Senior Vulnerability Engineer

3 days ago


Makati City, National Capital Region, Philippines Avaloq Full time
Company Description

Founded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 12 countries, and more than 170 clients in 35 countries. We are an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and wealth managers, investment managers, as well as retail and neo banks. Our research led approach and continual innovation is powered by the passion and creativity of our colleagues.

We are always looking for talented people to join us on our mission to orchestrate the financial ecosystem and democratize access to wealth management. Avaloq offers the opportunity to work closely with some of the world's leading financial institutions as we jointly develop and shape careers. Championing a collaborative, supportive and flexible work environment empowers our colleagues to reach their full potential.

Job Description

We are seeking a Senior Vulnerability Management Engineer to lead and enhance our vulnerability detection and remediation capabilities across on-prem and cloud environments. This role is highly technical and sits at the core of our cyber defense function, ensuring full alignment with FINMA, DORA and MAS requirements in this key area of cyber risk. 

You will serve as our technical authority for Tenable instances, on prem and cloud, and drive engineering improvements, integration with ITSM system, and regulatory-grade reporting. 

Your Key Tasks 

  • Lead engineering, architecture, and advanced configuration of  / / Nessus across hybrid infrastructures. 
  • Oversee authenticated scanning across servers, cloud workloads, network appliances, databases, and container platforms. 
  • Integrate Tenable with enterprise systems (CMDB, SIEM, ITSM) using APIs and scripting (Python/PowerShell). 
  • Engineer cloud vulnerability coverage via connectors, agents, and container registry scans. 
  • Enhance detection accuracy through custom plugins, scan policy tuning, and automation pipelines. 
  • Provide technical leadership and guidance to remediation teams, ensuring adherence to CIS/NIST/SWIFT/ISO standards. 
  • Produce regulator-ready metrics, dashboards, and audit evidence for FINMA and MAS reviews. 
  • Contribute to security architecture, hardening initiatives, and continuous improvement of the vulnerability management program. 
Qualifications
  • Extensive hands-on experience with Tenable , , Nessus Manager). 
  • Deep technical expertise in vulnerability detection, authenticated scan engineering, and hybrid infrastructure scanning. 
  • Strong knowledge of networks, Windows/Linux, VMware, cloud platforms (AWS and OCI), and container ecosystems. 
  • Scripting and automation skills (Python, PowerShell, REST APIs). 
  • Solid understanding of security frameworks: CIS Benchmarks, ISO 27001, SWIFT CSCF, CSA CCM. 
  • Experience in FINMA, MAS and DORA regulated financial environments (banks, insurers, securities firms). 
  • Ability to communicate technical risk clearly to both engineers and senior management. 
  • Certifications: OCI Security Professional, Tenable Certified Engineer, CISSP 
  • Exposure to Kubernetes, Terraform/Ansible, CI/CD pipelines, and automated hardening tools. 
  • Experience leading vulnerability engineering. 
Additional Information

We realize that managing work life balance is a challenge we all face in our daily lives and in order to support with this we are pleased to offer hybrid and flexible working for most of our Avaloqers to maintain work life balance and still continue our fantastic Avaloq culture in our global offices. 

In Avaloq we are proud to embrace diversity and understand the success of our business is built on the power of different opinions, we are whole heartedly committed to fostering an equal opportunity environment and inclusive culture where you can be your true authentic self. 

We hire, compensate and promote regardless of origin, age, gender identity, sexual orientation or any other fantastic traits that make us all unique, we have done our best to write this advert in an inclusive and neutral way. 

Please be aware that we will not accept speculative CV submissions for any of our roles from recruitment agencies, and any unsolicited candidate submissions will be exempt from any payment expectations.  

#LI-Hybrid



  • Makati City, National Capital Region, Philippines Royal Caribbean Group Full time

    About the CompanyThe Threat & Vulnerability Management Engineer is responsible for the deployment, configuration, and management of vulnerability management tools and delivery of related services. The role of Threat & Vulnerability Management Engineer is to detect security vulnerabilities in information systems and drive resolution in compliance with...


  • Makati City, National Capital Region, Philippines Chevron Full time

    Total Number of Openings15The Vulnerability Management Analyst will drive change within vulnerability management. Lead in defining processes and tool recommendations needed to identify vulnerabilities, tests Chevron's digital security defenses, analyzes malicious code, and leverages all authorized resources and analytic techniques to secure Chevron's...

  • Vulnerability Manager

    5 hours ago


    Quezon City, National Capital Region, Philippines Advanced Energy Industries, Inc. Full time

    Position Title: Vulnerability ManagerAbout Advanced EnergyAdvanced Energy Industries, Inc. (NASDAQ: AEIS), enables design breakthroughs and drives growth for leading semiconductor and industrial customers. Our precision power and control technologies, along with our applications know-how, inspire close partnerships and innovation in thin-film and industrial...


  • Makati City, National Capital Region, Philippines Advanced Outsourcing and Business Services Inc. Full time

    Are you passionate about building secure software at scale? Do you thrive at the intersection of development and security? We are looking for a VAPT Officer (AppSec) to lead application security efforts and drive our DevSecOps evolution.In this role, you will work directly with the Head of IT Security to manage vulnerability assessments, oversee our global...


  • Makati City, National Capital Region, Philippines Corporate Executive Search, Inc. (CESI) Full time

    Are you passionate about building secure software at scale? Do you thrive at the intersection of development and security? We are looking for aVAPT Officer (AppSec)to lead application security efforts and drive our DevSecOps evolution.In this role, you will work directly with the Head of IT Security to manage vulnerability assessments, oversee our global...


  • Makati City, National Capital Region, Philippines Avaloq Full time

    Company DescriptionFounded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 10 countries, and more than 160 clients in 35 countries. We are an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and...

  • Systems Engineer

    6 hours ago


    Makati City, National Capital Region, Philippines Questronix Corporation Full time

    System Availability-Ensure assigned systems and applications are consistently available and operational within agreed service levels.System Performance-Maintain optimal performance of systems by regularly monitoring and addressing potential issues.Security Compliance-Implement and maintain security measures to protect systems from threats and...

  • DevSecOps Engineer

    6 hours ago


    Makati City, National Capital Region, Philippines Avaloq Full time

    Job DescriptionThe Avaloq Security team is an international team of analysts, senior and expert software engineers and architects. The Avaloq Security team develops and maintains central application security frameworks and tools for all companywide technology stacks and consults the business teams on best practice implementations for context specific...


  • Makati City, National Capital Region, Philippines Ebizolution Full time

    Senior Network Security Engineer (NSE) will play a critical role in designing, implementing, and managing the firewall infrastructure to protect Clients' network and sensitive information from cyber threats. NSE will work closely with cross-functional teams to assess security risks, develop firewall policies, and respond to security incidents.Work-from-home...

  • VAPT Engineer

    6 hours ago


    Makati City, National Capital Region, Philippines Trends Group, Inc. Full time

    I. PURPOSETo accomplish all assigned tasks by the management in a timely and effective manner as deemed necessary for the betterment of the organization as a whole.II. DUTIES AND RESPONSIBILITIESEnsure the execution of services within the allocated budget hours or parameters defined by the Service Level Agreement.Obtain professional certifications and...