2 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄
Offensive Security Engineer (Fintech)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
Offensive Security Engineer (Fintech): Leading and executing red-team and advanced penetration-testing engagements across applications, infrastructure, cloud, and identity environments with an accent on adversary simulation, vulnerability chaining, and threat-informed testing. Focus on developing offensive-security tooling, improving detection and response with blue teams, and translating technical findings into actionable risk and remediation guidance.
Location: NCR - WGC, Philippines
Company
operates GCash, a large-scale fintech platform providing digital financial solutions to millions of Filipinos.
What you will do
- Lead and execute red-team and advanced penetration-testing engagements across applications, infrastructure, cloud, and identity environments.
- Identify, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business impact.
- Design adversary-simulation scenarios aligned with threat intelligence and the MITRE ATT&CK framework.
- Work with blue-team, security-engineering, and security-operations teams to improve detection, response, and security posture.
- Develop tooling, automation, and research to identify weaknesses at scale and improve testing efficiency.
- Prepare technical and executive reports with risk analysis, impact, and remediation guidance.
Requirements
- 1β3 years of hands-on experience in red teaming, offensive security, or advanced penetration testing.
- Demonstrated ability to discover impactful vulnerabilities, including complex or chained attack paths.
- Strong understanding of web, cloud, identity, and infrastructure attack vectors.
- Practical experience with adversary simulation and the MITRE ATT&CK framework.
- Ability to lead, mentor, and influence as a hands-on security leader.
- At least one practical security certification, such as OSCP, OSEP, OSWE, OSED, OSWP, CRTO, CRTL, CRTP, CRTE, GRTP, CPTS, CWEE, or CAPE.
Nice to have
- Write-ups, research, bug-bounty findings, or internal and external reports demonstrating offensive-security work.
Culture & Benefits
- Opportunity for career growth and professional development.
- Collaboration with a skilled, dynamic, and mission-driven security team.
- Direct impact on the protection of millions of users and high-value financial systems.
- Culture focused on technical excellence, ownership, and continuous improvement.
- Competitive and flexible compensation and benefits package.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β