
Web & API Security Engineer
4 days ago
Axos Business Center, Corp
About This Job
We're seeking a highly skilled Web & API Security Engineer with deep offensive security expertise. This is a hands-on role focused on identifying and exploiting vulnerabilities in modern web applications and APIs. You'll simulate real-world attacks, uncover complex flaws, and collaborate directly with engineering teams to strengthen our platform's defenses. If you thrive on manual testing, creative problem-solving, and thinking like an adversary, this role is built for you.
As a Web & API Security Engineer, you will:
- Conduct manual security testing of production-grade web apps and APIs (REST, GraphQL, gRPC)
- Identify advanced vulnerabilities beyond standard CVEs — including logic flaws, authentication bypasses, and chained exploits
- Simulate adversarial behavior and design attack paths that mimic real-world threat actors
- Analyze and exploit security controls such as WAFs, rate limits, and token-based auth systems
- Document findings clearly for engineering teams, enabling fast and effective remediation
- Explore edge cases and abuse scenarios that automated tools often miss
You'll have full autonomy over your testing strategy, tools, and targets — and your work will directly impact the security of our platform.
Qualifications:
- Proven experience in manual penetration testing of web applications and APIs
- Deep understanding of HTTP, cookies, sessions, JWTs, CORS, and authentication flows
- Expertise in AuthN/AuthZ vulnerabilities (e.g., OAuth abuse, IDOR, BOLA, SSO bypass)
- Familiarity with API attack vectors such as schema enforcement issues, replay attacks, and parameter pollution
- Proficiency with tools like Burp Suite Pro, Postman, ffuf, sqlmap, jwt_tool, mitmproxy, and scripting in Python or Bash
- Strong threat modeling mindset — you think in terms of abuse cases, not just known vulnerabilities
Ideal Traits:
- Operates independently with a red team mindset
- Demonstrates extreme ownership and attention to detail
- Thrives in a fast-paced, high-accountability environment
- Passionate about security and driven to uncover the unexpected
About Axos
Born digital-first, Axos delivers financial tools and services that allow individuals, small businesses, and companies to access and manage their money how, when, and where they want. We're a diverse team of dynamic, insightful, and independent innovators who are excited to provide technology-driven solutions that offer unbeatable value to our customers.
Axos Financial is our holding company and is publicly traded on the New York Stock Exchange under the symbol "AX" (NYSE: AX).
Learn More about working at Axos Business Center
Pre-Employment Background Check, Medical, and Drug Test:
All offers are contingent upon the candidate successfully passing a credit check, criminal background check, and pre-employment medical and drug screening.
Equal Employment Opportunity:
Axos is an Equal Opportunity employer. We are committed to providing equal employment opportunities to all employees and applicants without regard to race, religious creed, color, sex (including pregnancy, breast feeding and related medical conditions), gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship status, military and veteran status, marital status, age, protected medical condition, genetic information, physical disability, mental disability, or any other protected status in accordance with all applicable federal, state, and local laws.
Job Functions and Work Environment:
While performing the duties of this position, the employee is required to sit for extended periods of time. Manual dexterity and coordination are required while operating standard office equipment such as computer keyboard and mouse, calculator, telephone, copiers, etc.
The work environment characteristics described here are representative of those an employee may encounter while performing the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions of this position.
-
Azure API
15 hours ago
Manila, National Capital Region, Philippines CLPS Global Full time ₱800,000 - ₱1,200,000 per yearRole: AZURE-API, Microsoft Azure Integration. Net, CICDYears of Exp: 7 +Location: Philippines Makati City, ManilaHybrid RoleJD:The role involves designing developing testing and maintaining API Integration solutions using Microsoft Azure Integration Services The developer will collaborate with crossfunctional teams to gather requirements optimize performance...
-
QA Engineer
3 days ago
Manila, National Capital Region, Philippines Ridge Security Technology Inc. Full time ₱600,000 - ₱1,200,000 per yearJob Description: QA Engineer (Security Testing & Automation)About Us Ridge Security develops an AI-powered offensive security platform that detects and validates cyber risks with zero false positives, enabling enterprises to reduce risk through continuous threat exposure management. Our cutting-edge solutions incorporate advanced artificial intelligence for...
-
API Gateway Engineer
4 days ago
Manila, National Capital Region, Philippines Ascendion Full time ₱900,000 - ₱1,200,000 per yearAscendion is a leader in digital engineering, helping clients build scalable, secure, and high-performance systems that power modern enterprises. We're passionate about solving complex problems with elegant, efficient, and resilient technology solutions.Project Overview:We are building a high-performance API Gateway for a mission-critical enterprise system...
-
Application Security Engineer
2 weeks ago
Manila, National Capital Region, Philippines Axos Bank Full time ₱1,200,000 - ₱2,400,000 per yearAxos Business Center, CorpAbout This JobWe are seeking a Security Engineer with deep expertise in application security platforms to own, operate, and optimize our WAF, bot defense, API security, and application testing tools. This role will focus on ensuring these platforms are well-configured, continuously tuned, and delivering maximum security value with...
-
Frontend Web Engineers
1 week ago
Manila, National Capital Region, Philippines Complete Development (CoDev) Full time ₱900,000 - ₱1,200,000 per yearAbout the RoleAs a Frontend Web Engineer, you will be pivotal in crafting an intuitive user experience for our web applications. Your role involves developing user-centric interfaces that are critical to our project's success, ensuring seamless interaction for end-users through responsive and dynamic designs.About YouYou possess excellent problem-solving...
-
Security & Privacy Analyst
4 days ago
Manila, National Capital Region, Philippines Countable Web Productions Full time ₱1,920,000 - ₱2,520,000 per yearCompany: Cortico – Healthcare solutions for providers and patientsAre you passionate about security and privacy? Do you have a talent for aligning compliance frameworks with business goals, ensuring processes empower employees rather than burden them? If so, we'd love to meet youWe are seeking an Information Security & Privacy Compliance Manager to lead...
-
Software Development Engineer
3 days ago
Manila, National Capital Region, Philippines Ridge Security Technology Inc. Full time $104,000 - $130,878 per yearJob Description: Software Development EngineerAbout UsRidge Security develops an AI-powered offensive security platform that detects and validates cyber risks with zero false positives, enabling enterprises to reduce risk through continuous threat exposure management. Our cutting-edge solutions incorporate advanced artificial intelligence for comprehensive...
-
Software Engineer
3 days ago
Manila, National Capital Region, Philippines CVP Talent Full time ₱600,000 - ₱1,200,000 per yearSoftware Engineer – Payments & MobileOur client is a a fast-growing technology company headquartered in Melbourne, Australia, with our Tech Lead based in Manila.They have a global footprint, delivering secure and scalable payment solutions across cards, mobile wallets, and wearables. This is a permanent full-time role.Tech StackMobile:Kotlin (Android),...
-
Senior DevOps Engineer
4 weeks ago
Manila, National Capital Region, Philippines Staff4Me Full timeOverviewWe are seeking a highly experienced DevOps Developer and System Engineer with a strong background in PHP, Python, and DevOps practices. The ideal candidate will have at least 5 years of experience in system engineering, automation, and software development, with deep knowledge of ELK stack, Ansible playbooks, and RESTful API development. This role...
-
Senior Security Engineer
4 weeks ago
Manila, National Capital Region, Philippines InfoTrust Co. Full timeThe Senior Security Engineer is pivotal in delivering, managing, and supporting security solutions that ensure our customers' environments are secure, efficient, and resilient. This role combines hands-on implementation, customer enablement, project leadership, and pre-sales expertise. This ensures Infotrust customers receive high-value, strategic security...