Security Engineer
Azeus Convene Manila, Metro Manila, Philippines
Software Development · 201-500 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Security Engineer will perform penetration testing, manage the vulnerability lifecycle, and conduct technical investigations on security incidents. They will also collaborate with DevOps teams to implement security best practices and facilitate threat modelling within the software development lifecycle.
What they look for
Requirements
Candidates must have at least 5 years of experience in application security testing and a solid understanding of cybersecurity principles like OWASP Top 10. Proficiency in programming languages such as Java, JavaScript, and C/C++, along with experience in cloud architectures like AWS, is required.
Full description
About the Security Engineer role:
Responsibilities
Involved in Red Team activities:
- Perform penetration testing of Web and Mobile (iOS, Android, Windows, and Mac) applications
- Own the vulnerability management lifecycle from identification, remediation to reporting
- Active monitoring and detection of operational security risks in the organization
- Conduct technical investigations on security incidents and tools
- Liaise directly with users on security enquiries and concerns during Pre-sales and Support
Conduct engagement with the Blue Team for the following:
- Work with engineering and DevOps teams to implement security best practices
- Implement and improve workflows to automate vulnerability detection as part of the software development lifecycle
- Review risks and patches of software components used in the applications
- Facilitate threat modelling as part of the software development lifecycle
- Help in security awareness training
- Help in implementing the needed controls for different certification bodies such as ISO 27001 and SOC Type 2
Qualifications
- At least 5 years of experience in application security testing and assessments
- Solid understanding of cybersecurity principles, standards, and protocols such as OWASP Top 10 and SANS Critical Security Controls
- Experience with application security tools such as Burpsuite, OWASP ZAP, Metasploit, SonarQube (experience with Ghidra or IDA is a plus)
- Experience with programming languages such as Java, JavaScript, C/C++
- Experience with scripting languages such as Bash or PowerShell
- Experience and knowledge of cloud solutions and architectures such as AWS
- Experience and knowledge of Security Information and Event Management (SIEM) technologies
- Good analytical skills
- Strong sense of ownership
- Technical and industry certifications such as CISA, CISM, CISSP are a plus
Others:
- Successful completion of background check and NBI clearance will be required.
Similar roles
-
Senior Cybersecurity Engineer, Product Security
CHAOS Industries El Segundo, California, United States
-
Infrastructure Security Engineer (Bare Metal & Platform)
SpaceXAI Palo Alto, California, United States · $100K–$258K/yr
-
Technology & Cybersecurity Risk Management Analyst
Toyota Tsusho Systems Plano, Texas, United States
-
Senior Consultant- CyberSecurity
Sia New York, New York, United States · $131K–$136K/yr
-
Senior Game Application Security Analyst
PlayStation Global United States · $177K–$266K/yr
-
Principal Technical Advisor for Cybersecurity Incident Response
Microsoft Irving, Texas, United States · $131K–$304K/yr