
Application Security Engineer
3 days ago
Imagine a world where banking is not just a transaction but a transformative experience. Welcome to Axos Business Center We're on a mission to redefine the financial landscape with innovation, creativity, and customer-centric solutions at the core of everything we do. #Banking Evolved.
Ready to dive into a new chapter in your career journey and make your mark this year? We need visionary minds like yours Join our team and become part of a dynamic force that's reshaping how people interact with their finances.
Your next big opportunity is just a click away
**We are seeking a Security Engineer with deep expertise in application security platforms to own, operate, and optimize our WAF, bot defense, API security, and application testing tools. This role will focus on ensuring these platforms are well-configured, continuously tuned, and delivering maximum security value with minimal business friction.
The Security Engineer will also serve as the incident response lead for application-layer attacks, participate in the on-call rotation, and work primarily during Pacific Time (PT) business hours to align with our operations.**
Key Responsibilities
AppSec Tool Management & Optimization
Administer and tune Cloudflare WAF, maintaining rules, policies, and custom configurations.
- Manage and optimize bot defense platforms (e.g., F5/Shape, Arkose) to mitigate automated fraud, scraping, and credential stuffing.
- Oversee and tune API security solutions (e.g., Traceable) for visibility, anomaly detection, and protection.
- Operate DAST and SAST platforms, ensuring they are integrated into CI/CD and providing actionable insights.
Security Operations & Incident Response
Lead response to AppSec-related incidents, including botnet activity, API abuse, and web exploitation attempts.
- Participate in the on-call rotation, ensuring timely detection, escalation, and remediation of critical application security events.
- Build playbooks for WAF/bot/API incident handling and drive continuous improvement of detection/response.
- Collaborate with SOC, DevOps, and development teams to remediate issues and strengthen defenses.
Continuous Improvement
Tune tools to reduce false positives and improve detection accuracy.
- Track tool coverage and effectiveness, providing metrics and reports to leadership.
- Engage with vendors to leverage updates, intelligence feeds, and advanced features.
Collaboration & Governance
Partner with application teams to align security policies with business requirements.
- Support compliance initiatives by ensuring tooling configurations meet regulatory/security standards.
Key Responsibilities
AppSec Tool Management & Optimization
Administer and tune Cloudflare WAF, maintaining rules, policies, and custom configurations.
- Manage and optimize bot defense platforms (e.g., F5/Shape, Arkose) to mitigate automated fraud, scraping, and credential stuffing.
- Oversee and tune API security solutions (e.g., Traceable) for visibility, anomaly detection, and protection.
- Operate DAST and SAST platforms, ensuring they are integrated into CI/CD and providing actionable insights.
Security Operations & Incident Response
Lead response to AppSec-related incidents, including botnet activity, API abuse, and web exploitation attempts.
- Participate in the on-call rotation, ensuring timely detection, escalation, and remediation of critical application security events.
- Build playbooks for WAF/bot/API incident handling and drive continuous improvement of detection/response.
- Collaborate with SOC, DevOps, and development teams to remediate issues and strengthen defenses.
Continuous Improvement
Tune tools to reduce false positives and improve detection accuracy.
- Track tool coverage and effectiveness, providing metrics and reports to leadership.
- Engage with vendors to leverage updates, intelligence feeds, and advanced features.
Collaboration & Governance
Partner with application teams to align security policies with business requirements.
- Support compliance initiatives by ensuring tooling configurations meet regulatory/security standards.
Required Qualifications
- 4–6+ years of experience in information security or application security operations.
- Hands-on experience with Cloudflare WAF (or equivalent enterprise WAF).
- Experience managing bot defense tools (F5/Shape, Arkose, or similar).
- Familiarity with API security solutions (Traceable, Salt, or similar).
- Experience with DAST and/or SAST platforms in an enterprise environment.
- Strong understanding of OWASP Top 10 and API Security Top 10 threats.
- Background in incident response, particularly application and API security events.
- Willingness to participate in an on-call rotation for AppSec-related incidents.
- Ability to work Pacific Time (PT) business hours to support operational coverage.
Preferred Qualifications
- Experience integrating AppSec tools into CI/CD pipelines.
- Familiarity with SIEM/SOAR platforms for AppSec event enrichment and automation.
- Knowledge of cloud security (AWS, Azure, GCP) in relation to web and API workloads.
- Industry certifications (e.g., GWAPT, GWEB, CCSK, AWS Security Specialty) are a plus.
-
Security Engineer
3 days ago
Bonifacio Global, Metro Manila, Philippines YONDU INC. Full time ₱1,200,000 - ₱2,400,000 per yearMust have SkillsSecurity Risk Assessment (NIST,ISO, HIPA, PCIDSS)Cloud Security - AWS (preferred), Azure (at least 1)Cybersecurity FundamentalsUnderstanding in Security ArchitectureStakeholder ManagementHandles multiple projectsTechnical Assessment & DiscoveryParticipate in discovery sessions to understand technical requirements and existing security...
-
Cyber Security Engineer
2 weeks ago
Bonifacio Global, Metro Manila, Philippines AXOS BUSINESS CENTER CORP. Full time ₱1,200,000 - ₱2,400,000 per yearImagine a world where banking is not just a transaction but a transformative experience. Welcome to Axos Business Center We're on a mission to redefine the financial landscape with innovation, creativity, and customer-centric solutions at the core of everything we do. #Banking Evolved.Ready to dive into a new chapter in your career journey and make your mark...
-
Bonifacio Global, Metro Manila, Philippines B & M Global Services Manila, Inc. Full time ₱6,480,000 - ₱7,920,000 per yearThe Security Vulnerability and Penetration Testing (VAPT) Engineer will oversee and serve as a technical resource for all assessment activity related to the security posture of existing and proposed firm systems, platforms, and processes to protect and continually improve the confidentiality, integrity, and availability of information systems per the...
-
Vp For Application Security
1 week ago
, Metro Manila, Philippines Buscojobs Full timeOverview Vp For Application Security jobs in TaguigPosted today Job Description Job brief Seeking for an experienced Application Security Head to drive our secure development initiatives and lead a team of security professionals. The ideal candidate will have a strong technical background in application security, hands-on expertise with security testing...
-
Application Security Engineer
1 day ago
Manila, National Capital Region, Philippines Axos Bank Full time ₱1,200,000 - ₱2,400,000 per yearAxos Business Center, CorpAbout This JobWe are seeking a Security Engineer with deep expertise in application security platforms to own, operate, and optimize our WAF, bot defense, API security, and application testing tools. This role will focus on ensuring these platforms are well-configured, continuously tuned, and delivering maximum security value with...
-
Applications Security Analyst
1 week ago
, Metro Manila, Philippines Buscojobs Full timeVulnerability Assessment and Penetration Testing Specialist / Offensive Security Posted today Job Description QUALIFICATIONS: At least 3-5 years as a VAPT Specialist/Offensive Security or other related roles. Hands-on experience in web and mobile application VAPT, following the OWASP Top 10 testing framework Proficient in using open-source and commercial...
-
Application Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines GCash Full time ₱900,000 - ₱1,200,000 per yearDo you want to take the first step in making Filipinos' lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation G ka ba? Join the G Nation todayKey ResponsibilitiesSecure Development Practices:Conduct static (SAST) and dynamic (DAST)...
-
Cloud Engineer
7 days ago
Bonifacio Global, Metro Manila, Philippines YONDU INC. Full time ₱900,000 - ₱1,200,000 per yearResponsibilities:Design, build, and manage highly secure, scalable, and available architectures in the target cloud environments (Azure/AWS/GCP/Alibaba) for small scale projects in close coordination with development teams and project management.Implement and execute well-defined Infrastructure as Code (IaC) templates and scripts for basic infrastructure...
-
Senior Engineer
1 day ago
Bonifacio Global, Metro Manila, Philippines Private Advertiser Full time ₱1,200,000 - ₱1,500,000 per yearJob SummaryWe are seeking a highly skilled Senior System Engineer – Public Cloud with strong architecture experience to join our growing infrastructure and cloud operations team. This role is ideal for an experienced engineer who thrives in dynamic environments and has a deep understanding of cloud technologies, system architecture, and scalable...
-
Junior Security Analyst
2 weeks ago
Bonifacio Global, Metro Manila, Philippines Asticom Technology Inc Full time ₱900,000 - ₱1,200,000 per yearJob Description:Access Management SQL server administration access.● Salesforce ticketing tool for service and incident requests management. Supported 20,000+ endusers in managing user accounts on Active Directory (Creation, Deletion, Permissions, Securitygroups and VPN Access). Created and maintained email addresses and distribution lists inGoogle's Admin...