Application Security Engineer
2 hours ago
Be #InGoodHands with Metrobank
Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development. With Metrobank, a meaningful life is within your reach
Job Summary:
Develop and enforce security plans and standards; ensures that application security best practices are executed and implemented. Prepare the plans to deliver/implement the application security strategy prepared by the Security Architect. Provide support to the Security Architect in enterprise security projects including defining configuration standards, testing and implementation. Leads the research, evaluation and implementation of ISD security tools and small projects. Provide risk assessment support to CPSD and SQRD related to architecture for security concerns and/or security controls to be architected. Maintain and mature the security tools to ensure effective prevention and detection of incidents. Prepare the necessary documentation for project approval and implementation. Act as the subject matter expert on security of assigned technology domain/area (i.e., mobile application, web application, etc.).
Specific Duties & Responsibilities:
· Based on the approved IT security systems and application security architecture, develops detailed designs for implementation.
· Formulate, review and maintain IT security policies, technical standards, internal ISD procedures and guidelines related to securing the information processing environment, IT facilities and connected third party services/providers of the Bank.
· Provide support to CPSD and SQRD, serve as the security subject matter expert related to application security. Identify security design gaps in existing application systems and proposed architectures and recommend changes or enhancements.
· Evaluate cost-effective solutions and prepare the business case for IT security projects.
· Manage the testing of technical controls and monitors its implementation.
· Define and document security tool/device standard configuration parameters. Ensures that application security tools are securely configured and functions effectively and efficiently.
· Perform regular security configuration reviews, ensure efficacy of controls and use is optimized.
· Monitor and if necessary, assist ITG administrators in ensuring problems of security devices/systems are timely resolved.
· Review and/or evaluate vendor performance as part of VPRC process.
· Review installation and changes to CI/CD pipeline.
· Manages the implementation of baseline system security standards for application development.
· Collaborates and coordinates with other ISD Departments to ensure that holistic ISD service is provided to internal customers.
· Establish disaster recovery strategy of security tools implemented and ensures it is regularly tested for effectiveness.
· Stay up to date with latest security technology and trends, vulnerabilities and threats.
· Guide Infrastructure Security Specialists; review their work.
· Proactively works with the SAID Head in implementing programs for the continuous improvement of the bank's information security plans and strategies.
· Perform other information security governance, risk and compliance related duties and responsibilities as directed by the SAID Head.
Job Specifications:
· Graduate of any college degree in Computer Science or Information Security, or related technical field of expertise.
· Extensive/in-depth knowledge and understanding of secure coding principles and OWASP Top 10.
· Working experiences with designing/architecting CI/CD pipeline.
· Certification may include SANS GIAC, CISSP, CISM, GWAPT, or equivalent.
· At least 3+ years' experience in designing, implementing and maintaining application security solutions such as SAST, DAST, IAST, etc.
· Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action
· Scripting and programming – computer programming and scripting skills is an advantage.
· Strong written and oral communication skills to write technical reports on their assessments and communicate potential security weaknesses.
· Should also be abreast with security best practices and knowledge of common and emerging security threats.
· Self-starter, result-orientated in terms of disposition for corrective action to drive the remediation to reduce the risk exposure of the bank.
· Have good teamwork and collaboration skills: good team players with the ability to lead security initiatives.
· Good project management skills to lead and manage accomplishments of assigned tasks/projects within the predetermined time-frame
· Good communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.
-
Security Engineer
1 hour ago
Taguig, National Capital Region, Philippines Globe Telecom Full time ₱1,000,000 - ₱2,010,000 per yearAt Globe, our goal is to create a wonderful world for our people, business, and nation. By uniting people of passion who believe they can make a difference, we are confident that we can achieve this goal.Job DescriptionLeads the design, implementation, and optimization of security capabilities. Builds reusable modules and self-service tooling to make it...
-
Security Operations Engineer
1 week ago
Taguig, National Capital Region, Philippines WTW Full time ₱900,000 - ₱1,200,000 per yearDescriptionThe RoleAs a Security Operations Engineer, you will analyze software designs and implementations from a security perspective and identify and propose resolutions to security issues.You will include the appropriate security analysis, tooling and techniques to uncover InfoSec vulnerabilities, both static and dynamically, in our software...
-
Offensive Security Engineer
3 hours ago
Taguig, National Capital Region, Philippines Secuna Full time ₱30,000 - ₱90,000 per yearOFFENSIVE SECURITY ENGINEER (JUNIOR, MID & SENIOR)What we're looking for:Secuna is the leading offensive security platform, empowering organizations of all sizes to proactively identify and properly eliminate security vulnerabilities before they can be exploited by malicious threat actors and become an even more expensive problem.We are looking for...
-
Security Engineer
2 weeks ago
Taguig, National Capital Region, Philippines NRI Australia & New Zealand Full time ₱1,200,000 - ₱2,400,000 per yearThe OpportunityThis role offers the opportunity to strengthen enterprise security by managing vulnerabilities, incidents, and critical security systems across cloud, network, and endpoint environments. You'll work closely with vendors, cross-functional teams, and senior executives, ensuring proactive risk management and effective security...
-
Tech Security Engineer
2 weeks ago
Taguig, National Capital Region, Philippines Bershaw Consultancy Full time ₱1,500,000 - ₱2,500,000 per yearThe Technology Security Incident & Event Management (SIEM) Manager is responsible for managing the security incidents and events within an organization's technology infrastructure.This individual is responsible for monitoring, detecting, and responding to security incidents and events that could affect the confidentiality, integrity, or availability of the...
-
Cyber Security Engineer
2 hours ago
Taguig, National Capital Region, Philippines Spruson & Ferguson Full time $55,000 - $70,000 per yearAbout the RoleAs a motivatedCyber Security Engineerwho is joining our global security team under thisnewly created rolein our Philippines office, you will have hands-on experience with security tools and the ability to engineer solutions to mitigate risks. In this role you will be primarily responsible for designing, implementing, and maintaining robust...
-
IT Security Engineer
3 hours ago
Taguig, National Capital Region, Philippines EPS Staffing Service Group Inc Full time ₱720,000 - ₱1,440,000 per yearJob Type: Permanent (Full time)Work Arrangement: Hybrid (8 times RTO per month. Must be amenable to render overtime, work on weekends, and/or PH holidays if needed);Office Location: Taguig, BGCWork Schedule: Morning shift (8AM or 9AM), meetings in the evening occasionallySummaryTo oversee and serve as a technical resource for all assessment activities...
-
Security Engineering Lead
4 hours ago
Taguig, National Capital Region, Philippines Google Operations Center Full time ₱120,000 - ₱180,000 per yearJoin UsAt Google Operations Center we help Google users and customers solve problems and achieve their goals—all while enjoying a culture focused on improving continuously and being better together. We work hard, we play hard, and we want you to join usThe mission of Trust & Safety - Safe Browsing is to make the world's information safely accessible to...
-
Security VAPT Engineer
3 hours ago
Taguig, National Capital Region, Philippines Ben Edictio Corporated Full time ₱720,000 - ₱1,200,000 per yearThis is Direct Hire Permanent to our clientSalary offer depends on your experiences and skills. They will assess you. The salary range on this post is not the actual budget of our client but our idea only. Client may still negotiate with you.Position: Security Vulnerability and Penetration Testing (VAPT) EngineerWork Schedule: Morning shift (Shift starts:...
-
Taguig, National Capital Region, Philippines HCM Nexus Consulting Inc. Full time ₱1,200,000 - ₱2,400,000 per yearSecurity Vulnerability and Penetration Testing EngineerWork Setup: Hybrid (8x onsite per month - BGC, Taguig)Schedule: Morning shift (8:00 AM - 5:00 PM or 9:00 AM – 6:00 PM)Must be amenable to render overtime, work on weekends and/or Philippine holidays if needed.About the RoleThe Security Vulnerability and Penetration Testing Engineer is responsible for...