Application Security Engineer Penetration Testing Quality Assurance
Manila - Philippines
Job Summary
We are looking for an experienced Application Security Engineer to serve as the quality-assurance point for penetration testing deliverables across applications and this individual-contributor role you will independently review reports and findings before release confirm that risk ratings and supporting evidence are sound and help application teams move findings through remediation and closure. You will work closely with penetration testers vulnerability management leads and technology stakeholders to maintain consistent reporting standards improve testing quality and provide clear risk-based guidance.
- Perform final quality reviews of penetration test reports before release ensuring findings are technically accurate reproducible supported by sufficient evidence within the approved scope and written for both technical and business audiences.
- Validate affected assets exploitation paths business impact duplicate findings and false positives; challenge conclusions when the evidence does not support the stated risk.
- Review and calibrate severity ratings using CVSS exploitability asset criticality business impact environmental context and existing compensating controls.
- Confirm that test scope methodology coverage assumptions limitations and conclusions are complete and clearly documented; work with testers to address gaps before reports are issued.
- Provide practical risk-based remediation guidance and help application teams understand the issue expected corrective action and evidence required for closure.
- Track open findings and agreed remediation dates coordinate retesting validate corrective actions and document closure decisions or residual risks.
- Triage newly disclosed or emerging vulnerabilities to determine relevance potential exposure required validation and appropriate escalation.
- Support day-to-day Burp Suite and Snyk operations including access requests scan configuration issue triage troubleshooting scheduling reporting and coordination with platform owners.
- Maintain quality standards review checklists reporting templates and operating procedures; identify recurring defects and recommend improvements to testing reporting and aftercare processes.
- Produce accurate status updates and quality metrics and escalate material risks overdue actions or delivery concerns to the appropriate stakeholders.
- Bachelors degree in Computer Science Computer Engineering Information Technology Cybersecurity or a related field or equivalent practical experience.
- At least three years of relevant experience in penetration testing application security vulnerability assessment vulnerability management or security quality assurance.
- Hands-on experience reviewing penetration test reports validating technical evidence assessing exploitability and business impact assigning or challenging severity ratings and confirming remediation through retesting.
- Strong knowledge of web application and API security common attack techniques authentication and authorization weaknesses OWASP testing practices CVSS CWE and vulnerability classification.
- Practical experience with Burp Suite Professional or comparable web and API security testing tools.
- Working knowledge of SAST DAST SCA open-source vulnerability management DevSecOps pipelines and the end-to-end vulnerability management lifecycle.
- Strong analytical judgment and attention to detail with the ability to distinguish material risk from low-value noise and make defensible evidence-based decisions.
- Clear written and verbal communication skills including the ability to explain technical risk and remediation expectations to technical and non-technical stakeholders.
- Ability to manage competing priorities follow through on commitments and work effectively with globally distributed teams.
- Amenable to a hybrid work arrangement at UP Ayala Technohub Quezon City with three onsite days per week.
- Amenable to a fixed late mid-shift or night-shift schedule based on business requirements.
- Experience performing or reviewing penetration tests for web applications APIs mobile applications cloud environments or networks including assessments delivered by third-party providers.
- Experience in enterprise application security or vulnerability management within financial services insurance or another regulated industry.
- Familiarity with OWASP WSTG PTES NIST SP 800-115 or comparable penetration testing and reporting standards.
- Experience using vulnerability management or issue-tracking platforms to manage evidence ownership remediation dates exceptions retesting and closure.
- Experience with Snyk administration or enterprise application security tooling including onboarding scan configuration troubleshooting reporting and stakeholder support.
- Ability to automate data processing quality checks workflow updates dashboards or reports using Python PowerShell Unix shell VBA or a similar scripting language.
- A relevant certification such as OSCP OSWE CREST CCT/CRT GIAC GWAPT/GPEN CompTIA PenTest or an equivalent credential.
- Penetration test reports are complete technically defensible consistent and ready for stakeholders on time.
- Findings are accurately prioritized clearly explained and supported by evidence that enables timely remediation.
- Retesting and closure decisions are traceable risk-based and aligned with established standards.
- Recurring quality issues are identified and converted into practical improvements to testing reporting and aftercare processes.
- undefined
When you join our team:
Well empower you to learn and grow the career you want. Well recognize and support you in a flexible environment where well-being and inclusion are more than just words. As part of our global team well support you in shaping the future you want to see.
Manulife is an Equal Opportunity EmployerAt Manulife/JohnHancock we embrace our diversity. We strive to attractdevelopandretaina workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment retentionadvancement and compensation and we administer all of our practices and programs without discrimination on the basis of race ancestry place of origincolour ethnic origin citizenship religion or religious beliefs creed sex (including pregnancy and pregnancy-related conditions) sexual orientation genetic characteristics veteran status gender identity gender expression age marital status family status disability or any other ground protected by applicable law.It is our priority to remove barriers toprovideequal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application information shared during the accommodation request process will be stored and used in a manner that is consistent withapplicable laws and Manulife/John Hancock request a reasonable accommodation in the application process contact .
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider helping people make their decisions easier and lives better. To learn more about us visit is an Equal Opportunity Employer
At Manulife/John Hancock we embrace our diversity. We strive to attract develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment retention advancement and compensation and we administer all of our practices and programs without discrimination on the basis of race ancestry place of origin colour ethnic origin citizenship religion or religious beliefs creed sex (including pregnancy and pregnancy-related conditions) sexual orientation genetic characteristics veteran status gender identity gender expression age marital status family status disability or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process contact .
Working Arrangement
Required Experience:
IC
About Company
Manulife is a leading financial services group. We provide financial advice, insurance, as well as wealth and asset management solutions for individuals, groups and institutions.