Security Engineer

11 hours ago


Manila, National Capital Region, Philippines YONDU INC. Full time $90,000 - $120,000 per year

The VAPT Security Engineer is responsible for assessing and enhancing the organization's security posture by conducting Vulnerability Assessments and Penetration Testing (VAPT) across infrastructure, networks, and applications (Web, Mobile, Client-Server). This role involves identifying, analyzing, and mitigating security vulnerabilities, ensuring compliance with security standards, and proactively reducing risks. The engineer will leverage security tools and methodologies, collaborate with stakeholders, and drive remediation efforts to strengthen overall security resilience.

Location: Metro Manila

Work Setup: Hybrid

Department: Technology

Security Testing & Vulnerability Assessment

Conduct regular vulnerability assessments for infrastructure, network, and application environments (Web, Mobile, Client-Server).

Perform black-box, white-box, and gray-box penetration testing to uncover security flaws.

Execute application security testing using:

  • Static Application Security Testing (SAST) – for code vulnerabilities.
  • Dynamic Application Security Testing (DAST) – for runtime vulnerabilities.
  • Software Composition Analysis (SCA) – for open-source dependency risks.
  • Interactive Application Security Testing (IAST) – combining SAST and DAST for CI/CD pipelines.

Assess wireless networks, APIs, databases, and IoT devices for security weaknesses.

Conduct penetration testing activities to identify and exploit vulnerabilities.

Serve as the point of contact for third-party VAPT assessments.

Red Teaming & Adversary Simulations

Conduct Red Team engagements to simulate real-world cyber threats and evaluate the organization's detection and response capabilities.

Perform attack simulations using MITRE ATT&CK, TTPs, and APT methodologies.

Develop and execute custom exploits, lateral movement tactics, and privilege escalation techniques.

Collaborate with Blue Team/SOC to enhance Threat Detection, Incident Response, and Cyber Resilience.

Security Tool Management & Automation

Utilize security tools such as Burp Suite, Kali, Frida, Rapid7, Nessus, Qualys, Metasploit, OWASP ZAP, Nmap, Wireshark, Checkmarx, Fortify, Acunetix.

Automate security testing in CI/CD pipelines (DevSecOps).

Maintain penetration testing frameworks and develop custom security scripts and exploits.

Incident Response & Threat Management

Support incident response by analyzing vulnerabilities exploited in real-time attacks.

Assist in forensic analysis, malware reverse engineering, and threat hunting.

Collaborate with SOC, IT, and Security Operations teams to contain, eradicate, and recover from security incidents.

Provide security recommendations and post-incident lessons to strengthen security posture.

Risk Analysis & Compliance

Identify and prioritize security vulnerabilities based on risk impact and exploitability.

Develop detailed assessment reports outlining findings, risk ratings, and remediation plans.

Ensure security testing compliance with frameworks such as ISO 27001, NIST, PCI-DSS, GDPR, MAS TRM, CIS Benchmarks.

Conduct third-party security assessments and validate vendor security compliance.

Assist in audit and compliance efforts by providing security reports and mitigation evidence.

Security Awareness & Training

Develop and deliver security awareness programs to educate employees on cybersecurity best practices.

Conduct simulated phishing campaigns and social engineering tests to assess awareness levels.

Train development and IT teams on secure coding practices, vulnerability mitigation, and security operations.

Create and distribute security bulletins, newsletters, and case studies to highlight emerging threats.

Reporting & Remediation

Develop and maintain security assessment methodologies, playbooks, and Red Team strategies.

Prepare technical and executive reports on security findings, recommendations, and mitigation strategies.

Present assessment results to senior management, security teams, and business units.

Education –  Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related field

  • Professional Certification & Licenses: CEH (Certified Ethical Hacker), OSCP (Offensive Security Certified Professional), CRTP (Certified Red Team Professional), CMWAPT (Certified Mobile and Web Application Penetration Tester), GIAC certifications (e.g., GWAPT, GPEN), AWS/Azure/GCP Security Certifications (a strong plus)

Related Work Experience – 5+ years of experience in VAPT, penetration testing, and information security.

  • Leadership experience in managing VAPT projects and security teams.
  • Experience in:
  • Advanced penetration testing, security control bypassing, and exploit development.
  • Reverse engineering, malware analysis, threat emulation, and lateral movement.
  • IT security auditing (preferred).

Knowledge –

  • Network security, operating systems (Linux, Windows, RHEL), web application security.
  • Security frameworks and compliance standards (ISO 27001, NIST, PCI-DSS, etc.).
  • Security platforms: Crowdstrike, Splunk, Tenable, Ansible, FireEye, Imperva, Qualys, Acunetix, IBM AppScan, Deep Security.
  • System administration & scripting (Bash, Python, PowerShell).
  • Cloud security and DevSecOps practices.

Skills

  • Strong analytical and problem-solving skills to identify and mitigate vulnerabilities.
  • Excellent reporting, communication, and presentation skills to engage technical and non-technical stakeholders.

  • Security Engineer

    11 hours ago


    Manila, National Capital Region, Philippines TAC Security Full time $80,000 - $100,000 per year

    As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and networks. This...

  • Security Engineer

    12 hours ago


    Manila, National Capital Region, Philippines TAC Security Full time $80,000 - $100,000 per year

    As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and networks. This...

  • Security Engineer

    12 hours ago


    Manila, National Capital Region, Philippines Satellite Office Full time $60,000 - $100,000 per year

    SECURITY ENGINEER Work for our global clients and immerse in our rich and diverse company culture where you can thrive, grow and just be aweSOme Apply now and discover the Satellite Office Candidate Experience – recognized as one of BEST among BPO companies worldwide. WHAT IS A SECURITY ENGINEER? The Security Engineer is pivotal in delivering, managing,...

  • Security Engineer

    12 hours ago


    Manila, National Capital Region, Philippines Satellite Office Full time $40,000 - $80,000 per year

    SECURITY ENGINEER Work for our global clients and immerse in our rich and diverse company culture where you can thrive, grow and just be aweSOme Apply now and discover the Satellite Office Candidate Experience – recognized as one of BEST among BPO companies worldwide. WHAT IS A SECURITY ENGINEER? The Security Engineer is pivotal in delivering, managing,...

  • Security Engineer,

    12 hours ago


    Manila, National Capital Region, Philippines Solarwinds Software Full time $90,000 - $120,000 per year

    Security Engineer, (Product Security Team) Manila, Night-ShiftAt SolarWinds, we're a people-first company. Our purpose is to enrich the lives of the people we serve—including our employees, customers, shareholders, Partners, and communities. Join us in our mission to help customers accelerate business transformation with simple, powerful, and secure...

  • Security Engineer

    12 hours ago


    Manila, National Capital Region, Philippines Monroe Consulting Group Full time $60,000 - $80,000 per year

    Job SummaryWe are seeking a skilled and detail-oriented Mid-Level Security Engineer to join our team. The ideal candidate will ensure the integration of security measures at every stage of system, application, and infrastructure development. You will play a key role in identifying and mitigating vulnerabilities while contributing to the successful delivery...

  • Security Engineer

    13 hours ago


    Manila, National Capital Region, Philippines Monroe Consulting Group Full time $80,000 - $100,000 per year

    Monroe Consulting Group Philippines, a premier executive recruitment firm, is partnering with one of the world's most innovative technology and consulting companies to identify exceptional talent. Our client, a globally recognized technological leader, is dedicated to driving innovation and supporting its customers' core business processes through...

  • Security Engineer

    12 hours ago


    Manila, National Capital Region, Philippines Monroe Consulting Group Full time $90,000 - $120,000 per year

    Monroe Consulting Group Philippines, a premier executive recruitment firm, is partnering with one of the world's most innovative technology and consulting companies to identify exceptional talent. Our client, a globally recognized technological leader, is dedicated to driving innovation and supporting its customers' core business processes through...

  • Security Engineer

    11 hours ago


    Manila, National Capital Region, Philippines Globe Telecom Full time $60,000 - $80,000 per year

    Job DescriptionOversee, manage, identify, assess, review, and orchestrate the execution of appropriate risk mitigation plans for specific Change Activities such as emergency changes. Duties and ResponsibilitiesAdministration of Globe Telecom's security platforms, including but not limited to firewalls, ASAV, APT, SIEM, VPN, etc. Documentation of security...


  • Manila, National Capital Region, Philippines Satellite Office Full time $80,000 - $100,000 per year

    SENIOR SECURITY ENGINEERWork for our global clients and immerse in our rich and diverse company culture where you can thrive, grow and just be aweSOme Apply now and discover the Satellite Office Candidate Experience – recognized as one of BEST among BPO companies worldwide.WHAT IS A SENIOR SECURITY ENGINEER?Our awesome client, a prominent analytics and...