Назад
Company hidden
2 дня назад

Manager, Offensive Security Engineer (Fintech)

Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Philippines
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager, Offensive Security Engineer (Fintech): Leading red team and advanced penetration testing engagements across applications, infrastructure, cloud, and identity environments with an accent on adversary simulation, vulnerability chaining, and threat-informed testing. Focus on mentoring offensive security engineers, improving detection and response with security teams, and translating technical findings into business-impactful remediation guidance.

Location: NCR - WGC, Philippines

Company

hirify.global operates GCash, a fintech company creating digital financial solutions for the Philippines.

What you will do

  • Lead and execute red team and advanced penetration testing engagements across applications, infrastructure, cloud, and identity environments.
  • Identify, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business impact.
  • Design adversary simulation scenarios informed by threat intelligence and the MITRE ATT&CK framework.
  • Partner with blue team, security engineering, and security operations teams to improve detection, response, and security posture.
  • Develop tooling, automation, and research to identify security weaknesses at scale and improve testing efficiency.
  • Mentor offensive security engineers and produce technical and executive-level reports with remediation guidance.

Requirements

  • 3–5 years of hands-on experience in red teaming, offensive security, or advanced penetration testing.
  • Track record of discovering impactful vulnerabilities, including complex or chained attack paths.
  • Strong understanding of web, cloud, identity, and infrastructure attack vectors.
  • Practical experience with adversary simulation and the MITRE ATT&CK framework.
  • Ability to lead, mentor, and influence in a hands-on leadership role.
  • Strong written and verbal communication skills, including the ability to explain technical risk to engineers and executives.

Nice to have

  • At least one practical and one theoretical security certification.
  • Practical certifications such as OSCP, OSEP, OSWE, OSED, OSWP, CRTO, CRTL, CRTP, CRTE, GRTP, CPTS, CWEE, or CAPE.
  • Theoretical certifications such as CISSP, CISM, or equivalent.

Culture & Benefits

  • Career growth and development opportunities.
  • Dynamic and highly collaborative working environment.
  • Competitive and flexible compensation and benefits package.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →