Azeus Convene

Security Engineer

Azeus Convene Manila, Metro Manila, Philippines

Software Development · 201-500 employees

2 d ago
security Senior (5-10 yrs) Full-time Philippines
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Security Engineer will perform penetration testing, manage the vulnerability lifecycle, and conduct technical investigations on security incidents. They will also collaborate with DevOps teams to implement security best practices and facilitate threat modelling within the software development lifecycle.

What they look for

Penetration testing Vulnerability management Red team Blue team Threat modelling Burpsuite OWASP ZAP Metasploit SonarQube Java JavaScript C/C++ Bash PowerShell AWS SIEM

Requirements

Candidates must have at least 5 years of experience in application security testing and a solid understanding of cybersecurity principles like OWASP Top 10. Proficiency in programming languages such as Java, JavaScript, and C/C++, along with experience in cloud architectures like AWS, is required.

Full description

About the Security Engineer role:

Responsibilities

Involved in Red Team activities:

  • Perform penetration testing of Web and Mobile (iOS, Android, Windows, and Mac) applications
  • Own the vulnerability management lifecycle from identification, remediation to reporting
  • Active monitoring and detection of operational security risks in the organization
  • Conduct technical investigations on security incidents and tools
  • Liaise directly with users on security enquiries and concerns during Pre-sales and Support

Conduct engagement with the Blue Team for the following:

  • Work with engineering and DevOps teams to implement security best practices
  • Implement and improve workflows to automate vulnerability detection as part of the software development lifecycle
  • Review risks and patches of software components used in the applications
  • Facilitate threat modelling as part of the software development lifecycle
  • Help in security awareness training
  • Help in implementing the needed controls for different certification bodies such as ISO 27001 and SOC Type 2

Qualifications

  • At least 5 years of experience in application security testing and assessments
  • Solid understanding of cybersecurity principles, standards, and protocols such as OWASP Top 10 and SANS Critical Security Controls
  • Experience with application security tools such as Burpsuite, OWASP ZAP, Metasploit, SonarQube (experience with Ghidra or IDA is a plus)
  • Experience with programming languages such as Java, JavaScript, C/C++
  • Experience with scripting languages such as Bash or PowerShell
  • Experience and knowledge of cloud solutions and architectures such as AWS
  • Experience and knowledge of Security Information and Event Management (SIEM) technologies
  • Good analytical skills
  • Strong sense of ownership
  • Technical and industry certifications such as CISA, CISM, CISSP are a plus

Others:

  • Successful completion of background check and NBI clearance will be required.

Similar roles