Назад
Company hidden
11 часов назад

Cyber Security Engineer (AppSec)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Philippines
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Cyber Security Engineer (AppSec): Improving application security across cloud-native technology estates with an accent on developer-friendly security guardrails and CI/CD pipeline integration. Focus on vulnerability management, threat modelling, and automating security workflows to ensure secure engineering practices are embedded into the delivery lifecycle.

Location: Manila

Company

The hirify.global is a globally recognized news organization dedicated to delivering quality information and impartial journalism.

What you will do

  • Improve application security guardrails across GitHub-based CI/CD pipelines and engineering workflows.
  • Collaborate with product and platform teams to triage vulnerabilities and provide actionable remediation guidance.
  • Facilitate lightweight threat-modelling sessions for new features and services.
  • Develop scripts and tools, primarily in Python, to automate security tasks and improve visibility.
  • Manage security findings from SAST, dependency scanning, and bug bounty reports.
  • Provide secure coding guidance to ensure security is integrated into the development process.

Requirements

  • Practical experience in application security within modern engineering environments.
  • Experience working directly with software engineers to explain and remediate security risks.
  • Proficiency in vulnerability triage, prioritization, and remediation tracking.
  • Familiarity with security tooling such as SAST, software composition analysis, and secret scanning.
  • Ability to write scripts or small tools, ideally in Python, for automation.
  • Strong communication and collaboration skills with familiarity in Agile or Scrum methodologies.

Nice to have

  • Exposure to AWS security, infrastructure-as-code (Terraform/CloudFormation), or container/Kubernetes security.
  • Experience with Splunk or similar SIEM platforms.
  • Exposure to AI security, including LLM-enabled applications and prompt/data leakage risks.
  • Relevant security certifications such as GIAC, ISC2, or CREST.

Culture & Benefits

  • Collaborative and diverse work environment that supports professional growth and wellbeing.
  • Commitment to diversity, equity, and inclusion with a focus on removing barriers for underrepresented groups.
  • Opportunities to work on high-impact projects within a globally recognized news organization.
  • Disability confident employer with support for reasonable adjustments.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →