Offensive Security Engineer
Metro ManilaPosted 2 days agoJobStreet
Skills mentioned
Members see a match score against their own skills and get a resume + cover letter written for this posting.
About the role
The Offensive Security Engineer Lead performs penetration testing, ethical hacking, and red team exercises across network infrastructure, web and mobile applications, and other critical systems to identify security vulnerabilities and potential attack paths. Collaborate with IT and development teams to recommend and validate remediation measures, strengthen security controls, and enhance the bank's overall cybersecurity posture through proactive security assessments and continuous improvement initiatives.
Key responsibilities
Plan, develop, and execute penetration testing engagements, red team exercises, and security assessments across networks, systems, web applications, mobile applications, and wireless environments. Conduct threat analysis and simulate real-world attack scenarios, including social engineering and physical security assessments. Identify vulnerabilities, attack paths, and security weaknesses using both manual and automated testing techniques. Assess the effectiveness of security controls such as firewalls, intrusion detection/prevention systems, and other defensive technologies. Develop testing methodologies, abuse cases, and custom scripts or tools to enhance security testing capabilities. Document findings, prepare comprehensive technical and executive reports, and communicate remediation recommendations to stakeholders. Partner with IT and development teams to validate security fixes and drive timely remediation of identified vulnerabilities. Review security configurations, policies, and procedures, providing recommendations to strengthen the organization's security posture. Support cybersecurity investigations and security-related risk assessments as required. Stay current with emerging cyber threats, attack techniques, vulnerability trends, and penetration testing tools.
About you
Bachelor's degree in computer science, Information Security, Cybersecurity, or a related technical field. Strong understanding of security vulnerabilities, common attack techniques, and an attacker mindset to identify and assess potential threats. Solid knowledge of OWASP Top 10 Application Security risks and best practices. Relevant cybersecurity certifications such as OSCP, GPEN, GWAP, CEH, or equivalent are an advantage. Hands-on experience in penetration testing and ethical hacking. Strong technical background in networking, digital forensics, reverse engineering, web applications, databases, and wireless technologies. Proficiency in scripting and programming for security testing and automation. Good understanding of the business and financial impact of cybersecurity incidents and breaches. Highly analytical with strong problem-solving and critical-thinking abilities. Results-driven with a focus on identifying risks and driving effective remediation efforts.
About us
At Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. With Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development.
Sourced from JobStreet · posted 2 days ago · you apply on the original site