GoTyme PH (Philippines)

Senior Cyber Security Engineer

GoTyme PH (Philippines) Quezon City, Metro Manila, Philippines

Financial Services · 201-500 employees

5 h ago
Remote security Senior (5-10 yrs) Full-time Philippines
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Senior Cyber Security Engineer will lead advanced security monitoring, threat detection, and incident response activities across cloud and endpoint environments. They will also design security controls, mentor junior staff, and partner with business teams to strengthen the organization's overall security posture.

What they look for

Cybersecurity Engineering Incident Response Threat Hunting Cloud Security AWS Security Azure Security SIEM SOAR EDR/XDR Identity and Access Management Python PowerShell Bash Forensics Malware Analysis Detection Engineering

Requirements

Candidates must have 7–10+ years of hands-on experience in cybersecurity engineering or security operations, along with a bachelor's degree in a relevant field. Strong technical expertise in AWS, Azure, EDR/XDR platforms, and automation scripting is required.

Full description

About GoTyme

GoTyme is a joint venture between the Gokongwei Group, one of the biggest conglomerates in the Philippines, and the Singapore-headquartered digital banking group Tyme. This venture combines the trusted Gokongwei brand, customer base, and distribution ecosystem with Tyme’s globally proven digital banking technology and hands-on experience building South Africa’s leading digital bank, TymeBank, one of the fastest-growing digital banks in the world today.

At GoTyme, we have embarked on a journey to democratize financial services and bring next-level banking to the Philippines. We seek individuals who share our belief that the game is worth changing, to join our growing team of GoTymers as we build, launch, and scale a bank that empowers all Filipinos to navigate a path to financial freedom.

About the role

We are seeking a Senior Cyber Security Engineer to join our cybersecurity team, operating with an AI- and automation-first mindset. This role goes beyond monitoring and response and requires technical leadership, deep investigative expertise, and the ability to design, improve, and scale security controls across cloud, endpoint, and identity environments.

The successful candidate will act as a subject-matter expert, leading complex investigations, driving proactive threat detection, mentoring junior engineers, and partnering with technology and business teams to continuously strengthen the organisation’s security posture.

Security Monitoring, Engineering & Analysis• Lead advanced monitoring and analysis of security events across AWS, Azure, and endpoint platforms

  • Design, enhance, and optimise detection logic using CloudTrail, GuardDuty, Security Hub, Azure Sentinel, Defender, and EDR/XDR tools
  • Proactively identify security gaps, misconfigurations, and control weaknesses across cloud and SaaS environments
  • Develop and maintain automated detection and response workflows using scripting and SOAR principles
  • Perform deep analysis of DLP alerts, ensuring protection of sensitive and regulated data

Incident Response, Forensics & Crisis Management• Act as a lead investigator for high-severity security incidents

  • Drive end-to-end incident response activities, including containment, eradication, and recovery
  • Conduct advanced host, cloud, and log-based forensic analysis
  • Produce executive-level incident reports, root-cause analyses, and post-incident improvement plans
  • Support tabletop exercises, incident simulations, and continuous improvement of IR playbooks

Threat Detection, Hunting & Intelligence• Lead proactive threat hunting activities using behavioural analytics and threat intelligence

  • Map detections to MITRE ATT&CK and continuously improve coverage
  • Perform advanced malware analysis and support reverse-engineering efforts when required
  • Translate threat intelligence into actionable detections and preventive controls
  • Stay ahead of emerging attack techniques, cloud-native threats, and identity-based attacks

Identity, Access & Privileged Security• Oversee monitoring and investigation of privileged access and identity-based threats

  • Lead IAM security reviews and contribute to least-privilege and zero-trust initiatives
  • Investigate anomalous authentication behaviour and insider-risk indicators
  • Partner with IAM teams to strengthen identity security architecture and controls

Security Engineering, Architecture & Enablement• Contribute to the design and improvement of cloud and enterprise security architectures

  • Define security requirements for new platforms, services, and integrations
  • Support compliance initiatives aligned to ISO 27001, SOC 2, NIST, PCI DSS and internal risk frameworks
  • Mentor junior engineers and analysts, providing technical guidance and review
  • Influence security strategy through technical insight and data-driven recommendations
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field
  • 7–10+ years of hands-on experience in cybersecurity engineering, SOC, or security operations roles
  • Demonstrated experience leading complex security investigations and incident response
  • Proven ability to design, tune, and maintain security detections at scale
  • Experience mentoring or technically leading other security practitioners
  • Deep expertise in AWS security services (CloudTrail, GuardDuty, Config, Security Hub)
  • Strong experience with Azure security tooling (Sentinel, Defender, Security Center)
  • Advanced knowledge of EDR/XDR platforms and endpoint telemetry
  • Hands-on experience with SIEM, SOAR, and log analytics platforms
  • Strong understanding of networking, IAM, authentication protocols, and attack vectors
  • Proficiency in Python, PowerShell, or Bash for automation and analysis
  • Experience applying threat hunting and detection engineering methodologies
  • Familiarity with AI-driven security tooling and prompt-based analysis

Similar roles