Do you want to take the first step in making Filipinos’ lives better everyday? Here in GCash we want to stay at the forefront of the FinTech industry by creating innovative, meaningful, and convenient financial solutions for the nation! G ka ba? Join the G Nation today!
We are looking for a Manager, Offensive Security Engineer to lead and execute advanced red team and offensive security operations. This role is for someone who thinks like an attacker, operates with discipline, and can translate technical findings into meaningful security improvements across the organization.
If you enjoy breaking things responsibly, mentoring other operators, and influencing security strategy, not just running tools, this role is for you.
Lead and execute red team and advanced penetration testing engagements that simulate real-world threat actors across applications, infrastructure, cloud, and identity environments
Identify, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business impact
Design and improve adversary simulation scenarios aligned with real-world threat intelligence and the MITRE ATT&CK framework
Partner closely with blue team, security engineering, and security operations teams to improve detection, response, and overall security posture
Develop tooling, automation, or research to identify security weaknesses at scale and improve testing efficiency
Mentor and guide offensive security engineers, providing technical leadership and raising the team’s overall capability
Produce high-quality technical and executive-level reports, clearly communicating risk, impact, and remediation guidance
Stay ahead of emerging threats, techniques, and tooling, continuously evolving red team tradecraft
At least 3-5 years of hands-on experience in red teaming, offensive security, or advanced penetration testing
Proven track record of discovering impactful vulnerabilities, including complex or chained attack paths
Strong understanding of attacker tradecraft, including web, cloud, identity, and infrastructure attack vectors
Practical experience with adversary simulation and the MITRE ATT&CK framework
Ability to lead, mentor, and influence (this is a hands-on leadership role, not just an individual contributor position)
Strong written and verbal communication skills, with the ability to explain technical risk to both engineers and executives
At least one practical and one theoretical security certification, such as:
OSCP, OSEP, OSWE, OSED, OSWP, CRTO, CRTL, CRTP, CRTE, GRTP, CPTS, CWEE, CAPE (practical)
CISSP, CISM, or equivalent (theoretical)
What We Offer
Opportunity for career growth and development in the #1 FinTech company in the country Working with a dynamic and highly collaborative team who want to change the game A company that values their people with highly competitive and flexible compensation and benefits package
Skills Required
- Lead and execute red team and advanced penetration testing engagements
- Identify, exploit, and chain vulnerabilities to demonstrate realistic attack paths and business impact
- Design and improve adversary simulation scenarios aligned with threat intelligence and MITRE ATT&CK
- Partner with blue team, security engineering, and security operations to improve detection and response
- Develop tooling, automation, or research to identify security weaknesses at scale
- Mentor and guide offensive security engineers and provide technical leadership
- Produce high-quality technical and executive-level reports communicating risk and remediation guidance
- At least 3-5 years of hands-on red teaming, offensive security, or advanced penetration testing experience
- Proven track record of discovering impactful vulnerabilities, including complex or chained attack paths
- Strong understanding of attacker tradecraft across web, cloud, identity, and infrastructure
- Practical experience with adversary simulation and the MITRE ATT&CK framework
- Strong written and verbal communication skills for technical and executive audiences
- At least one practical and one theoretical security certification (examples: OSCP/OSWE/CRTP etc. and CISSP/CISM)
What We Do
Mynt is the first and only duacorn in the Philippines. It's a leader in mobile financial services focused on accelerating financial inclusion through mobile money, financial services, and technology. Mynt operates two fintech companies: GXI, the mobile wallet operator of GCash — the #1 Finance App in the Philippines, and Fuse Lending, a tech-based lending company that gives Filipinos access to microloans and business loans. Mynt, through its fintech operations, is a staunch supporter of the United Nations Sustainable Development Goals (SDGs), particularly UN SDGs 5,8,10, and 13, which focus on safety & security, financial inclusion, diversity, equity, and inclusion as well as taking urgent action to combat climate change and its impacts, respectively.







