368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$27k – $60k per year (Estimated)
Location
Remote/Hybrid (Taguig, Philippines)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Coins.ph is a digital wallet and exchange founded in 2014 and headquartered in Manila. It combines crypto trading with bill payments, remittances and mobile top-ups, functioning as a general financial application for Filipino users. The company holds virtual asset and electronic money licences from the central bank of the Philippines.

Key Responsibilities

    As an Application Security Engineering Manager, you will be the core leader of the company’s application security team, responsible for formulating and implementing the company’s application security strategy and technical roadmap. You will lead the team to build a full-lifecycle application security system covering requirements, design, development, testing, deployment, and operation, focusing on identifying and mitigating security risks of core business systems in digital currency trading and payment scenarios. This role requires in-depth understanding of application security technologies, rich team management experience, and familiarity with global regulatory requirements for digital assets and payment security, to ensure the security, stability, and compliance of the company’s application systems.

    Key Responsibilities

    1. Application Security Strategy & System Construction

  • Formulate the company’s long-term and short-term application security strategy, technical roadmap, and implementation plan, combining the company’s business development goals, risk control requirements, and regulatory compliance needs.

  • Lead the construction, optimization, and iteration of the application security system, including security development lifecycle (SDLC) management, vulnerability management, security code review, penetration testing, and security monitoring, to ensure the system’s comprehensiveness and effectiveness.

  • Establish and improve application security standards, specifications, and operation processes, including security coding standards, security test standards, and vulnerability handling processes, to standardize the application security work of the entire company.

  • Track the latest application security technologies, vulnerabilities, and attack methods, introduce advanced security tools and technical solutions, and continuously improve the company’s application security defense capabilities.

  • 2. Team Management & Development

  • Build, manage, and develop the application security engineering team, formulate team OKRs, performance assessment standards, and talent training plans to improve the team’s professional capabilities (security code review, penetration testing, vulnerability research, etc.).

  • Arrange daily work assignments for the team, supervise work progress, solve technical difficulties in application security, and create a positive and collaborative team atmosphere.

  • Guide team members’ professional growth, organize technical training, security skill exchanges, and vulnerability emergency response drills, and cultivate a professional application security talent echelon.

  • Manage team performance, conduct regular performance reviews, and motivate team members to achieve work goals and improve work quality.

  • 3. Application Security Risk Management & Control

  • Lead the team to conduct application security risk assessments for core business systems (digital currency trading platform, payment system, user authentication system, etc.), identify potential security risks and vulnerabilities, and formulate targeted risk mitigation plans.

  • Promote the integration of security into the entire SDLC, conduct security reviews in the requirements and design phases, perform security code reviews and penetration testing in the development and testing phases, and implement security verification in the deployment phase.

  • Establish and manage the vulnerability management system, track the discovery, classification, remediation, and verification of vulnerabilities, ensure that high-risk vulnerabilities are handled in a timely manner, and reduce security risks.

  • Respond to application security incidents (such as code vulnerabilities, data leakage, and attack incidents), organize the team to conduct emergency disposal, investigate the root cause, and formulate prevention measures to avoid recurrence.

  • 4. Compliance & Regulatory Support

  • Ensure that application security work complies with global regulatory requirements (FATF, MiCA, local regulations) and industry standards (such as ISO 27001, PCI DSS), and meets the security and compliance requirements of digital currency and payment businesses.

  • Cooperate with the compliance team to complete application security-related compliance audits, risk assessments, and regulatory reporting, and provide relevant technical materials and explanations.

  • Participate in the formulation and improvement of the company’s information security compliance system, and promote the implementation of application security compliance requirements in all business links.

  • 5. Cross-departmental Collaboration & Security Promotion

  • Communicate closely with R&D, product, testing, operation, and compliance departments to promote the integration of application security into business processes and ensure that security requirements are implemented in each link.

  • Provide application security technical support and guidance for R&D teams, including security coding training, vulnerability remediation guidance, and security solution consultation.

  • Promote enterprise-wide application security awareness training, improve the security awareness of employees in all departments, and reduce security risks caused by human factors.

  • Cooperate with the network security, data security, and other teams to build a comprehensive information security defense system and ensure the overall security of the company’s business.

Requirements

    • Experience: 8+ years of application security or related work experience, including 3+ years of senior application security team management experience; preferred experience in fintech, digital currency, payment, or blockchain industries. Deep understanding of the application security risks and characteristics of digital currency trading and payment systems.

    • Professional Expertise:

      • Proficient in application security technologies, including security code review, penetration testing, vulnerability research, SDLC security management, and application security monitoring.

      • Familiar with common application security vulnerabilities (OWASP Top 10) and attack methods, and have rich experience in vulnerability discovery and remediation.

      • Proficient in at least one programming language (Java, Python, Go, etc.), able to conduct security code review and customize penetration testing tools.

      • Familiar with application security tools (such as SAST, DAST, IAST, vulnerability scanners) and able to lead the team to use and optimize these tools.

      • Understanding of global regulatory requirements (FATF, MiCA, etc.) and industry standards (ISO 27001, PCI DSS) related to digital assets and payment security.

    • Leadership & Management: Excellent leadership and team management capabilities, able to build and lead a high-performance application security team; strong cross-departmental coordination and resource integration capabilities.

    • Analytical & Problem-Solving: Strong security sensitivity and analytical thinking, able to quickly identify application security risks and provide effective solutions; have experience in handling major application security incidents.

    • Communication Skills: Excellent oral and written communication skills in both Chinese and English, able to effectively communicate with senior management, R&D teams, and regulatory authorities.

    • Education: Bachelor’s degree or above in Computer Science, Information Security, Network Security, or related fields; relevant professional certifications (such as CISSP, CISM, CEH) are preferred.

    Preferred Qualifications

  • Has experience in building application security systems for compliant digital currency exchanges or payment institutions.

  • Familiar with the security architecture of digital currency trading platforms, payment systems, and blockchain-related applications, and has experience in solving complex application security problems.

  • Has experience in leading large-scale application security projects (such as SDLC security transformation, vulnerability management system construction) and has achieved remarkable results.

  • Familiar with cloud security technologies and has experience in building application security systems in cloud environments (AWS, GCP, Azure, etc.).

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Taguig
$42k – $49k per year (net) • In office • Full-Time • Bachelor's Degree • Moscow
Go
Python
Rust
TypeScript
DevOps
CI/CD
AWS
Kubernetes
IAM
Cybersecurity
CVE
ISO 27001
PCI DSS
SOC 2
Threat Modeling
Web3
Smart Contracts
Apply
$42k – $104k per year (Estimated) • In office • Internship • 5+ years exp
Bash
PowerShell
Python
DevOps
Amazon EC2
Amazon EKS
Ansible
AWS
AWS Lambda
Azure
CentOS Stream
Chef
CI/CD
CloudFormation
Configuration Management
Datadog
FinOps
GCP
Git
GitHub Actions
GitLab CI
Grafana
Hyper-V
Istio
Jenkins
Kubernetes
KVM
Linkerd
Platform Engineering
Prometheus
Puppet
Service Mesh
Splunk
Terraform
Ubuntu
VMWare
Windows Server
Amazon CloudWatch
Amazon ECS
Amazon S3
API Gateway
AWS Step Functions
GitHub
GitLab
IAM
Cybersecurity
GDPR
ISO 27001
SOC 2
Apply
In office • Full-Time • Bucharest
Assembly
DevOps
Akamai
Incident Management
Cybersecurity
ISO 27001
Wireshark
Management
ServiceNow
Apply
In office • Full-Time • 5+ years exp • Bachelor's Degree • Shanghai
DevOps
AWS
Cybersecurity
GDPR
PCI DSS
Analytics
Power BI
Tableau
Management
Confluence
Jira
Trello
Apply
$67k – $173k per year (Estimated) • In office • Contractor • 3+ years exp • Bachelor's Degree • Singapore
JavaScript
Python
DevOps
AWS
Azure
GCP
Cybersecurity
ISO 27001
OWASP Top 10
Apply
Remote/Hybrid • Full-Time • 3+ years exp • Shanghai
AI/ML
OCR
Web3
Chainalysis
TRM Labs
Apply
Remote/Hybrid • Full-Time • 5+ years exp • Shanghai
DevOps
SLI/SLO/SLA
Apply
Remote/Hybrid • Full-Time • 3+ years exp • Shanghai
SQL
Analytics
A/B Testing
Design
Figma
Marketing
Amplitude
Mixpanel
Apply
Remote/Hybrid • Full-Time • 5+ years exp
Python
DevOps
Amazon EC2
AWS
CloudFormation
Terraform
Amazon S3
IAM
Cybersecurity
CIS Benchmarks
MITRE ATT&CK
Prisma Cloud
Wiz
Apply
Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree
Web3
Smart Contracts
Tron
Apply
$5.5k – $23k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Taguig
AI/ML
ChatGPT
Copilot
Analytics
Power BI
Tableau
Management
Power Apps
Power Automate
UiPath
Apply
$9k – $21k per year (Estimated) • Remote/Hybrid • Full-Time • Taguig
SQL
Apply
$9.5k – $21k per year (Estimated) • Remote/Hybrid • Full-Time • Taguig
Apply
$14k – $46k per year (Estimated) • In office • Full-Time • 3+ years exp • Taguig
Python
SQL
TypeScript
DevOps
GCP
Apply
$7k – $16k per year (Estimated) • In office • Full-Time • 1+ year exp • Taguig
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.