Talent.com
Application Security Manager
Application Security ManagerPwC • Makati
Application Security Manager

Application Security Manager

PwC • Makati
30+ days ago
Job description

Description

& SummaryA career in our Security Architecture practice, within Cybersecurity and Privacy services, will provide you with the opportunity to help our clients implement an effective cybersecurity programme that protects against threats, propels transformation, and drives growth. As companies pivot toward a digital business model, exponentially more data is generated and shared among organisations, partners and customers. You’ll play an integral role in helping our clients ensure they are protected by developing transformation strategies focused on security, efficiently integrate and manage new or existing technology systems to deliver continuous operational improvements and increase their cybersecurity investment, and detect, respond, and remediate threats.

In joining, you’ll be a part of a team that helps organisations design and create sustainable security solutions to provide foundational capabilities and operational discipline through a focus on enterprise requirements and prioritisation, Information Technology security architecture, and the software development lifecycle.

Job Responsibilities:

  • Manage, direct and deliver cyber-attack simulations as part of the RED team activity
  • Manage, direct and deliver Vulnerability Assessment (VA) and Penetration Testing (PT) and configuration review for network, web, mobile and thick-client applications, APIs, POS etc
  • Manage, direct and deliver source-code review using automated and manual approaches, review results to eliminate false positives
  • Manage, direct and deliver configuration reviews for OS , DB, Firewall, routers, switches and other security devices/components
  • Perform and deliver gap analysis and assessments based on standards, guidelines, notices, circulars (eg., ISO27K1, MAS TRM, HKMA etc)
  • Prepare and review detailed reports and ensure timely delivery of status updates and final reports to clients

Provide technical guidance with respect to the development and execution of our key application security service offerings, including:

  • conducting assessments of applications (web, cloud, mobile, API) using range of manual and automated source code review techniques;
  • performing security architecture reviews and risk assessments for applications in design and production phases;
  • identifying potential threats and attacks to applications systems through threat modeling;
  • identifying security recommendations and aligning them to appropriate risk ranking systems;
  • integrating application security tools and process in pipeline;
  • agile penetration testing; evaluating, developing, enhancing and/or running application security programs for our clients;
  • conducting the above with a specific focus on DevSecOps.
  • Manage client stakeholders, provide project status updates, discuss findings and explain recommendations
  • Work with clients to analyze, evaluate, and enhance the effectiveness of their application/product security posture at procedural and technological levels from design to deployment.
  • Keep abreast of the latest IT Security news, exploits, hacks

Essential Skills:

  • Manage projects, team members and client stakeholders for successful delivery
  • Manage project economics
  • Thorough and practical knowledge of OWASP, network protocols, data on the wire, and covert channels
  • Hands on experience with popular security tools – Nmap, Nessus, Kali, Metasploit, BurpSuite, Netsparker, OWASP CSRF Tester, Fortify/Checkmarx, SonarQube, Synopsys, SQLite browser, Drozer
  • Working knowledge of manual testing of web applications
  • Understands Software Development Life Cycle and SOAP, REST and GraphQL APIs
  • Skills in performing VAPT for Web applications, Mobile applications, APIs, Network infrastructure, Thick client applications
  • Good knowledge of modifying and compiling exploit code
  • Good understanding and knowledge of codes languages
  • Has practical experience in auditing various OS, DB, Network and Security technologies
  • Strong understanding Unix/Linux/Mac/Windows, operating systems, including bash and Powershell

Experience in at least three of the following:

  • Set up and operate red team infrastructure
  • Perform targeted, covert penetration tests with vulnerability identification, exploitation, and post-exploitation activities
  • Email, phone, or physical social-engineering assessments
  • Developing, extending, or modifying exploits, shellcode or exploit tools
  • Reverse engineering malware, data obfuscators, or ciphers
  • Strong credentials in wireless, web application, and network security testing
  • Familiar with MITRE ATT&CK framework and D3FEND matrix

Educational Requirements & Experience

  • Bachelors in Computer Science/IT/Electronics Engineering or equivalent University degree.
  • Minimum of 5-7 years of experience in the managing and delivering security tests and compliance review projects.
  • Certifications: CREST CRT, CREST CPSA, Offensive Security Certified Professional (OSCP), GIAC Certified Web Application Defender (GWEB)
  • Other Certifications: OSWP, BSCP, Certified Red Team Professional

Education

Degrees/Field of Study required: Bachelor of Science - Information TechnologyDegrees/Field of Study preferred:

Certifications

Required Skills

Optional Skills

Desired Languages

Travel Requirements

Not Specified

Available for Work Visa Sponsorship?

No

Government Clearance Required?

Yes

Job Posting End Date

Create a job alert for this search

Application Security Manager • Makati

Similar jobs
Application Security Engineer

Application Security Engineer

SYSGEN RPO • national capital region, ph
This role involves triaging and demonstrating the impact of security vulnerabilities, maintaining security scanning tools, and serving as the technical escalation point for complex security issues....Show more
Last updated: 7 days ago • Promoted
Cyber Security Engineer - Identity and Access Management

Cyber Security Engineer - Identity and Access Management

Netrust Philippines Corporation • national capital region, ph
Take ownership of managing and securing user identities and access to systems, applications, and resources within the organization.Design, implement, and maintain identity and access management (IA...Show more
Last updated: 7 days ago • Promoted
Infrastructure Security Engineer

Infrastructure Security Engineer

Maya • national capital region, ph
The primary objective of Information Security Specialist is to build the mindset that \"security is everyone’s responsibility\" with the goal of safely distributing security decisions at speed and ...Show more
Last updated: 7 days ago • Promoted
Senior Application Security Engineer - Remote SSDLC Leader

Senior Application Security Engineer - Remote SSDLC Leader

Hammerjack Pty Ltd • Quezon City, Metro Manila, Philippines
A global technology company is seeking a highly skilled Senior Application Security Engineer to enhance their secure software development lifecycle.This role offers 100% remote work, focusing on in...Show more
Last updated: 11 days ago • Promoted
SAP Business Technology Platform (BTP) Security Architect Manager

SAP Business Technology Platform (BTP) Security Architect Manager

JTI • national capital region, ph
SAP Business Technology Platform (BTP) Security Architect Manager.In this role, you will be designing and maintaining access model and governance related business processes based on information fro...Show more
Last updated: 7 days ago • Promoted
Security Engineering Manager

Security Engineering Manager

DFI Retail Group • national capital region, ph
This role will assist the IT organization to implement on enhance network security system from Group requirements and collaborate with 1st line of response team to handle network and cyber security...Show more
Last updated: 7 days ago • Promoted
Manager, Information Security & Data Privacy Engineering

Manager, Information Security & Data Privacy Engineering

ABSI • national capital region, ph
Job Roles and Responsibilities.The Manager, Information Security & Data Privacy Engineering is a senior security leadership role responsible for architecting and operationalizing a \"Trust by Desig...Show more
Last updated: 7 days ago • Promoted
Security Operations Center

Security Operations Center

SYSGEN RPO • national capital region, ph
We’re Hiring: IT Specialist – Security Operations Center (SOC).IT Specialist – Security Operations Center (SOC).This role is critical in identifying, analyzing, and responding to IT security threat...Show more
Last updated: 7 days ago • Promoted
Security and Risk 1, Exposure Management & Security Development

Security and Risk 1, Exposure Management & Security Development

Asurion • national capital region, ph
This is an exciting opportunity to join Asurion as a Security and Risk 1 within the Exposure Management & Security Development team.As a full-time position based in Taguig City, Metro Manila, you w...Show more
Last updated: 7 days ago • Promoted
Security Operations Center Analyst

Security Operations Center Analyst

Elite Workforce Partners • national capital region, ph
We specialize in helping companies build highly skilled teams to achieve sustainable growth and profitability.Through our services, businesses gain access to experienced professionals at a fraction...Show more
Last updated: 7 days ago • Promoted
Information Security Analyst

Information Security Analyst

DITO Telecommunity Corporation • national capital region, ph
As an Information Security Analyst, you will be working collaboratively with CIS in managing cybersecurity risk management and compliance.You will have an opportunity to develop your skills across ...Show more
Last updated: 7 days ago • Promoted
Application Security Architect

Application Security Architect

Tyler Technologies, Inc. • Manila, Metro Manila, Philippines
Position SummaryWe are seeking a highly independent and proactive Subject Matter Expert (SME) to drive quality and documentation standards across our products.You will be responsible for testing pr...Show more
Last updated: 13 days ago • Promoted
Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst

Cyber Defence - Global Security Operations Centre (GSOC) Level 2 Analyst

Risewave Consulting, Inc. • national capital region, ph
Cyber Defense Center or Security Operations Center (SOC).Linux, macOS, and Windows operating systems.Any relevant security certifications (SC-200, SC-900, Security+, CySA+, CASP+, etc.Any relevant ...Show more
Last updated: 14 hours ago • Promoted • New!
Specialist - Cyber Security Program Governance and Analytics

Specialist - Cyber Security Program Governance and Analytics

Smart Communications, Inc. • national capital region, ph
This role oversees enterprise-wide Cybersecurity program governance, ensuring strategic alignment, delivery excellence, and adherence to established frameworks.It manages resources, vendor performa...Show more
Last updated: 5 days ago • Promoted
Application Security Analyst

Application Security Analyst

SYSGEN RPO • national capital region, ph
This position requires a collaborative approach, working closely with development teams to triage vulnerabilities and inefficiencies identified in security scans.The overarching objective of the ap...Show more
Last updated: 5 days ago • Promoted
Senior Application Security Engineer (SecApp)

Senior Application Security Engineer (SecApp)

Hammerjack Pty Ltd • Makati, Metro Manila, Philippines
It's fun to work in a company where people truly BELIEVE in what they're doing!.We're committed to bringing passion and customer focus to the business.Avid makes technology and collaborative tools ...Show more
Last updated: 11 days ago • Promoted
Assistant Security Manager

Assistant Security Manager

Asian Terminals Inc. (ATI) • national capital region, ph
The role of this position is to support the Security Manager in ensuring the effective protection of ATI’s port facilities, personnel, and assets.The Assistant Security Manager will assist in overs...Show more
Last updated: 7 days ago • Promoted
Application Security Support Manager

Application Security Support Manager

SM Investments • national capital region, ph
At SM Investments, we shape sustainable growth stories that move industries and uplift communities.As one of the Philippines’ leading conglomerates, we build opportunities across retail, banking, a...Show more
Last updated: 7 days ago • Promoted