Senior Application Security Engineer
Inriver · Davao City, Davao Region, Philippines
Software Development · 201-500 employees
About the role
You will own application security across the SDLC, managing vulnerabilities and integrating security tooling into CI/CD pipelines. Additionally, you will conduct threat modeling, secure cloud infrastructure, and provide guidance on AI-specific security risks.
What they look for
Requirements
The role requires over 8 years of experience in application security or software engineering with a strong security focus. Candidates must possess hands-on experience with Azure, .NET, and common security tooling within CI/CD environments.
Full description
About the role
We're looking for a Senior Application Security Engineer. You own security in the software development lifecycle (SDLC) — end to end, hands-on, and independently. You report to the CISO. The CISO sets direction, risk appetite, and handles executive escalation; you run application security day to day without needing constant support. You'll partner with engineering teams to find, fix, and prevent vulnerabilities in a platform built primarily on .NET and hosted in Azure, while helping us secure the next generation of AI-powered features. This is a hands-on role for someone who wants to make secure development the path of least resistance for our engineers.
What you’ll do
· Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs. Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs.
· Security tooling in CI/CD. Build, integrate, and operate SAST, SCA, and DAST in Azure DevOps pipelines, including PR gating on new critical and high findings, secret scanning, and automated routing of findings to tickets.
· Azure security. Secure our cloud estate across identity and access management (Entra ID, Auth0), network configuration, secrets management, and workload protection, working with Defender for Cloud policy and posture.
· Threat modeling and reviews. Conduct threat models, design reviews, and code reviews for new and existing services — with a threat model in place before any new service reaches production.
· AI feature security. Evaluate security and privacy implications of our AI functionality, including LLM-specific risks such as prompt injection, data leakage, and model misuse, and define controls for them.
· Standards and enablement. Define and uphold secure coding standards, train engineers, and build a security champion in each product team so risk assessment becomes self-service rather than a security-team bottleneck.
· Pen tests and scans. Coordinate penetration tests and application vulnerability scanning, review the findings, identify fixes, and implement them hands-on when needed.
· Incident response. Support security incident investigation and response as the application subject-matter expert, working with our 24/7 managed detection and response partner.
What you’ll bring
· 8+ years of experience in application security, or in software engineering with a strong security focus.
· Experience integrating and operating security tooling within CI/CD pipelines.
· Strong .NET (C#) working knowledge; ability to read and reason about Python is a plus.
· Fluency in common vulnerability classes (OWASP Top 10, API security risks) and how they manifest in real code — not just in scanner output.
· Hands-on Azure experience: creating resources, securing applications, Azure networking, and secrets management.
· Hands-on experience with Auth0 in production environments.
· Strong communication skills and the ability to influence engineers without owning their backlog.
· A pragmatic, risk-based mindset that balances security with delivery — you know which findings matter and which are noise