Senior Security Engineer

3 days ago


Taguig, National Capital Region, Philippines Carlson Wagonlit Travel (Hauptsitz Deutschland) CWT Beheermaatschappij B.V. Deutschland Full time

Job Description - Senior Security Engineer (2500004Q)

CWT is one of the world's leading digital travel management companies and as a Business-to-Business-for-Employees (B2B4E) travel management platform, companies and governments rely on us to keep their people connected – anywhere, anytime, anyhow – and across six continents, we provide their employees with innovative technology and an efficient, safe and secure travel experience.

Position Overview

The Sr Security Engineer for Application Security will lead CWT's application security efforts, overseeing security tools and initiatives that protect CWT applications from internal and external threats. The role will work closely with engineering, DevOps, and security teams to implement best practices and improve security posture.

Key Responsibilities:

  1. Security Tool Management:
    • Lead and manage Veracode platform for Static Application Security Testing (SAST), Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST), and Manual Penetration Testing (MPT).
    • Manage HashiCorp Vault to store sensitive application credentials and secrets securely.
    • Oversee the use of Fastly NGWAF and Salt Security platform to protect CWT applications from web and API-based attacks.
    • Administer and enhance BugCrowd's Bug Bounty and Vulnerability Disclosure Program.
  2. Secure Software Development Lifecycle (SDLC):
    • Integrate security into CI/CD pipelines to enforce secure coding standards.
    • Establish and maintain security coding guidelines for developers.
    • Provide security training and awareness for developers and DevOps teams.
  3. Vulnerability Management & Threat Mitigation:
    • Work with engineering teams to remediate vulnerabilities identified through automated security scans, bug bounties, and penetration tests.
    • Continuously enhance threat modeling processes for CWT applications.
    • Develop metrics and key performance indicators (KPIs) to measure application security effectiveness.
  4. Collaboration & Leadership:
    • Partner with development, DevOps, and infrastructure teams to ensure security is embedded in application architecture.
    • Provide guidance on regulatory compliance requirements related to application security.
    • Act as the primary escalation point for application security incidents.

Qualifications

Position Requirements
  • Bachelor's degree in Computer Science, Cybersecurity, or related field (or equivalent experience).
  • 5-10 years of experience in application security, DevSecOps, or software development.
  • Strong expertise in secure coding, threat modeling, and vulnerability management.
  • Proficiency in Veracode, HashiCorp Vault, Fastly NGWAF, Salt Security, and BugCrowd platforms.
  • Experience with API security, Web Application Firewalls (WAF), and container security.
  • Knowledge of SAST, DAST, SCA, penetration testing, and security automation.
  • Scripting and automation skills (Python, Bash, PowerShell, or similar languages).
  • Understanding of security compliance frameworks (PCI-DSS, SOC2, NIST, OWASP, GDPR, etc.)

Leadership

  • Strong problem-solving skills with a results-oriented mindset.
  • Ability to influence and guide development teams in adopting security best practices.
  • Strong communication and stakeholder management skills across multiple teams.
  • Ability to manage security projects, prioritize tasks, and drive security initiatives.

Relationship Management

  • Ability to manage senior relationships across all CWT organizations.
  • Ability to develop cooperative and constructive working relationships.
  • Ability to handle complaints, settle disputes and resolve conflicts and negotiate with others.
  • Collaborative team player orientation towards work relationships, strong culture awareness.

Project Oversight and Decision Making

  • Highly developed skills in priority setting and alignment of project priorities with Departmental strategy.
  • Ability to break down complex problems and projects into manageable goals.
  • Ability to get to the heart of the problem and make sound and timely decisions to resolve problems.
#J-18808-Ljbffr

  • Taguig, National Capital Region, Philippines CWTSatoTravel Full time

    Join to apply for the Senior Security Engineer role at CWTSatoTravelJob Description - Senior Security Engineer (2500004Q)CWT is one of the world's leading digital travel management companies and as a Business-to-Business-for-Employees (B2B4E) travel management platform, companies and governments rely on us to keep their people connected – anywhere,...


  • Taguig, National Capital Region, Philippines CWT Philippines, Inc. Full time

    CWTis one of the world's leading digital travel management companies and as a Business-to-Business-for-Employees (B2B4E) travel management platform, companies and governments rely on us to keep their people connected – anywhere, anytime, anyhow – and across six continents, we provide their employees with innovative technology and an efficient, safe and...


  • Taguig, National Capital Region, Philippines beBee Careers Full time

    Secure Application Engineer RoleThe position of a Secure Application Engineer is designed to lead CWT's application security efforts, overseeing security tools and initiatives that protect CWT applications from internal and external threats. The role will work closely with engineering, DevOps, and security teams to implement best practices and improve...


  • Taguig, National Capital Region, Philippines KMC Solutions Full time

    SummaryA new alliance is seeking a Senior Cloud Security Engineer to join its organization and Technical Support Team. The role involves providing world-class Managed Security, Consulting, and Cyber Threat Detection & Response Services to businesses and governments. You will manage and perform customer security support across various channels and...

  • Security Engineer

    4 weeks ago


    Taguig, National Capital Region, Philippines Globe Telecom Full time

    Security Engineer (DevSecOps/SRE) - ManagerJoin to apply for the Security Engineer (DevSecOps/SRE) - Manager role at Globe TelecomSecurity Engineer (DevSecOps/SRE) - Manager1 week ago Be among the first 25 applicantsJoin to apply for the Security Engineer (DevSecOps/SRE) - Manager role at Globe TelecomGet AI-powered advice on this job and more exclusive...


  • Taguig, National Capital Region, Philippines beBee Careers Full time

    Job SummaryThis Senior Security Engineer role is responsible for leading the application security efforts, overseeing security tools and initiatives that protect CWT applications from internal and external threats.The ideal candidate will have 5-10 years of experience in application security, DevSecOps, or software development, with a strong background in...

  • Senior IAM Engineer

    1 week ago


    Taguig, National Capital Region, Philippines beBee Careers Full time

    Job Title: Senior IAM Engineer - Security Solutions ArchitectJob SummaryWe are looking for an experienced Senior IAM Engineer to join our team as a Security Solutions Architect. In this role, you will be responsible for designing, implementing, and maintaining our IAM infrastructure, with a focus on security and compliance.Key ResponsibilitiesDesign and...

  • Security Engineer

    2 weeks ago


    Taguig, National Capital Region, Philippines Globe Telecom Full time

    Security Engineer (DevSecOps/SRE) - ManagerThis role requires a highly skilled professional with diverse technical abilities, blending DevSecOps, Platform Engineering, and Site Reliability Engineering (SRE) principles.Job DescriptionThe Security Engineer in this position will build and maintain secure, scalable infrastructure platforms, enhancing developer...


  • Taguig, National Capital Region, Philippines Nokia Full time

    Nokia Taguig, National Capital Region, PhilippinesJoin or sign in to find your next jobJoin to apply for the Senior Security Consultant role at NokiaNokia Taguig, National Capital Region, Philippines1 month ago Be among the first 25 applicantsJoin to apply for the Senior Security Consultant role at NokiaGet AI-powered advice on this job and more exclusive...


  • Taguig, National Capital Region, Philippines Nokia Full time

    Nokia Taguig, National Capital Region, PhilippinesJoin or sign in to find your next jobJoin to apply for the Senior Security Consultant role at NokiaNokia Taguig, National Capital Region, Philippines1 day ago Be among the first 25 applicantsJoin to apply for the Senior Security Consultant role at NokiaJob DescriptionThe Senior Security Consultant drives...