Inriver

Senior Application Security Engineer

Inriver · Davao City, Davao Region, Philippines

Software Development · 201-500 employees

10 h ago
Senior (5-10 yrs) Full-time Philippines
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will own application security across the SDLC, managing vulnerabilities and integrating security tooling into CI/CD pipelines. Additionally, you will conduct threat modeling, secure cloud infrastructure, and provide guidance on AI-specific security risks.

What they look for

Application Security Software Development Lifecycle Azure .NET C# CI/CD SAST SCA DAST Auth0 Threat Modeling Vulnerability Management Identity and Access Management Python Security Incident Response

Requirements

The role requires over 8 years of experience in application security or software engineering with a strong security focus. Candidates must possess hands-on experience with Azure, .NET, and common security tooling within CI/CD environments.

Full description

About the role

We're looking for a Senior Application Security Engineer. You own security in the software development lifecycle (SDLC) — end to end, hands-on, and independently. You report to the CISO. The CISO sets direction, risk appetite, and handles executive escalation; you run application security day to day without needing constant support. You'll partner with engineering teams to find, fix, and prevent vulnerabilities in a platform built primarily on .NET and hosted in Azure, while helping us secure the next generation of AI-powered features. This is a hands-on role for someone who wants to make secure development the path of least resistance for our engineers.

What you’ll do

· Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs. Vulnerability management, end to end. Identify, triage, and drive security findings to closure through the product teams' Azure DevOps backlogs with severity-based SLAs.

· Security tooling in CI/CD. Build, integrate, and operate SAST, SCA, and DAST in Azure DevOps pipelines, including PR gating on new critical and high findings, secret scanning, and automated routing of findings to tickets.

· Azure security. Secure our cloud estate across identity and access management (Entra ID, Auth0), network configuration, secrets management, and workload protection, working with Defender for Cloud policy and posture.

· Threat modeling and reviews. Conduct threat models, design reviews, and code reviews for new and existing services — with a threat model in place before any new service reaches production.

· AI feature security. Evaluate security and privacy implications of our AI functionality, including LLM-specific risks such as prompt injection, data leakage, and model misuse, and define controls for them.

· Standards and enablement. Define and uphold secure coding standards, train engineers, and build a security champion in each product team so risk assessment becomes self-service rather than a security-team bottleneck.

· Pen tests and scans. Coordinate penetration tests and application vulnerability scanning, review the findings, identify fixes, and implement them hands-on when needed.

· Incident response. Support security incident investigation and response as the application subject-matter expert, working with our 24/7 managed detection and response partner.

What you’ll bring

· 8+ years of experience in application security, or in software engineering with a strong security focus.

· Experience integrating and operating security tooling within CI/CD pipelines.

· Strong .NET (C#) working knowledge; ability to read and reason about Python is a plus.

· Fluency in common vulnerability classes (OWASP Top 10, API security risks) and how they manifest in real code — not just in scanner output.

· Hands-on Azure experience: creating resources, securing applications, Azure networking, and secrets management.

· Hands-on experience with Auth0 in production environments.

· Strong communication skills and the ability to influence engineers without owning their backlog.

· A pragmatic, risk-based mindset that balances security with delivery — you know which findings matter and which are noise