- Workplace
- Onsite
- Type
- Full-time
- Department
- Security
- Seniority
- Entry
- Experience
- 1+ years
- Education
- Bachelor
- Source
- RecruiterFlow
Description
Location: Ortigas
Work Setup: Onsite
Compensation Range: up to ₱60,000
KEY RESPONSIBILITIES
-
Conduct vulnerability assessments and penetration testing across web applications, mobile applications, and other relevant technology environments to identify and validate security weaknesses.
-
Prepare, document, and submit VAPT reports, periodic assessment reports, and other required security documentation.
-
Present assessment findings to stakeholders in a clear and concise manner, providing actionable remediation recommendations.
-
Support cybersecurity and non-cybersecurity teams in vulnerability assessments, penetration testing activities, and security-related initiatives.
-
Validate, monitor, and track identified vulnerabilities through remediation and closure, including findings from various threat intelligence sources.
-
Monitor Common Vulnerabilities and Exposures (CVEs), conduct zero-day vulnerability analysis, and support cloud security assessment activities.
-
Contribute to Threat Exposure and Attack Surface Management initiatives to identify, assess, and reduce organizational exposure to security risks.
-
Analyze technical vulnerabilities, evaluate potential business impacts, and recommend appropriate mitigation and remediation measures.
REQUIRED QUALIFICATIONS
-
Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or another related four-year degree program.
-
At least 1 year of hands-on experience in web and/or mobile application vulnerability assessment and penetration testing (VAPT), penetration testing, or security research.
-
Strong understanding of the OWASP Top 10 and its application in web application security testing.
-
Hands-on experience with open-source and/or commercial security testing tools, such as Kali Linux, Metasploit, Qualys, Nessus, Burp Suite, OWASP ZAP, or equivalent tools.
-
Ability to identify and validate vulnerabilities, interpret technical findings, and recommend appropriate remediation measures.
-
Strong analytical, problem-solving, technical documentation, and communication skills.
PREFERRED QUALIFICATIONS
-
Knowledge of Industrial Control Systems (ICS), Operational Technology (OT), DevOps, or related technologies.
-
Working knowledge of web and mobile application development, common application architectures, and associated security risks.
-
Experience assessing vulnerabilities identified through threat intelligence sources and supporting vulnerability remediation tracking.
-
Familiarity with cloud security, CVE monitoring, zero-day vulnerability analysis, and Threat Exposure and Attack Surface Management initiatives.
-
Cybersecurity certifications such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or other relevant industry certifications.
REQUIRED SKILLS & TECHNOLOGIES
-
Vulnerability Assessment & Penetration Testing: Web and mobile application VAPT, penetration testing, vulnerability validation, risk assessment, and remediation tracking.
-
Security Frameworks: OWASP Top 10 and common application security vulnerabilities.
-
Security Testing Tools: Kali Linux, Metasploit, Qualys, Nessus, Burp Suite, OWASP ZAP, and equivalent tools.
-
Threat & Vulnerability Management: CVE monitoring, threat intelligence analysis, zero-day vulnerability assessment, and vulnerability lifecycle management.
-
Cloud & Infrastructure Security: Cloud security assessment and familiarity with relevant infrastructure security risks.
-
Emerging Security Areas: Threat Exposure and Attack Surface Management, with exposure to ICS, OT, or DevOps environments considered an advantage.
-
Reporting & Communication: VAPT reporting, technical documentation, stakeholder presentations, and remediation recommendations.
-
Core Competencies: Analytical thinking, problem-solving, attention to detail, collaboration, and effective communication with technical and non-technical stakeholders.