Application Security Engineer

3 days ago


Bonifacio Global Metro Manila, Philippines AXOS BUSINESS CENTER CORP. Full time ₱1,200,000 - ₱2,400,000 per year

Imagine a world where banking is not just a transaction but a transformative experience. Welcome to Axos Business Center We're on a mission to redefine the financial landscape with innovation, creativity, and customer-centric solutions at the core of everything we do. #Banking Evolved.

Ready to dive into a new chapter in your career journey and make your mark this year? We need visionary minds like yours Join our team and become part of a dynamic force that's reshaping how people interact with their finances.

Your next big opportunity is just a click away

**We are seeking a Security Engineer with deep expertise in application security platforms to own, operate, and optimize our WAF, bot defense, API security, and application testing tools. This role will focus on ensuring these platforms are well-configured, continuously tuned, and delivering maximum security value with minimal business friction.

The Security Engineer will also serve as the incident response lead for application-layer attacks, participate in the on-call rotation, and work primarily during Pacific Time (PT) business hours to align with our operations.**

Key Responsibilities

  • AppSec Tool Management & Optimization

  • Administer and tune Cloudflare WAF, maintaining rules, policies, and custom configurations.

  • Manage and optimize bot defense platforms (e.g., F5/Shape, Arkose) to mitigate automated fraud, scraping, and credential stuffing.
  • Oversee and tune API security solutions (e.g., Traceable) for visibility, anomaly detection, and protection.
  • Operate DAST and SAST platforms, ensuring they are integrated into CI/CD and providing actionable insights.
  • Security Operations & Incident Response

  • Lead response to AppSec-related incidents, including botnet activity, API abuse, and web exploitation attempts.

  • Participate in the on-call rotation, ensuring timely detection, escalation, and remediation of critical application security events.
  • Build playbooks for WAF/bot/API incident handling and drive continuous improvement of detection/response.
  • Collaborate with SOC, DevOps, and development teams to remediate issues and strengthen defenses.
  • Continuous Improvement

  • Tune tools to reduce false positives and improve detection accuracy.

  • Track tool coverage and effectiveness, providing metrics and reports to leadership.
  • Engage with vendors to leverage updates, intelligence feeds, and advanced features.
  • Collaboration & Governance

  • Partner with application teams to align security policies with business requirements.

  • Support compliance initiatives by ensuring tooling configurations meet regulatory/security standards.

Key Responsibilities

  • AppSec Tool Management & Optimization

  • Administer and tune Cloudflare WAF, maintaining rules, policies, and custom configurations.

  • Manage and optimize bot defense platforms (e.g., F5/Shape, Arkose) to mitigate automated fraud, scraping, and credential stuffing.
  • Oversee and tune API security solutions (e.g., Traceable) for visibility, anomaly detection, and protection.
  • Operate DAST and SAST platforms, ensuring they are integrated into CI/CD and providing actionable insights.
  • Security Operations & Incident Response

  • Lead response to AppSec-related incidents, including botnet activity, API abuse, and web exploitation attempts.

  • Participate in the on-call rotation, ensuring timely detection, escalation, and remediation of critical application security events.
  • Build playbooks for WAF/bot/API incident handling and drive continuous improvement of detection/response.
  • Collaborate with SOC, DevOps, and development teams to remediate issues and strengthen defenses.
  • Continuous Improvement

  • Tune tools to reduce false positives and improve detection accuracy.

  • Track tool coverage and effectiveness, providing metrics and reports to leadership.
  • Engage with vendors to leverage updates, intelligence feeds, and advanced features.
  • Collaboration & Governance

  • Partner with application teams to align security policies with business requirements.

  • Support compliance initiatives by ensuring tooling configurations meet regulatory/security standards.

Required Qualifications

  • 4–6+ years of experience in information security or application security operations.
  • Hands-on experience with Cloudflare WAF (or equivalent enterprise WAF).
  • Experience managing bot defense tools (F5/Shape, Arkose, or similar).
  • Familiarity with API security solutions (Traceable, Salt, or similar).
  • Experience with DAST and/or SAST platforms in an enterprise environment.
  • Strong understanding of OWASP Top 10 and API Security Top 10 threats.
  • Background in incident response, particularly application and API security events.
  • Willingness to participate in an on-call rotation for AppSec-related incidents.
  • Ability to work Pacific Time (PT) business hours to support operational coverage.

Preferred Qualifications

  • Experience integrating AppSec tools into CI/CD pipelines.
  • Familiarity with SIEM/SOAR platforms for AppSec event enrichment and automation.
  • Knowledge of cloud security (AWS, Azure, GCP) in relation to web and API workloads.
  • Industry certifications (e.g., GWAPT, GWEB, CCSK, AWS Security Specialty) are a plus.

  • Security Engineer

    3 days ago


    Bonifacio Global, Metro Manila, Philippines YONDU INC. Full time ₱1,200,000 - ₱2,400,000 per year

    Must have SkillsSecurity Risk Assessment (NIST,ISO, HIPA, PCIDSS)Cloud Security - AWS (preferred), Azure (at least 1)Cybersecurity FundamentalsUnderstanding in Security ArchitectureStakeholder ManagementHandles multiple projectsTechnical Assessment & DiscoveryParticipate in discovery sessions to understand technical requirements and existing security...


  • Bonifacio Global, Metro Manila, Philippines AXOS BUSINESS CENTER CORP. Full time ₱1,200,000 - ₱2,400,000 per year

    Imagine a world where banking is not just a transaction but a transformative experience. Welcome to Axos Business Center We're on a mission to redefine the financial landscape with innovation, creativity, and customer-centric solutions at the core of everything we do. #Banking Evolved.Ready to dive into a new chapter in your career journey and make your mark...


  • Bonifacio Global, Metro Manila, Philippines B & M Global Services Manila, Inc. Full time ₱6,480,000 - ₱7,920,000 per year

    The Security Vulnerability and Penetration Testing (VAPT) Engineer will oversee and serve as a technical resource for all assessment activity related to the security posture of existing and proposed firm systems, platforms, and processes to protect and continually improve the confidentiality, integrity, and availability of information systems per the...


  • , Metro Manila, Philippines Buscojobs Full time

    Overview Vp For Application Security jobs in TaguigPosted today Job Description Job brief Seeking for an experienced Application Security Head to drive our secure development initiatives and lead a team of security professionals. The ideal candidate will have a strong technical background in application security, hands-on expertise with security testing...


  • Manila, National Capital Region, Philippines Axos Bank Full time ₱1,200,000 - ₱2,400,000 per year

    Axos Business Center, CorpAbout This JobWe are seeking a Security Engineer with deep expertise in application security platforms to own, operate, and optimize our WAF, bot defense, API security, and application testing tools. This role will focus on ensuring these platforms are well-configured, continuously tuned, and delivering maximum security value with...


  • , Metro Manila, Philippines Buscojobs Full time

    Vulnerability Assessment and Penetration Testing Specialist / Offensive Security Posted today Job Description QUALIFICATIONS: At least 3-5 years as a VAPT Specialist/Offensive Security or other related roles. Hands-on experience in web and mobile application VAPT, following the OWASP Top 10 testing framework Proficient in using open-source and commercial...


  • Manila, National Capital Region, Philippines GCash Full time ₱900,000 - ₱1,200,000 per year

    Do you want to take the first step in making Filipinos' lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation G ka ba? Join the G Nation todayKey ResponsibilitiesSecure Development Practices:Conduct static (SAST) and dynamic (DAST)...

  • Cloud Engineer

    7 days ago


    Bonifacio Global, Metro Manila, Philippines YONDU INC. Full time ₱900,000 - ₱1,200,000 per year

    Responsibilities:Design, build, and manage highly secure, scalable, and available architectures in the target cloud environments (Azure/AWS/GCP/Alibaba) for small scale projects in close coordination with development teams and project management.Implement and execute well-defined Infrastructure as Code (IaC) templates and scripts for basic infrastructure...

  • Senior Engineer

    1 day ago


    Bonifacio Global, Metro Manila, Philippines Private Advertiser Full time ₱1,200,000 - ₱1,500,000 per year

    Job SummaryWe are seeking a highly skilled Senior System Engineer – Public Cloud with strong architecture experience to join our growing infrastructure and cloud operations team. This role is ideal for an experienced engineer who thrives in dynamic environments and has a deep understanding of cloud technologies, system architecture, and scalable...


  • Bonifacio Global, Metro Manila, Philippines Asticom Technology Inc Full time ₱900,000 - ₱1,200,000 per year

    Job Description:Access Management SQL server administration access.● Salesforce ticketing tool for service and incident requests management. Supported 20,000+ endusers in managing user accounts on Active Directory (Creation, Deletion, Permissions, Securitygroups and VPN Access). Created and maintained email addresses and distribution lists inGoogle's Admin...