Application Security
3 hours ago
Be #InGoodHands with Metrobank
Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development. With Metrobank, a meaningful life is within your reach
Job Title: Application Security
Job Summary:
Develop and enforce security plans and standards; ensures that application security best practices are executed and implemented. Prepare the plans to deliver/implement the application security strategy prepared by the Security Architect. Provide support to the Security Architect in enterprise security projects including defining configuration standards, testing and implementation. Leads the research, evaluation and implementation of ISD security tools and small projects. Provide risk assessment support to CPSD and SQRD related to architecture for security concerns and/or security controls to be architected. Maintain and mature the security tools to ensure effective prevention and detection of incidents. Prepare the necessary documentation for project approval and implementation. Act as the subject matter expert on security of assigned technology domain/area (i.e., mobile application, web application, etc.).
Specific Duties & Responsibilities:
- Based on the approved IT security systems and application security architecture, develops detailed designs for implementation.
- Formulate, review and maintain IT security policies, technical standards, internal ISD procedures and guidelines related to securing the information processing environment, IT facilities and connected third party services/providers of the Bank.
- Provide support to CPSD and SQRD, serve as the security subject matter expert related to application security. Identify security design gaps in existing application systems and proposed architectures and recommend changes or enhancements.
- Evaluate cost-effective solutions and prepare the business case for IT security projects.
- Manage the testing of technical controls and monitors its implementation.
- Define and document security tool/device standard configuration parameters. Ensures that application security tools are securely configured and functions effectively and efficiently.
- Perform regular security configuration reviews, ensure efficacy of controls and use is optimized.
- Monitor and if necessary, assist ITG administrators in ensuring problems of security devices/systems are timely resolved.
- Review and/or evaluate vendor performance as part of VPRC process.
- Review installation and changes to CI/CD pipeline.
- Manages the implementation of baseline system security standards for application development.
- Collaborates and coordinates with other ISD Departments to ensure that holistic ISD service is provided to internal customers.
- Establish disaster recovery strategy of security tools implemented and ensures it is regularly tested for effectiveness.
- Stay up to date with latest security technology and trends, vulnerabilities and threats.
- Guide Infrastructure Security Specialists; review their work.
- Proactively works with the SAID Head in implementing programs for the continuous improvement of the bank's information security plans and strategies.
- Perform other information security governance, risk and compliance related duties and responsibilities as directed by the SAID Head.
Job Specifications:
- Graduate of any college degree in Computer Science or Information Security, or related technical field of expertise.
- Extensive/in-depth knowledge and understanding of secure coding principles and OWASP Top 10.
- Working experiences with designing/architecting CI/CD pipeline.
- Certification may include SANS GIAC, CISSP, CISM, GWAPT, or equivalent.
- At least 3+ years' experience in designing, implementing and maintaining application security solutions such as SAST, DAST, IAST, etc.
- Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action
- Scripting and programming – computer programming and scripting skills is an advantage.
- Strong written and oral communication skills to write technical reports on their assessments and communicate potential security weaknesses.
- Should also be abreast with security best practices and knowledge of common and emerging security threats.
- Self-starter, result-orientated in terms of disposition for corrective action to drive the remediation to reduce the risk exposure of the bank.
- Have good teamwork and collaboration skills: good team players with the ability to lead security initiatives.
- Good project management skills to lead and manage accomplishments of assigned tasks/projects within the predetermined time-frame
- Good communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts
-
Application Security SME
2 hours ago
Manila, National Capital Region, Philippines Socium - Teams Done Differently Full time ₱1,500,000 - ₱3,000,000 per yearWhy explore this opportunity?One of the key advantages of applying through us isdirect access to hiring managers. After our quick discussion about the opportunity, we candirectly endorse your profileto the hiring team, ensuring it gets the visibility it deserves. This role offers a100% direct employment setup,meaning your contract and salary will be managed...
-
Security Officer
4 hours ago
Manila, National Capital Region, Philippines LanceSoft, Inc. Full time ₱1,500,000 - ₱2,500,000 per yearGreetings From LanceSoftLocation: ManilaOn-site SetupPermanent RoleRole: Security OfficerInsurance Industry experienceKey ResponsibilitiesFocuses on Core BISO activities:Conduct Information Security Business Impact Assessments (ISBIA) for Projects, Applications, and Third-Party Outsourcing arrangements, aligning with Singlife Standards. Collaborate with...
-
Security Consultant
3 hours ago
Manila, National Capital Region, Philippines NCC Group Full time ₱900,000 - ₱1,200,000 per yearAs a Security Consultant, you will play a key role in delivering high-quality technical security assessments for prominent clients worldwide. Your responsibilities will include:Executing technical tasks across a variety of penetration testing and security assessment engagements.Delivering high-quality technical solutions and actionable risk mitigation...
-
Senior Security Analyst
4 hours ago
Manila, National Capital Region, Philippines Converge ICT Solutions Inc. Full time ₱60,000 - ₱120,000 per yearJob SummaryWe are seeking a dedicated and experienced Senior Security Analyst to be our subject matter expert for Application Security and DevSecOps. In this hands-on technical role, you will act as a critical bridge between our cybersecurity team and our development and operations teams. Your mission will be to champion and integrate security practices...
-
Application Developer
2 weeks ago
Manila, National Capital Region, Philippines MEGA PRIME FOODS INCORPORATED Full time ₱600,000 - ₱800,000 per yearKey ResponsibilitiesApplication Development & Coding · Write clean, efficient, and well-documented code in accordance with design specifications.Unit & Integration Testing · Develop and execute comprehensive test cases to verify code quality, functionality, and system integration.Defect Identification & Resolution · Collaborate with the QA team to...
-
Security Analyst
4 hours ago
Manila, National Capital Region, Philippines Infor Full time $50,000 - $1,000,000 per yearGeneral informationCountryPhilippinesCityManilaJob ID46793DepartmentDevelopmentExperience LevelMID_SENIOR_LEVELEmployment StatusFULL_TIMEWorkplace TypeHybridDescription & RequirementsThe Security Analyst role will function as an Application Security Analyst for the Infor Landmark Product. This role is responsible for performing threat intelligence analyses,...
-
Security Analyst
2 weeks ago
Manila, National Capital Region, Philippines Cambridge University Press & Assessment Full time ₱60,000 - ₱81,000 per yearSalary:₱60,000 - ₱81,000- Location:Manila- Country:Philippines- Business Unit:Technology- Vacancy Type:Permanent- Closing Date:8 November 2025Meet the recruiterBeige SalesWork setup: We operate in a hybrid work environment, and we encourage applicants who are open to working in the office two days a week to apply.Work schedule: 15:00 to 23:00 Manila...
-
Application Engineer
2 weeks ago
Manila, National Capital Region, Philippines Vault Cloud Full time ₱600,000 - ₱1,200,000 per yearVault Cloud is the national leader of providing highly secure and scalable sovereign cloud capability to the Australian Government, National Intelligence Community and Critical Infrastructure sector. We pioneered the development of Australia's only sovereign, hyperscale cloud with security at its core, being one of the first cloud organisations to be...
-
Security Consultant
2 weeks ago
Manila, National Capital Region, Philippines Zone IT Solutions Full time ₱40,000 - ₱80,000 per yearZone IT Solutions is seeking an experienced Security Consultant. In this role, you will provide expert advice and guidance on a range of security issues, helping to improve our clients' security posture and compliance.RequirementsResponsibilities:Assess clients' security policies, systems, and controls to identify vulnerabilities and areas for improvement,...
-
Cloud Security
1 week ago
Manila, National Capital Region, Philippines Russell Tobin Full time ₱1,200,000 - ₱2,400,000 per yearWE ARE HIRING Job Title: Cloud Security - SMELocation: Metro Manila, PhilippinesEmployment Type: Onsite/OfficeEligibility: Only Filipino Citizens can applyExperience: yearsAbout the RoleWe are seeking experiencedCloud Security (SMEs)to join our dynamic team. In this role, you will leverage your expertise in multi-cloud security environments to safeguard our...