Назад
Company hidden
1 день назад

Offensive Security Engineer (Fintech)

Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Philippines
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Offensive Security Engineer (Fintech): Leading and executing red-team and advanced penetration-testing engagements across applications, infrastructure, cloud, and identity environments with an accent on adversary simulation, vulnerability chaining, and threat-informed testing. Focus on developing offensive-security tooling, improving detection and response with blue teams, and translating technical findings into actionable risk and remediation guidance.

Location: NCR - WGC, Philippines

Company

hirify.global operates GCash, a large-scale fintech platform providing digital financial solutions to millions of Filipinos.

What you will do

  • Lead and execute red-team and advanced penetration-testing engagements across applications, infrastructure, cloud, and identity environments.
  • Identify, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business impact.
  • Design adversary-simulation scenarios aligned with threat intelligence and the MITRE ATT&CK framework.
  • Work with blue-team, security-engineering, and security-operations teams to improve detection, response, and security posture.
  • Develop tooling, automation, and research to identify weaknesses at scale and improve testing efficiency.
  • Prepare technical and executive reports with risk analysis, impact, and remediation guidance.

Requirements

  • 1–3 years of hands-on experience in red teaming, offensive security, or advanced penetration testing.
  • Demonstrated ability to discover impactful vulnerabilities, including complex or chained attack paths.
  • Strong understanding of web, cloud, identity, and infrastructure attack vectors.
  • Practical experience with adversary simulation and the MITRE ATT&CK framework.
  • Ability to lead, mentor, and influence as a hands-on security leader.
  • At least one practical security certification, such as OSCP, OSEP, OSWE, OSED, OSWP, CRTO, CRTL, CRTP, CRTE, GRTP, CPTS, CWEE, or CAPE.

Nice to have

  • Write-ups, research, bug-bounty findings, or internal and external reports demonstrating offensive-security work.

Culture & Benefits

  • Opportunity for career growth and professional development.
  • Collaboration with a skilled, dynamic, and mission-driven security team.
  • Direct impact on the protection of millions of users and high-value financial systems.
  • Culture focused on technical excellence, ownership, and continuous improvement.
  • Competitive and flexible compensation and benefits package.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →