to be performed by a 3rd party vendor or group-initiated
    security testing.
2. Red Teaming & Adversary Simulations
  1. Conduct Red Team engagements to simulate real-world cyber threats and evaluate an organization's
    detection and response capabilities.
  2. Perform attack simulations using techniques from MITRE ATT&CK, TTPs, and APT methodologies.
  3. Develop and execute custom exploits, lateral movement tactics, and privilege escalation techniques.
  4. Collaborate with the Blue Team/SOC to assess Threat Detection, Incident Response, and Cyber Resilience.
3. Security Tool Management & Automation
  1. Utilize security tools (e.g., Burp Suite, Kali, Frida, Rapid7, Nessus, Qualys, Metasploit, OWASP ZAP, Nmap,
    Wireshark, Checkmarx, Fortify, Acunetix).
  2. Automate security testing in CI/CD pipelines (DevSecOps).
  3. Maintain penetration testing frameworks and develop custom security scripts and exploits.
4. Incident Response & Incident Management
  1. Participate in incident response activities by analyzing vulnerabilities exploited in real-time attacks.
  2. Support forensic analysis, malware reverse engineering, and threat hunting.
  3. Work with SOC, IT, and Security Operations teams to contain, eradicate, and recover from security incidents.
  4. Provide security recommendations and lessons learned post-incident to improve overall security posture.
5. Risk Analysis & Compliance
  1. Identify and prioritize security vulnerabilities based on risk impact and exploitability.
  2. Develop detailed assessment reports, outlining findings, risk ratings, and remediation plans.
  3. Ensure security testing aligns with industry frameworks and regulatory standards (e.g., ISO 27001, NIST,
    PCI-DSS, GDPR, MAS TRM, CIS Benchmarks).
  4. Conduct third-party security assessments and validate vendor security compliance.
  5. Assist in audit and compliance efforts by providing security assessment reports and mitigation evidence.
6. Security Awareness & Training
  1. Develop and deliver security awareness programs to educate employees on cybersecurity best practices.
  2. Conduct simulated phishing campaigns and social engineering tests to assess awareness levels.
  3. Train development and IT teams on secure coding practices, vulnerability mitigation, and security
    operations.
  4. Create and distribute security bulletins, newsletters, and case studies to highlight emerging threats.
7. Reporting and Remediation:
  1. Develop and maintain security assessment methodologies, playbooks, and Red Team strategies.
  2. Prepare technical and executive reports on security findings, recommendations, and mitigation strategies.
  3. Present assessment results for senior management, security teams, and business units.

REQUIREMENTS:

Proven experience (5+ years) in a VAPT role or similar position.
Advance penetration testing, bypassing security controls.
Experience in reverse engineering, exploitation, malware analysis, threat
emulation, persistence techniques, and lateral movement.
Hands-on experience techniques, tools, and process for exploitation.
Excellent problem-solving and analytical skills.
Strong communication and collaboration abilities.

#J-18808-Ljbffr

  • Manila, National Capital Region, Philippines Private Advertiser Full time

    The Private Advertiser team is seeking a highly skilled vulnerability remediation specialist to help us strengthen our security posture. In this role, you will be responsible for identifying and exploiting vulnerabilities in our systems, infrastructure, and applications, and providing actionable recommendations for remediation.Essential Skills and...


  • Manila, National Capital Region, Philippines Copeland Philippines, Inc. Full time

    Cybersecurity Threat Analyst Job DescriptionCopeland Philippines, Inc. is looking for a skilled Cybersecurity Threat Analyst to help strengthen its cybersecurity posture.The ideal candidate will have experience with threat analysis, incident response, and security information and event management (SIEM) systems.Key Responsibilities:Monitor security tools and...


  • Manila, National Capital Region, Philippines YONDU INC. Full time

    About YONDU INC.YONDU INC. is a pioneering technology company that delivers innovative cybersecurity solutions to protect businesses and organizations from emerging threats.Job DescriptionWe are seeking a skilled Vulnerability Assessment Expert to join our team as a Security Vulnerability Engineer. The ideal candidate will have a strong background in...


  • Manila, National Capital Region, Philippines Sysgen RPO, Inc. Full time

    JOB DESCRIPTIONPosition Title: Cybersecurity EngineerReporting Relationships: Reports to IT Operations Head / Security Operations Center HeadJob Summary: The Cybersecurity Engineer will be responsible for designing, implementing, and maintaining security measures to protect our network, systems, and data. This role involves collaborating with other IT teams,...


  • Manila, National Capital Region, Philippines Razr Corp Full time

    We're seeking a Network Vulnerability Consultant to join our team at Razr Corp. As a key member, you'll play a crucial role in identifying and addressing potential security vulnerabilities within our systems and networks.Your responsibilities will include conducting thorough vulnerability assessments, simulating real-world cyber-attacks, and providing...


  • Manila, National Capital Region, Philippines Avature Full time

    About the Role: We are seeking a skilled Cloud Security Engineer to join our team. As an IAM Engineer, you will play a crucial role in ensuring the security and integrity of our clients' cloud-based systems.Your Responsibilities: Collaborate with Technical Resources, IT, and business teams to analyze security risks, define requirements, and ensure compliance...


  • Manila, National Capital Region, Philippines Metacom Careers Full time

    Direct message the job poster from Metacom CareersSourcing Specialist Team Lead | Proficient in Candidate Sourcing & ScreeningUrgent Hiring: Information Security Engineer (Mid-Senior) | Hybrid (Makati)Level: Mid-SeniorSalary Range:Mid-Level: PHP 50K - 70KSenior-Level: PHP 70K - 100KAbout the RoleMetacom Solutions is seeking a highly skilled Information...


  • Manila, National Capital Region, Philippines Metacom Careers Full time

    Urgent Hiring: Information Security Engineer (Mid-Senior) | Hybrid (Makati)Level: Mid-SeniorSalary Range:Mid-Level: PHP 50K - 70KSenior-Level: PHP 70K - 100KAbout the RoleMetacom Solutions is seeking a highly skilled Information Security Engineer to strengthen security measures, ensure compliance, and lead vulnerability management efforts. This role is ideal...


  • Manila, National Capital Region, Philippines Alchemy Insights, LLC Full time

    The Role As an Application Security Engineer at Alchemy, you'll be responsible for building and maintaining the security of our web applications and APIs. You'll work closely with development teams to ensure security is built into our products from the ground up while developing tools and automation to scale our security efforts.What You'll DoLead security...

  • Security Analyst

    3 days ago


    Manila, National Capital Region, Philippines Copeland Philippines, Inc. Full time

    Job PurposeAs a Security Analyst, you will be a key member of our Global Cybersecurity Team, helping to strengthen Copeland's cybersecurity posture. This role involves monitoring tools and dashboards, identifying and mitigating security vulnerabilities, and collaborating with teams to address risks effectively. You will also contribute to continuously...


  • Manila, National Capital Region, Philippines Monroe Consulting Group Full time

    We are seeking a highly skilled Digital Security Specialist to join our client's dynamic team in Ortigas, Pasig.About the Job:The Digital Security Specialist will play a critical role in safeguarding the organization's digital assets by proactively identifying and mitigating potential vulnerabilities.Key Responsibilities:Cybersecurity Threat...


  • Manila, National Capital Region, Philippines Pointwest Innovations Corp. Full time

    Vulnerability Assessment and Penetration TestingWe are seeking an experienced Cybersecurity Specialist 2 to join our team at Pointwest Innovations Corp. The ideal candidate will have a strong background in vulnerability assessment and penetration testing, with experience working with various audit tools and technologies. The successful candidate will be...


  • Manila, National Capital Region, Philippines YONDU INC. Full time

    Security Testing RoleAs a seasoned Application Vulnerability Assessor, you will be responsible for identifying and remediating vulnerabilities in application source code. Your expertise in SAST and DAST tools will enable you to design and implement effective security testing processes, ensuring the integrity of our applications.About the RoleYou will work...


  • Manila, National Capital Region, Philippines TGI Full time

    Job Summary:Trends Group Inc. is looking for a highly skilled Vulnerability Assessment Expert to join our team. In this role, you will be responsible for simulating real-world cyber-attacks to identify potential weaknesses.Key Responsibilities:Deliver high-quality services to clients with the goal of ensuring customer satisfaction.Plan and execute...


  • Manila, National Capital Region, Philippines JK Network Services Full time

    Security Malware Engineer COMPANY PROFILE: An IT Consultancy company that is renowned worldwide professional services organization that assists the world's top businesses, governments, and other organizations construct and optimize their digital cores.Position: Security Malware EngineerCompany Industry: IT CompanyWork Location: Taguig/Quezon City Work...


  • Manila, National Capital Region, Philippines Copeland Philippines, Inc. Full time

    Job SummaryCopeland Philippines, Inc. is seeking a skilled IT Security Threat Analyst to help strengthen its cybersecurity posture.The ideal candidate will have experience with threat analysis, incident response, and security information and event management (SIEM) systems.Key Responsibilities:Monitor security tools and dashboards to identify...


  • Manila, National Capital Region, Philippines YONDU INC. Full time

    Job SummaryWe are seeking an experienced Cloud Security Test Engineer to join our team. In this role, you will be responsible for designing and implementing cloud-based security testing processes to identify vulnerabilities in application source code.About the RoleYour primary focus will be on leveraging automated dynamic application security testing (DAST)...


  • Manila, National Capital Region, Philippines Metropolitan Bank & Trust Company Full time

    Metrobank seeks a highly skilled cybersecurity professional to join our teamWe are a leading financial institution that prides itself on being at the forefront of innovation and technology. Our commitment to excellence and customer satisfaction drives us to continuously improve our services and processes. As a result, we seek a dedicated and experienced...


  • Manila, National Capital Region, Philippines JK Network Services Full time

    Security Malware Engineer COMPANY PROFILE: An IT Consultancy company that is renowned worldwide professional services organization that assists the world's top businesses, governments, and other organizations construct and optimize their digital cores.Position: Security Malware EngineerCompany Industry: IT CompanyWork Location: Taguig/Quezon City Work...


  • Manila, National Capital Region, Philippines Manpower Philippines Full time

    About Our Ideal CandidateWe are looking for a Secure Software Developer with a strong background in application security and software engineering.The successful candidate will be responsible for:Secure Development Practices: Conducting security testing, developing secure coding standards, and performing manual code reviewsTooling and Automation: Configuring...