Application Security Enablement Engineer

Posted Yesterday
Be an Early Applicant
Makati City, Metro Manila, National Capital Region, PHL
In-Office
Senior level
Fintech • Insurance • Financial Services
The Role
Drives application security enablement across the software development lifecycle in Asia. Responsibilities include vulnerability assessment and remediation, threat modeling, exception reviews, secure coding guidance, application security testing, DevSecOps integration, and security tooling automation. The role partners with global security, engineering, architecture, and development teams to implement enterprise standards, improve security maturity, support audits, and strengthen application security across cloud, container, API, and hybrid environments.
Summary Generated by Built In

The Asia CISO function is responsible for ensuring effective cybersecurity risk management, regulatory compliance, and secure technology enablement across all Asia markets. This role sits within the regional cybersecurity leadership team and is accountable for application security enablement across the software development lifecycle. It serves as the bridge between global application security strategy and regional execution, driving outcomes through strong partnership and influence across application development, engineering, and architecture teams in both regional and market environments.


Deliver application security engineering and enablement capabilities across Asia, embedding secure development practices into the software development lifecycle (SDLC) and enabling adoption of enterprise security standards. This role focuses on driving vulnerability assessment, prioritization and remediation, centralized exception review, threat modeling, and SME support to strengthen application security posture.


Position Responsibilities:

  • Help drive adoption of enterprise application security standards across applications, platforms, and cloud environments
  • Enable automation for vulnerability detection, remediation, exception review and reporting to improve efficiency and consistency.
  • Provide actionable, risk-based technical guidance and training to developers on secure design and coding standards (e.g., OWASP).
  • Partner with architects, product owners, and development teams during design and planning phases to embed secure-by-design principles.
  • Conduct and validate application security testing (automated and manual), including intake and validation of findings from external penetration tests and bug bounty programs.

Accountabilities:


Individual Accountabilities:


  • Support vulnerability management processes, including triage, exception review, remediation, and reporting.
  • Conduct application and architecture-level Threat Modeling for new applications, major enhancements, and high-risk changes.
  • Support uplift of Threat Modeling maturity by defining templates, playbooks, and reusable threat libraries for common platforms and patterns.
  • Support to scale workstreams such as secrets, SCA, SAST, DAST vulnerability remediation.
  • Partner with development teams to integrate security expectations into CI/CD pipelines and DevSecOps workflows.
  • Validate and contextualize findings from automated tools, penetration tests, and external assessments where design-level issues are identified.

 

Key Shared Accountabilities:


  • Partner with Global Application Security on standards, tooling and continuous improvement
  • Collaborate with CIO, engineering, and architecture teams to ensure consistent adoption and accountability
  • Align with Vulnerability Management function on remediation prioritization and risk treatment
  • Support audit, regulatory, and control assurance activities

Required Qualifications:

  • Minimum 5+ years in application security or software development roles with a focus on secure coding and DevSecOps.
  • Strong understanding of application security principles, SDLC, and CI/CD pipelines.
  • Strong understanding of application penetration testing
  • Knowledge of secure coding standards and frameworks (e.g., OWASP Top 10, NIST).
  • Excellent collaboration and communication skills to engage developers and stakeholders.

Preferred Qualifications:

  • Hands-on experience with security tools (e.g., Secrets, SCA, SAST, Container security, DAST) and automation frameworks.
  • Familiarity with cloud-native application security concepts.
  • Certifications: OSCP, CISSP or preferred equivalent.
  • Additional certifications such as Advanced application testing certifications (OSWP, GIAC GWAPT, INE eWPTX) are considered an advantage.

Tooling and Technology Coverage:

  • In addition to SAST, DAST, and SCA, familiarity with complementary controls such as WAF and NAC were relevant to application-layer protection.
  • Practical exposure to API security, Kubernetes and container platforms, Infrastructure as Code (IaC), hybrid cloud environments, and penetration testing or vulnerability scanning toolchains.

When you join our team:

  • We’ll empower you to learn and grow the career you want.
  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we’ll support you in shaping the future you want to see.

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].

Working Arrangement

Hybrid

Skills Required

  • Minimum 5+ years in application security or software development focused on secure coding and DevSecOps
  • Strong understanding of application security principles, SDLC, and CI/CD pipelines
  • Strong understanding of application penetration testing
  • Knowledge of secure coding standards and frameworks, including OWASP Top 10 and NIST
  • Excellent collaboration and communication skills for engaging developers and stakeholders
  • Hands-on experience with security tools such as Secrets, SCA, SAST, container security, and DAST
  • Experience with security automation frameworks
  • Familiarity with cloud-native application security concepts
  • OSCP, CISSP, or equivalent certification
  • Advanced application testing certifications such as OSWP, GIAC GWAPT, or INE eWPTX
  • Practical exposure to API security, Kubernetes, container platforms, Infrastructure as Code, hybrid cloud environments, penetration testing, or vulnerability scanning toolchains

Manulife Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Manulife and has not been reviewed or approved by Manulife.

  • Healthcare Strength — Healthcare coverage is portrayed as comprehensive, spanning medical, dental, prescription drugs, vision, critical illness, and short- and long-term disability. Mental-health support is emphasized via EAP-style services and high annual coverage limits in some regions, alongside wellness programs and navigation tools.
  • Retirement Support — Retirement offerings are positioned as a meaningful part of total rewards, including group RRSP/defined contribution pension options and employer matching in some cases. Ownership-related programs such as share purchase/stock options are also described as available for eligible employees.
  • Flexible Benefits — Benefits are described as robust and flexible, with customizable packages and spending-account style options in some plans. Digital tools (mobile app/claims) and reward-linked wellness programs are framed as making benefits easier to use and more engaging.

Manulife Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Toronto, Ontario
32,427 Employees
Year Founded: 1887

What We Do

Manulife is a leading international financial services group that helps people make their decisions easier and lives better. With our global headquarters in Toronto, we operate as Manulife across our offices in Canada, Asia, and Europe, and primarily as John Hancock in the United States. We have more than 40,000 employees, over 116,000 agents serving ~34 million customers worldwide, and over $1.3 trillion in assets under management and administration. Visit www.Manulife.com to find out more. For Manulife terms of use, please visit http://bit.ly/SM_Terms

Similar Jobs

Capital One Logo Capital One

Sr. Associate, Associate Relations

Fintech • Machine Learning • Payments • Software • Financial Services
Remote or Hybrid
Metro Manila, PHL
55000 Employees

Optum Logo Optum

Vice President, General Management

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Makati City, Metro Manila, National Capital Region, PHL
160000 Employees

Optum Logo Optum

Instructional Designer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Makati City, Metro Manila, National Capital Region, PHL
160000 Employees
Remote or Hybrid
2 Locations
289097 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account