Senior Cyber Security Engineer
GoTyme PH (Philippines) Quezon City, Metro Manila, Philippines
Financial Services · 201-500 employees
About the role
The Senior Cyber Security Engineer will lead advanced security monitoring, threat detection, and incident response activities across cloud and endpoint environments. They will also design security controls, mentor junior staff, and partner with business teams to strengthen the organization's overall security posture.
What they look for
Requirements
Candidates must have 7–10+ years of hands-on experience in cybersecurity engineering or security operations, along with a bachelor's degree in a relevant field. Strong technical expertise in AWS, Azure, EDR/XDR platforms, and automation scripting is required.
Full description
About GoTyme
GoTyme is a joint venture between the Gokongwei Group, one of the biggest conglomerates in the Philippines, and the Singapore-headquartered digital banking group Tyme. This venture combines the trusted Gokongwei brand, customer base, and distribution ecosystem with Tyme’s globally proven digital banking technology and hands-on experience building South Africa’s leading digital bank, TymeBank, one of the fastest-growing digital banks in the world today.
At GoTyme, we have embarked on a journey to democratize financial services and bring next-level banking to the Philippines. We seek individuals who share our belief that the game is worth changing, to join our growing team of GoTymers as we build, launch, and scale a bank that empowers all Filipinos to navigate a path to financial freedom.
About the role
We are seeking a Senior Cyber Security Engineer to join our cybersecurity team, operating with an AI- and automation-first mindset. This role goes beyond monitoring and response and requires technical leadership, deep investigative expertise, and the ability to design, improve, and scale security controls across cloud, endpoint, and identity environments.
The successful candidate will act as a subject-matter expert, leading complex investigations, driving proactive threat detection, mentoring junior engineers, and partnering with technology and business teams to continuously strengthen the organisation’s security posture.
Security Monitoring, Engineering & Analysis• Lead advanced monitoring and analysis of security events across AWS, Azure, and endpoint platforms
- Design, enhance, and optimise detection logic using CloudTrail, GuardDuty, Security Hub, Azure Sentinel, Defender, and EDR/XDR tools
- Proactively identify security gaps, misconfigurations, and control weaknesses across cloud and SaaS environments
- Develop and maintain automated detection and response workflows using scripting and SOAR principles
- Perform deep analysis of DLP alerts, ensuring protection of sensitive and regulated data
Incident Response, Forensics & Crisis Management• Act as a lead investigator for high-severity security incidents
- Drive end-to-end incident response activities, including containment, eradication, and recovery
- Conduct advanced host, cloud, and log-based forensic analysis
- Produce executive-level incident reports, root-cause analyses, and post-incident improvement plans
- Support tabletop exercises, incident simulations, and continuous improvement of IR playbooks
Threat Detection, Hunting & Intelligence• Lead proactive threat hunting activities using behavioural analytics and threat intelligence
- Map detections to MITRE ATT&CK and continuously improve coverage
- Perform advanced malware analysis and support reverse-engineering efforts when required
- Translate threat intelligence into actionable detections and preventive controls
- Stay ahead of emerging attack techniques, cloud-native threats, and identity-based attacks
Identity, Access & Privileged Security• Oversee monitoring and investigation of privileged access and identity-based threats
- Lead IAM security reviews and contribute to least-privilege and zero-trust initiatives
- Investigate anomalous authentication behaviour and insider-risk indicators
- Partner with IAM teams to strengthen identity security architecture and controls
Security Engineering, Architecture & Enablement• Contribute to the design and improvement of cloud and enterprise security architectures
- Define security requirements for new platforms, services, and integrations
- Support compliance initiatives aligned to ISO 27001, SOC 2, NIST, PCI DSS and internal risk frameworks
- Mentor junior engineers and analysts, providing technical guidance and review
- Influence security strategy through technical insight and data-driven recommendations
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field
- 7–10+ years of hands-on experience in cybersecurity engineering, SOC, or security operations roles
- Demonstrated experience leading complex security investigations and incident response
- Proven ability to design, tune, and maintain security detections at scale
- Experience mentoring or technically leading other security practitioners
- Deep expertise in AWS security services (CloudTrail, GuardDuty, Config, Security Hub)
- Strong experience with Azure security tooling (Sentinel, Defender, Security Center)
- Advanced knowledge of EDR/XDR platforms and endpoint telemetry
- Hands-on experience with SIEM, SOAR, and log analytics platforms
- Strong understanding of networking, IAM, authentication protocols, and attack vectors
- Proficiency in Python, PowerShell, or Bash for automation and analysis
- Experience applying threat hunting and detection engineering methodologies
- Familiarity with AI-driven security tooling and prompt-based analysis
Similar roles
-
Information Security Engineer - Cloud Security
Ryanair Group Holdings Wrocław, Lower Silesian Voivodeship, Poland
-
Cybersecurity Threat Analyst - English(US)
Welocalize Arlington, Texas, United States · $112K/yr
-
Cybersecurity Threat Analyst - English(Philippines)
Welocalize Manila, Metro Manila, Philippines · $19K/yr
-
Cybersecurity Threat Analyst - English(India)
Welocalize Delhi, India · $21K/yr
-
Cloud Security Engineer, Product Security
Recorded Future Gothenburg, Västra Götaland County, Sweden
-
Cybersecurity Risk Analyst
Inetum Porto, Portugal