
Application Security Engineer
14 hours ago
About This Job
We are seeking a Security Engineer with deep expertise in application security platforms to own, operate, and optimize our WAF, bot defense, API security, and application testing tools. This role will focus on ensuring these platforms are well-configured, continuously tuned, and delivering maximum security value with minimal business friction.
The Security Engineer will also serve as the incident response lead for application-layer attacks, participate in the on-call rotation, and work primarily during Pacific Time (PT) business hours to align with our operations.
Key Responsibilities
AppSec Tool Management & Optimization
Administer and tune Cloudflare WAF, maintaining rules, policies, and custom configurations.
Manage and optimize bot defense platforms (e.g., F5/Shape, Arkose) to mitigate automated fraud, scraping, and credential stuffing.
Oversee and tune API security solutions (e.g., Traceable) for visibility, anomaly detection, and protection.
Operate DAST and SAST platforms, ensuring they are integrated into CI/CD and providing actionable insights.
Security Operations & Incident Response
Lead response to AppSec-related incidents, including botnet activity, API abuse, and web exploitation attempts.
Participate in the on-call rotation, ensuring timely detection, escalation, and remediation of critical application security events.
Build playbooks for WAF/bot/API incident handling and drive continuous improvement of detection/response.
Collaborate with SOC, DevOps, and development teams to remediate issues and strengthen defenses.
Continuous Improvement
Tune tools to reduce false positives and improve detection accuracy.
Track tool coverage and effectiveness, providing metrics and reports to leadership.
Engage with vendors to leverage updates, intelligence feeds, and advanced features.
Collaboration & Governance
Partner with application teams to align security policies with business requirements.
Support compliance initiatives by ensuring tooling configurations meet regulatory/security standards.
Key Responsibilities
AppSec Tool Management & Optimization
Administer and tune Cloudflare WAF, maintaining rules, policies, and custom configurations.
Manage and optimize bot defense platforms (e.g., F5/Shape, Arkose) to mitigate automated fraud, scraping, and credential stuffing.
Oversee and tune API security solutions (e.g., Traceable) for visibility, anomaly detection, and protection.
Operate DAST and SAST platforms, ensuring they are integrated into CI/CD and providing actionable insights.
Security Operations & Incident Response
Lead response to AppSec-related incidents, including botnet activity, API abuse, and web exploitation attempts.
Participate in the on-call rotation, ensuring timely detection, escalation, and remediation of critical application security events.
Build playbooks for WAF/bot/API incident handling and drive continuous improvement of detection/response.
Collaborate with SOC, DevOps, and development teams to remediate issues and strengthen defenses.
Continuous Improvement
Tune tools to reduce false positives and improve detection accuracy.
Track tool coverage and effectiveness, providing metrics and reports to leadership.
Engage with vendors to leverage updates, intelligence feeds, and advanced features.
Collaboration & Governance
Partner with application teams to align security policies with business requirements.
Support compliance initiatives by ensuring tooling configurations meet regulatory/security standards.
Required Qualifications
4–6+ years of experience in information security or application security operations.
Hands-on experience with Cloudflare WAF (or equivalent enterprise WAF).
Experience managing bot defense tools (F5/Shape, Arkose, or similar).
Familiarity with API security solutions (Traceable, Salt, or similar).
Experience with DAST and/or SAST platforms in an enterprise environment.
Strong understanding of OWASP Top 10 and API Security Top 10 threats.
Background in incident response, particularly application and API security events.
Willingness to participate in an on-call rotation for AppSec-related incidents.
Ability to work Pacific Time (PT) business hours to support operational coverage.
Preferred Qualifications
Experience integrating AppSec tools into CI/CD pipelines.
Familiarity with SIEM/SOAR platforms for AppSec event enrichment and automation.
Knowledge of cloud security (AWS, Azure, GCP) in relation to web and API workloads.
Industry certifications (e.g., GWAPT, GWEB, CCSK, AWS Security Specialty) are a plus.
About Axos
Born digital-first, Axos delivers financial tools and services that allow individuals, small businesses, and companies to access and manage their money how, when, and where they want. We're a diverse team of dynamic, insightful, and independent innovators who are excited to provide technology-driven solutions that offer unbeatable value to our customers.
Axos Financial is our holding company and is publicly traded on the New York Stock Exchange under the symbol "AX" (NYSE: AX).
Learn More about working at Axos Business Center
Pre-Employment Background Check, Medical, and Drug Test:
All offers are contingent upon the candidate successfully passing a credit check, criminal background check, and pre-employment medical and drug screening.
Equal Employment Opportunity:
Axos is an Equal Opportunity employer. We are committed to providing equal employment opportunities to all employees and applicants without regard to race, religious creed, color, sex (including pregnancy, breast feeding and related medical conditions), gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship status, military and veteran status, marital status, age, protected medical condition, genetic information, physical disability, mental disability, or any other protected status in accordance with all applicable federal, state, and local laws.
Job Functions and Work Environment:
While performing the duties of this position, the employee is required to sit for extended periods of time. Manual dexterity and coordination are required while operating standard office equipment such as computer keyboard and mouse, calculator, telephone, copiers, etc.
The work environment characteristics described here are representative of those an employee may encounter while performing the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.
-
Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines TAC Security Full time $80,000 - $100,000 per yearAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and networks. This...
-
Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines TAC Security Full time $80,000 - $100,000 per yearAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and networks. This...
-
Application Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines Manulife Full time $90,000 - $120,000 per yearAre you looking for a supportive and collaborative workplace with great benefits and clear career development? You've come to the right place.Why choose Manulife?Competitive Salary packages and performance bonuses Day 1 HMO + FREE coverage for your dependents (inclusive of same-sex partners)Retirement savings benefit Rewarding culture that values wellness...
-
Application Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines Globe Telecom Full time ₱900,000 - ₱1,200,000 per yearApplication Security EngineerApply locations NCR - WGC time type Full time posted on Posted 2 Days Ago job requisition id R Do you want to take the first step in making Filipinos' lives better every day? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation...
-
Application Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines GCash Full time ₱900,000 - ₱1,200,000 per yearDo you want to take the first step in making Filipinos' lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation G ka ba? Join the G Nation todayKey ResponsibilitiesSecure Development Practices:Conduct static (SAST) and dynamic (DAST)...
-
Application Security Professional
7 days ago
Manila, National Capital Region, Philippines beBeeApplication Full time $80,000 - $95,000This role focuses on delivering secure products through proactive collaboration with our product development organization. The successful candidate will work closely with cross-functional teams to build and maintain a robust security posture.Key Responsibilities:Provide expert guidance on application security best practices, security automation within the...
-
Security Engineer,
2 weeks ago
Manila, National Capital Region, Philippines Solarwinds Software Full time $90,000 - $120,000 per yearSecurity Engineer, (Product Security Team) Manila, Night-ShiftAt SolarWinds, we're a people-first company. Our purpose is to enrich the lives of the people we serve—including our employees, customers, shareholders, Partners, and communities. Join us in our mission to help customers accelerate business transformation with simple, powerful, and secure...
-
Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines YONDU INC. Full time $90,000 - $120,000 per yearThe VAPT Security Engineer is responsible for assessing and enhancing the organization's security posture by conducting Vulnerability Assessments and Penetration Testing (VAPT) across infrastructure, networks, and applications (Web, Mobile, Client-Server). This role involves identifying, analyzing, and mitigating security vulnerabilities, ensuring compliance...
-
Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines Monroe Consulting Group Full time $60,000 - $80,000 per yearJob SummaryWe are seeking a skilled and detail-oriented Mid-Level Security Engineer to join our team. The ideal candidate will ensure the integration of security measures at every stage of system, application, and infrastructure development. You will play a key role in identifying and mitigating vulnerabilities while contributing to the successful delivery...
-
Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines Monroe Consulting Group Full time $90,000 - $120,000 per yearMonroe Consulting Group Philippines, a premier executive recruitment firm, is partnering with one of the world's most innovative technology and consulting companies to identify exceptional talent. Our client, a globally recognized technological leader, is dedicated to driving innovation and supporting its customers' core business processes through...