Application Security Engineer

3 days ago


Bonifacio Global Metro Manila, Philippines AXOS BUSINESS CENTER CORP. Full time ₱1,200,000 - ₱2,400,000 per year

Imagine a world where banking is not just a transaction but a transformative experience. Welcome to Axos Business Center We're on a mission to redefine the financial landscape with innovation, creativity, and customer-centric solutions at the core of everything we do. #Banking Evolved.

Ready to dive into a new chapter in your career journey and make your mark this year? We need visionary minds like yours Join our team and become part of a dynamic force that's reshaping how people interact with their finances.

Your next big opportunity is just a click away

**We are seeking a Security Engineer with deep expertise in application security platforms to own, operate, and optimize our WAF, bot defense, API security, and application testing tools. This role will focus on ensuring these platforms are well-configured, continuously tuned, and delivering maximum security value with minimal business friction.

The Security Engineer will also serve as the incident response lead for application-layer attacks, participate in the on-call rotation, and work primarily during Pacific Time (PT) business hours to align with our operations.**

Key Responsibilities

  • AppSec Tool Management & Optimization

  • Administer and tune Cloudflare WAF, maintaining rules, policies, and custom configurations.

  • Manage and optimize bot defense platforms (e.g., F5/Shape, Arkose) to mitigate automated fraud, scraping, and credential stuffing.
  • Oversee and tune API security solutions (e.g., Traceable) for visibility, anomaly detection, and protection.
  • Operate DAST and SAST platforms, ensuring they are integrated into CI/CD and providing actionable insights.
  • Security Operations & Incident Response

  • Lead response to AppSec-related incidents, including botnet activity, API abuse, and web exploitation attempts.

  • Participate in the on-call rotation, ensuring timely detection, escalation, and remediation of critical application security events.
  • Build playbooks for WAF/bot/API incident handling and drive continuous improvement of detection/response.
  • Collaborate with SOC, DevOps, and development teams to remediate issues and strengthen defenses.
  • Continuous Improvement

  • Tune tools to reduce false positives and improve detection accuracy.

  • Track tool coverage and effectiveness, providing metrics and reports to leadership.
  • Engage with vendors to leverage updates, intelligence feeds, and advanced features.
  • Collaboration & Governance

  • Partner with application teams to align security policies with business requirements.

  • Support compliance initiatives by ensuring tooling configurations meet regulatory/security standards.

Key Responsibilities

  • AppSec Tool Management & Optimization

  • Administer and tune Cloudflare WAF, maintaining rules, policies, and custom configurations.

  • Manage and optimize bot defense platforms (e.g., F5/Shape, Arkose) to mitigate automated fraud, scraping, and credential stuffing.
  • Oversee and tune API security solutions (e.g., Traceable) for visibility, anomaly detection, and protection.
  • Operate DAST and SAST platforms, ensuring they are integrated into CI/CD and providing actionable insights.
  • Security Operations & Incident Response

  • Lead response to AppSec-related incidents, including botnet activity, API abuse, and web exploitation attempts.

  • Participate in the on-call rotation, ensuring timely detection, escalation, and remediation of critical application security events.
  • Build playbooks for WAF/bot/API incident handling and drive continuous improvement of detection/response.
  • Collaborate with SOC, DevOps, and development teams to remediate issues and strengthen defenses.
  • Continuous Improvement

  • Tune tools to reduce false positives and improve detection accuracy.

  • Track tool coverage and effectiveness, providing metrics and reports to leadership.
  • Engage with vendors to leverage updates, intelligence feeds, and advanced features.
  • Collaboration & Governance

  • Partner with application teams to align security policies with business requirements.

  • Support compliance initiatives by ensuring tooling configurations meet regulatory/security standards.

Required Qualifications

  • 4–6+ years of experience in information security or application security operations.
  • Hands-on experience with Cloudflare WAF (or equivalent enterprise WAF).
  • Experience managing bot defense tools (F5/Shape, Arkose, or similar).
  • Familiarity with API security solutions (Traceable, Salt, or similar).
  • Experience with DAST and/or SAST platforms in an enterprise environment.
  • Strong understanding of OWASP Top 10 and API Security Top 10 threats.
  • Background in incident response, particularly application and API security events.
  • Willingness to participate in an on-call rotation for AppSec-related incidents.
  • Ability to work Pacific Time (PT) business hours to support operational coverage.

Preferred Qualifications

  • Experience integrating AppSec tools into CI/CD pipelines.
  • Familiarity with SIEM/SOAR platforms for AppSec event enrichment and automation.
  • Knowledge of cloud security (AWS, Azure, GCP) in relation to web and API workloads.
  • Industry certifications (e.g., GWAPT, GWEB, CCSK, AWS Security Specialty) are a plus.

  • Security Engineer

    2 weeks ago


    Manila, National Capital Region, Philippines TAC Security Full time $80,000 - $100,000 per year

    As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and networks. This...

  • Security Engineer

    2 weeks ago


    Manila, National Capital Region, Philippines TAC Security Full time $80,000 - $100,000 per year

    As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and networks. This...


  • Manila, National Capital Region, Philippines Manulife Full time $90,000 - $120,000 per year

    Are you looking for a supportive and collaborative workplace with great benefits and clear career development? You've come to the right place.Why choose Manulife?Competitive Salary packages and performance bonuses Day 1 HMO + FREE coverage for your dependents (inclusive of same-sex partners)Retirement savings benefit Rewarding culture that values wellness...

  • Dev Engineer

    3 days ago


    Bonifacio Global, Metro Manila, Philippines OwnBank Full time ₱1,500,000 - ₱2,500,000 per year

    Duties and ResponsibilitiesOversee end-to-end software development lifecycle of banking platforms and applications.Provide technical leadership to a team of software engineers and IT specialists.Design scalable, secure, and high-performance systems aligned with rural banking needs.Evaluate and select technology stacks, frameworks, and toolsIntegrate with...

  • Citrix Engineer

    14 hours ago


    Bonifacio Global, Metro Manila, Philippines Philtech Full time ₱1,200,000 - ₱2,400,000 per year

    Albertsons-Safeway Company is one of the largest food and drug retailers with 2,300+ stores. The Albertsons-Safeway family of brands includes some of the most prominent brands in food retailing, with a growing base of loyal shoppers. Thanks to the professionalism, diversity, spirit, and friendliness of our people, we have locations across the U.S.The...


  • Manila, National Capital Region, Philippines Axos Bank Full time ₱1,200,000 - ₱2,400,000 per year

    Axos Business Center, CorpAbout This JobWe are seeking a Security Engineer with deep expertise in application security platforms to own, operate, and optimize our WAF, bot defense, API security, and application testing tools. This role will focus on ensuring these platforms are well-configured, continuously tuned, and delivering maximum security value with...


  • Manila, National Capital Region, Philippines Globe Telecom Full time ₱900,000 - ₱1,200,000 per year

    Application Security EngineerApply locations NCR - WGC time type Full time posted on Posted 2 Days Ago job requisition id R Do you want to take the first step in making Filipinos' lives better every day? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation...


  • Manila, National Capital Region, Philippines GCash Full time ₱900,000 - ₱1,200,000 per year

    Do you want to take the first step in making Filipinos' lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation G ka ba? Join the G Nation todayKey ResponsibilitiesSecure Development Practices:Conduct static (SAST) and dynamic (DAST)...


  • Manila, National Capital Region, Philippines beBeeApplication Full time $80,000 - $95,000

    This role focuses on delivering secure products through proactive collaboration with our product development organization. The successful candidate will work closely with cross-functional teams to build and maintain a robust security posture.Key Responsibilities:Provide expert guidance on application security best practices, security automation within the...

  • IT Systems Engineer

    3 days ago


    Bonifacio Global, Metro Manila, Philippines DigiPlus Interactive Corp. Full time ₱900,000 - ₱1,200,000 per year

    About DigiPlus Interactive Corp.DigiPlus Interactive Corp. pioneered digital entertainment in the Philippines. It introduced leading platforms BingoPlus and ArenaPlus, widely known for their engaging experiences in interactive gaming and sports entertainment. DigiPlus also operates GameZone, with more to come.For more information, visit: Key...