Security Engineer

Posted 4 Days Ago
Be an Early Applicant
Makati City, Metro Manila, National Capital Region, PHL
In-Office
Mid level
Fintech • Insurance • Financial Services
The Role
Lead application security assessments (SAST/DAST/manual code review/pen testing) across web, API, AI/ML, mobile and desktop. Build AI-powered security automation and internal tooling, perform threat modeling, produce risk-rated reports, advise product teams, and mentor junior engineers while contributing to AppSec policies and training.
Summary Generated by Built In

The Security Engineer plays a key role in strengthening Manulife's application security posture across its digital products, platforms, and financial services systems. Operating with greater autonomy, this role leads security assessments, drives remediation efforts, and actively contributes to the development of AppSec programs and standards. The ideal candidate brings solid hands-on experience in secure software development, offensive security techniques, AI-driven security automation, and cross-functional leadership — all grounded in Manulife's core values.

Position Responsibilities:

  • Lead end-to-end application security assessments including SAST, DAST, manual code reviews and penetration testing.

  • Independently conduct ad hoc and scheduled penetration testing on web applications, APIs, AI/ML, and mobile applications — documenting and presenting findings to stakeholders.

  • Perform in-depth analysis of OWASP Top 10 and advanced vulnerability classes including business logic flaws, broken access control, and insecure deserialization.

  • Design, code, and deploy AI-powered automation tools and security scripts that enhance vulnerability detection, threat triage, and testing efficiency at scale.

  • Write clean, maintainable code to build internal security tooling, integrations, and AI-assisted workflows that reduce manual effort across the Security Engineering Team.

  • Conduct threat modeling for complex, high-risk systems and new product initiatives, recommending security architecture improvements.

  • Serve as a security advisor and informal leader to development and product teams — driving security-by-design principles and secure coding best practices.

  • Mentor and coach associate security engineers —
    conducting knowledge-sharing sessions, reviewing their work, and supporting their professional development.

  • Produce clear, risk-rated vulnerability reports with actionable remediation guidance for both technical and non-technical audiences.

  • Contribute to the development and maintenance of application security policies, standards, playbooks, and training materials.

  • Stay ahead of evolving threats and vulnerabilities in the financial services and fintech space, translating intelligence into actionable controls.

Required Qualifications:

  • 3–6 years of hands-on experience in application security, with demonstrated ownership of security assessments and remediation cycles.

  • Deep familiarity with OWASP Top 10, OWASP Testing Guide (OWTG), and OWASP Application Security Verification Standard (ASVS).

  • Proven experience conducting Web application, API, AI/ML, Mobile and Desktop penetration testing using tools such as Burp Suite Pro, OWASP ZAP, or Metasploit.

  • Demonstrated ability to code and build AI-powered security automation tools — including scripts or integrations using Python, JavaScript, or similar languages.

  • Experience working with AI/ML APIs or LLM-based tools to automate security workflows such as vulnerability analysis, report generation, or threat detection.

  • Demonstrated leadership skills — including the ability to guide peers, facilitate technical discussions, and influence security outcomes across teams.

  • Excellent communication skills — able to articulate risk clearly to both technical teams and business stakeholders.

  • Has background in threat modeling and mobile penetration testing.

Preferred Qualifications:

  • Industry certifications such as OSCP, GWAPT, eWPT, CSSLP, CISSP, or equivalent.

  • Experience in banking, insurance, or financial services with working knowledge of PCI-DSS, BSP regulations, ISO 27001, or SOC 2.

  • Cloud security experience on AWS, Azure, or GCP — including knowledge of cloud-native appsec controls.

  • Experience with mobile application security testing on iOS and Android platforms.

  • Proficiency in threat modeling using STRIDE, PASTA, or similar methodologies for complex, multi-tier systems.

  • Exposure to red team exercises or bug bounty programs.

  • Track record of leading or co-leading security initiatives, process improvements, or cross-team programs.

When you join our team:

  • We’ll empower you to learn and grow the career you want.

  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.

  • As part of our global team, we’ll support you in shaping the future you want to see.

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].

Working Arrangement

Hybrid

Skills Required

  • 3-6 years of hands-on experience in application security with ownership of assessments and remediation cycles.
  • Deep familiarity with OWASP Top 10, OWASP Testing Guide (OWTG), and OWASP Application Security Verification Standard (ASVS).
  • Proven experience conducting web application, API, AI/ML, mobile and desktop penetration testing using tools such as Burp Suite Pro, OWASP ZAP, or Metasploit.
  • Demonstrated ability to code and build AI-powered security automation tools, including scripts or integrations using Python, JavaScript, or similar languages.
  • Experience working with AI/ML APIs or LLM-based tools to automate security workflows such as vulnerability analysis, report generation, or threat detection.
  • Demonstrated leadership skills including guiding peers, facilitating technical discussions, and influencing security outcomes across teams.
  • Excellent communication skills, able to articulate risk to both technical teams and business stakeholders.
  • Background in threat modeling and mobile penetration testing.
  • Industry certifications such as OSCP, GWAPT, eWPT, CSSLP, CISSP, or equivalent.
  • Experience in banking, insurance, or financial services and knowledge of PCI-DSS, BSP regulations, ISO 27001, or SOC 2.
  • Cloud security experience on AWS, Azure, or GCP, including cloud-native appsec controls.
  • Experience with mobile application security testing on iOS and Android platforms.
  • Proficiency in threat modeling using STRIDE, PASTA, or similar methodologies.
  • Exposure to red team exercises or bug bounty programs.
  • Track record of leading or co-leading security initiatives, process improvements, or cross-team programs.

Manulife Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Manulife and has not been reviewed or approved by Manulife.

  • Healthcare Strength Healthcare coverage is portrayed as comprehensive, spanning medical, dental, prescription drugs, vision, critical illness, and short- and long-term disability. Mental-health support is emphasized via EAP-style services and high annual coverage limits in some regions, alongside wellness programs and navigation tools.
  • Retirement Support Retirement offerings are positioned as a meaningful part of total rewards, including group RRSP/defined contribution pension options and employer matching in some cases. Ownership-related programs such as share purchase/stock options are also described as available for eligible employees.
  • Flexible Benefits Benefits are described as robust and flexible, with customizable packages and spending-account style options in some plans. Digital tools (mobile app/claims) and reward-linked wellness programs are framed as making benefits easier to use and more engaging.

Manulife Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Toronto, Ontario
32,427 Employees
Year Founded: 1887

What We Do

Manulife is a leading international financial services group that helps people make their decisions easier and lives better. With our global headquarters in Toronto, we operate as Manulife across our offices in Canada, Asia, and Europe, and primarily as John Hancock in the United States. We have more than 40,000 employees, over 116,000 agents serving ~34 million customers worldwide, and over $1.3 trillion in assets under management and administration. Visit www.Manulife.com to find out more. For Manulife terms of use, please visit http://bit.ly/SM_Terms

Similar Jobs

Kroll Logo Kroll

Security Engineer

Big Data • Security • Software • Analytics • Cybersecurity
In-Office
Manila, Metro Manila, National Capital Region, PHL
5001 Employees

Binance Logo Binance

Security Engineer

Blockchain • Fintech • Software • Cryptocurrency • Metaverse
Remote or Hybrid
19 Locations
7696 Employees

Binance Logo Binance

Security Engineer

Blockchain • Fintech • Software • Cryptocurrency • Metaverse
In-Office or Remote
19 Locations
7696 Employees

Binance Logo Binance

Security Engineer

Blockchain • Fintech • Software • Cryptocurrency • Metaverse
In-Office or Remote
18 Locations
7696 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account