Назад
Company hidden
2 мСсяца Π½Π°Π·Π°Π΄

Offensive Security Engineer (Fintech)

Π€ΠΎΡ€ΠΌΠ°Ρ‚ Ρ€Π°Π±ΠΎΡ‚Ρ‹
onsite
Π’ΠΈΠΏ Ρ€Π°Π±ΠΎΡ‚Ρ‹
fulltime
Π“Ρ€Π΅ΠΉΠ΄
lead
Английский
b2
Π‘Ρ‚Ρ€Π°Π½Π°
Philippines
Вакансия ΠΈΠ· списка Hirify.GlobalВакансия ΠΈΠ· Hirify Global, списка ΠΌΠ΅ΠΆΠ΄ΡƒΠ½Π°Ρ€ΠΎΠ΄Π½Ρ‹Ρ… tech-ΠΊΠΎΠΌΠΏΠ°Π½ΠΈΠΉ
Для мэтча ΠΈ ΠΎΡ‚ΠΊΠ»ΠΈΠΊΠ° Π½ΡƒΠΆΠ΅Π½ Plus

ΠœΡΡ‚Ρ‡ & Π‘ΠΎΠΏΡ€ΠΎΠ²ΠΎΠ΄

Для мэтча с этой вакансиСй Π½ΡƒΠΆΠ΅Π½ Plus

ОписаниС вакансии

ВСкст:
/
TL;DR
Offensive Security Engineer (Fintech): Leading and executing red-team and advanced penetration-testing engagements across applications, infrastructure, cloud, and identity environments with an accent on adversary simulation, vulnerability chaining, and threat-informed testing. Focus on developing offensive-security tooling, improving detection and response with blue teams, and translating technical findings into actionable risk and remediation guidance.

Location: NCR - WGC, Philippines

Company

hirify.global operates GCash, a large-scale fintech platform providing digital financial solutions to millions of Filipinos.

What you will do

  • Lead and execute red-team and advanced penetration-testing engagements across applications, infrastructure, cloud, and identity environments.
  • Identify, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business impact.
  • Design adversary-simulation scenarios aligned with threat intelligence and the MITRE ATT&CK framework.
  • Work with blue-team, security-engineering, and security-operations teams to improve detection, response, and security posture.
  • Develop tooling, automation, and research to identify weaknesses at scale and improve testing efficiency.
  • Prepare technical and executive reports with risk analysis, impact, and remediation guidance.

Requirements

  • 1–3 years of hands-on experience in red teaming, offensive security, or advanced penetration testing.
  • Demonstrated ability to discover impactful vulnerabilities, including complex or chained attack paths.
  • Strong understanding of web, cloud, identity, and infrastructure attack vectors.
  • Practical experience with adversary simulation and the MITRE ATT&CK framework.
  • Ability to lead, mentor, and influence as a hands-on security leader.
  • At least one practical security certification, such as OSCP, OSEP, OSWE, OSED, OSWP, CRTO, CRTL, CRTP, CRTE, GRTP, CPTS, CWEE, or CAPE.

Nice to have

  • Write-ups, research, bug-bounty findings, or internal and external reports demonstrating offensive-security work.

Culture & Benefits

  • Opportunity for career growth and professional development.
  • Collaboration with a skilled, dynamic, and mission-driven security team.
  • Direct impact on the protection of millions of users and high-value financial systems.
  • Culture focused on technical excellence, ownership, and continuous improvement.
  • Competitive and flexible compensation and benefits package.

Π‘ΡƒΠ΄ΡŒΡ‚Π΅ остороТны: Ссли Ρ€Π°Π±ΠΎΡ‚ΠΎΠ΄Π°Ρ‚Π΅Π»ΡŒ просит Π²ΠΎΠΉΡ‚ΠΈ Π² ΠΈΡ… систСму, ΠΈΡΠΏΠΎΠ»ΡŒΠ·ΡƒΡ iCloud/Google, ΠΏΡ€ΠΈΡΠ»Π°Ρ‚ΡŒ ΠΊΠΎΠ΄/ΠΏΠ°Ρ€ΠΎΠ»ΡŒ, Π·Π°ΠΏΡƒΡΡ‚ΠΈΡ‚ΡŒ ΠΊΠΎΠ΄/ПО, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡ‚Π΅ этого - это мошСнники. ΠžΠ±ΡΠ·Π°Ρ‚Π΅Π»ΡŒΠ½ΠΎ ΠΆΠΌΠΈΡ‚Π΅ "ΠŸΠΎΠΆΠ°Π»ΠΎΠ²Π°Ρ‚ΡŒΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡˆΠΈΡ‚Π΅ Π² ΠΏΠΎΠ΄Π΄Π΅Ρ€ΠΆΠΊΡƒ. ΠŸΠΎΠ΄Ρ€ΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β†’