Application Security Engineer

Posted One Month Ago
Be an Early Applicant
Manila, Metro Manila, National Capital Region, PHL
Hybrid
Mid level
Software
The Role
Hands-on application security engineer who reads and writes code, performs manual vulnerability assessments, integrates and tunes security tooling into CI/CD, builds secure libraries and patterns, conducts threat modeling and design reviews, supports incident response, and elevates engineering security practices across the organization.
Summary Generated by Built In
Interact provides enterprise-grade intranet software that connects over three million employees to leading global names like Levi's, Domino’s, Teva Pharmaceuticals, and Technicolor.
Our team of customer-focused problem solvers are passionate about helping organizations to communicate better. We do this together by constantly working to improve every service and product we offer. With offices in Manchester, New York, Dubai, Warsaw, and Poland, we operate across North America, EMEA, and Australia.
Click on any of our vacancies and you’ll see one thing in common – they all begin with this message. Why? Because at Interact we treat everyone with the same respect and honesty. Whether you’re a developer fresh out of college or a seasoned salesperson, we live the motto that we uphold for our customers: our people are our most valuable assets.

As an Application Security Engineer you'll make our software secure by building, not by watching dashboards. You'll spend most of your time in the codebase - reading and writing code, manually reviewing changes, hunting for and exploiting vulnerabilities, and shipping the libraries, patterns, and guardrails that make the next class of bug hard to introduce. You'll work shoulder-to-shoulder with engineers, treating security as an engineering problem to be solved at the source rather than a report to be filed. 

Key Responsibilities
  • Read and write real code. Review pull requests for security-relevant changes and contribute fixes directly rather than filing tickets and walking away. 
  • Manually assess applications and APIs — find, exploit, and prove real vulnerabilities, and distinguish genuine risks. 
  • Build secure building blocks: reviewing libraries, safe wrappers, auth patterns, and paved-road templates so the easy way is the secure way. 
  • Perform threat modelling and design reviews on new features, working from how the system actually behaves, not a checklist. 
  • Automate security into CI/CD (Octopus deploy/Azure DevOps) 
  • Fix vulnerabilities; When you find a bug, ask what pattern allowed it and eliminate the pattern. 
  • Support incident investigation and remediation for application security issues and get hands-on with logs, code, and root cause. 
  • Level up engineers through code, examples, and quarterly training 
  • Help shape standards and priorities for the wider engineering teams (this is a small team; you'll have real influence, but the day job is engineering). 
  • Stay updated with the latest security threats, vulnerabilities, and industry trends to proactively address potential risks 
  • Advocate for security best practices and influence engineering culture to prioritize security 
  • Evaluate and adopt new security tools and technologies to enhance the security posture 
  • Participate incident response efforts for application security incidents, including investigation and remediation 
  • Collaborate with compliance teams to ensure applications meet regulatory and industry-specific security requirements (e.g., GDPR, ISO 27001) 
  • Implement and oversee security tools and technologies such as SAST, and DAST solutions 
  • Facilitate security architecture reviews and threat modelling sessions for new and existing applications 
  • Report on security metrics and KPIs to senior management, providing insights into the security posture and areas for improvement 
  • Drive continuous improvement, fostering a culture of security awareness and proactive risk management 
  • Coordinate with third-party vendors and security consultants as needed for specialised assessments or audits 


Skills, Knowledge and Expertise
  • Strong software engineering background — you've written and shipped production code, ideally in .NET and/or TypeScript/React, and you can drop into an unfamiliar codebase and reason about it. 
  • Solid application security experience securing web apps and APIs. 
  • Demonstrated ability to find vulnerabilities manually and explain both the exploit and the fix. 
  • Comfortable integrating and, crucially, tuning security testing in CI/CD so the output is trustworthy. 
  • You've influenced engineers as a peer, through code and pragmatism. 
  • Expert knowledge of application security principles, practices, and frameworks such as OWASP Top Ten, SANS/CWE Top 25 
  • Proficiency with security testing tools like Burp Suite, OWASP ZAP, Fortify, Checkmarx, SonarQube or similar 
  • Strong understanding of secure coding practices in languages and frameworks such as JavaScript, TypeScript, ReactJS, .NET, and others 
  • Familiarity with DevSecOps practices and integrating security tools into CI/CD pipelines  
  • Knowledge of authentication and authorization protocols such as OAuth, SAML, JWT, and multi-factor authentication 
  • Understanding of cloud security principles and experience with cloud platforms like AWS and/or Azure 
  • Experience with compliance standards and regulations like GDPR, ISO 27001, PCI DSS, and SOC 2 
  • Knowledge of encryption standards, key management, and data protection strategies 
  • Experience with incident response processes and security event management 
  • Excellent communication skills, adept at conveying security concepts to both technical and non-technical stakeholders 
  • High attention to detail with a commitment to maintaining the highest standards of security and quality 
  • Proactive and strategic thinker, able to anticipate security challenges and stay ahead of emerging threats 
  • Collaborative mindset, thriving in a cross-functional team environment and building strong relationships across departments 
  • Passionate about security, with a continuous desire to learn and stay updated on the latest industry trends and threats 
  • Resilient and adaptable, capable of handling high-pressure situations and making sound decisions during security incidents 
  • Ethical and trustworthy, maintaining the highest level of integrity in handling sensitive information
Certifications (Preferred): 
  • Offensive/practical certs like OSCP, or an equivalent  
  • Cloud security depth in AWS and/or Azure; container/orchestration security. 
  • Familiarity with GDPR, ISO 27001, SOC 2 as constraints to engineer around. 
 

About
Interact is an enterprise intranet software company serving over 1,000 customers and millions of employees.Our mission is to inform and connect every organization's greatest asset: its people.For more than 15 years, Interact has worked with organizations like Levi’s, Sony PlayStation, Teva Pharmaceuticals and Domino’s to delivering outstanding intranet experiences.Interact has offices in Manchester, New York, Tulsa and Manila and operates across the whole of the US and Canada, EMEA, and Australia.

Skills Required

  • Strong software engineering background with experience writing and shipping production code (ideally .NET and/or TypeScript/React)
  • Solid application security experience securing web applications and APIs
  • Demonstrated ability to find vulnerabilities manually and explain both the exploit and the fix
  • Experience integrating and tuning security testing in CI/CD pipelines (Octopus Deploy, Azure DevOps)
  • Proficiency with security testing tools such as Burp Suite, OWASP ZAP, Fortify, Checkmarx, SonarQube or similar
  • Experience with SAST and DAST solutions and DevSecOps practices
  • Knowledge of authentication and authorization protocols (OAuth, SAML, JWT) and multi-factor authentication
  • Understanding of cloud security principles and experience with AWS and/or Azure and container/orchestration security
  • Ability to perform threat modelling and security design reviews
  • Experience supporting incident investigation and remediation for application security issues
  • Familiarity with compliance standards and regulations (GDPR, ISO 27001, SOC 2, PCI DSS)
  • Offensive/practical certifications such as OSCP
  • Strong communication skills and ability to influence engineers through code and training
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Manchester
239 Employees

What We Do

Interact delivers enterprise-grade intranet software to over 1,000 customers and millions of employees worldwide. Our mission is to inform and connect every organization's greatest asset: its people. For more than 15 years, Interact has worked with organizations such as Levi Strauss & Co., New York Life, Teva Pharmaceuticals, and Domino’s to deliver outstanding intranet experiences. Interact has offices in New York, Tulsa, and Manchester and operates across North America, EMEA, and Australia.

Similar Jobs

Manulife Logo Manulife

Application Security Engineer

Fintech • Insurance • Financial Services
In-Office
Quezon City, Metro Manila, National Capital Region, PHL
32427 Employees

Manulife Logo Manulife

Application Security Engineer

Fintech • Insurance • Financial Services
In-Office
Quezon City, Metro Manila, National Capital Region, PHL
32427 Employees

Vertiv Logo Vertiv

Application and Product Security II Engineer II

Hardware • Software • Analytics
In-Office
2 Locations
8435 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account