1,285,480open jobs
74,416companies
214,296added this week
Browse all
Salary
≈ $23k – $54k per year (Estimated)
Location
In office (Makati)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 6, 2026. First seen by Alion on Oct 6, 2026. Manulife scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Manulife is a Canadian insurance and asset management group founded in Toronto in 1887, with the first Canadian prime minister as its founding president. It sells life and health insurance, annuities and retirement products in Canada, the United States under the John Hancock brand and across a dozen Asian markets, and runs Manulife Investment Management as a global asset manager for institutional and retail clients. Headquartered in Toronto and listed in Toronto, New York and Hong Kong, it earns a growing share of its profit in Asia and has been reducing its exposure to legacy long-term care liabilities through reinsurance transactions.

The Asia CISO function is responsible for ensuring effective cybersecurity risk management, regulatory compliance, and secure technology enablement across all Asia markets. This role sits within the regional cybersecurity leadership team and is accountable for application security enablement across the software development lifecycle. It serves as the bridge between global application security strategy and regional execution, driving outcomes through strong partnership and influence across application development, engineering, and architecture teams in both regional and market environments.

Deliver application security engineering and enablement capabilities across Asia, embedding secure development practices into the software development lifecycle (SDLC) and enabling adoption of enterprise security standards. This role focuses on driving vulnerability assessment, prioritization and remediation, centralized exception review, threat modeling, and SME support to strengthen application security posture.

Position Responsibilities:

  • Help drive adoption of enterprise application security standards across applications, platforms, and cloud environments
  • Enable automation for vulnerability detection, remediation, exception review and reporting to improve efficiency and consistency.
  • Provide actionable, risk-based technical guidance and training to developers on secure design and coding standards (e.g., OWASP).
  • Partner with architects, product owners, and development teams during design and planning phases to embed secure-by-design principles.
  • Conduct and validate application security testing (automated and manual), including intake and validation of findings from external penetration tests and bug bounty programs.

Accountabilities:

Individual Accountabilities:

  • Support vulnerability management processes, including triage, exception review, remediation, and reporting.
  • Conduct application and architecture-level Threat Modeling for new applications, major enhancements, and high-risk changes.
  • Support uplift of Threat Modeling maturity by defining templates, playbooks, and reusable threat libraries for common platforms and patterns.
  • Support to scale workstreams such as secrets, SCA, SAST, DAST vulnerability remediation.
  • Partner with development teams to integrate security expectations into CI/CD pipelines and DevSecOps workflows.
  • Validate and contextualize findings from automated tools, penetration tests, and external assessments where design-level issues are identified.

Key Shared Accountabilities:

  • Partner with Global Application Security on standards, tooling and continuous improvement
  • Collaborate with CIO, engineering, and architecture teams to ensure consistent adoption and accountability
  • Align with Vulnerability Management function on remediation prioritization and risk treatment
  • Support audit, regulatory, and control assurance activities

Required Qualifications:

  • Minimum 5+ years in application security or software development roles with a focus on secure coding and DevSecOps.
  • Strong understanding of application security principles, SDLC, and CI/CD pipelines.
  • Strong understanding of application penetration testing
  • Knowledge of secure coding standards and frameworks (e.g., OWASP Top 10, NIST).
  • Excellent collaboration and communication skills to engage developers and stakeholders.

Preferred Qualifications:

  • Hands-on experience with security tools (e.g., Secrets, SCA, SAST, Container security, DAST) and automation frameworks.
  • Familiarity with cloud-native application security concepts.
  • Certifications: OSCP, CISSP or preferred equivalent.
  • Additional certifications such as Advanced application testing certifications (OSWP, GIAC GWAPT, INE eWPTX) are considered an advantage.

Tooling and Technology Coverage:

  • In addition to SAST, DAST, and SCA, familiarity with complementary controls such as WAF and NAC were relevant to application-layer protection.
  • Practical exposure to API security, Kubernetes and container platforms, Infrastructure as Code (IaC), hybrid cloud environments, and penetration testing or vulnerability scanning toolchains.

When you join our team:

  • We’ll empower you to learn and grow the career you want.
  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we’ll support you in shaping the future you want to see.

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].

Working Arrangement

Hybrid
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,285,480 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Makati
≈ $17k – $39k per year (Estimated) • In office • Full-Time • 3+ years exp • Philippines
Cybersecurity
Least Privilege
Apply
$175k – $291k per year • Hybrid • Full-Time • 12+ years exp • Bachelor's Degree • Bloomfield
Python
PowerShell
DevOps
GCP
Azure
AWS
IAM
Cybersecurity
Okta
CyberArk
GDPR
HIPAA
Zero Trust
Microsoft Entra ID
Ping Identity
LDAP
Apply
≈ $67k – $155k per year (Estimated) • In office • Full-Time • Gothenburg
Cybersecurity
ISO 27001
Apply
≈ $54k – $151k per year (Estimated) • In office • Full-Time • Gothenburg
Cybersecurity
OWASP
Apply
$96k – $133k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Louisville • Centennial
Python
PowerShell
DevOps
GCP
Azure
AWS
IAM
Cybersecurity
PCI DSS
GDPR
HIPAA
Zero Trust
SIEM
Apply
R&D Engineer Fullstack 11 hours ago
In office • Full-Time • 4+ years exp • Bachelor's Degree • Bengaluru
JavaScript
TypeScript
SQL
C#
Node JS
C#
ASP.NET Core
Databases
PostgreSQL
AI/ML
Time Series Forecasting
Frontend
Angular
Bootstrap
React.js
DevOps
Azure
CI/CD
Git
Docker
Kubernetes
TCP/IP
DNS
Management
Agile
Apply
≈ $42k – $106k per year (Estimated) • Remote (Cyprus, Poland, Serbia, Spain, Georgia) • Full-Time
Python
JavaScript
TypeScript
SQL
Bash
Databases
PostgreSQL
Redis
RabbitMQ
DevOps
Terraform
Ansible
GCP
DigitalOcean
Helm
OpenTelemetry
Debian
FluxCD
Kustomize
Prometheus
GitLab CI
CI/CD
GitOps
ArgoCD
Git
AWS
Kubernetes
Ubuntu
Grafana
Google GKE
Hetzner
IAM
Linux
TCP/IP
DNS
Cybersecurity
HashiCorp Vault
Least Privilege
Apply
≈ $48k – $108k per year (Estimated) • In office • London
Java
SQL
Java
Maven
AssertJ
Databases
ActiveMQ
Mobile
JUnit
DevOps
Rest API
Splunk
Azure DevOps
Azure
CI/CD
Git
Kubernetes
Grafana
Apache HTTP Server
Management
Jira
Agile
QA
Selenium
Cucumber
JMeter
Playwright
WebDriverIO
Rest-Assured
k6
Apply
≈ $77k – $168k per year (Estimated) • In office • London
Java
SQL
Databases
PostgreSQL
DevOps
Terraform
Azure DevOps
Azure
CI/CD
Jenkins
Git
Kubernetes
Azure AKS
GitLab
Management
Confluence
Jira
Agile
Scrum
Kanban
ITIL
ITSM
Apply
Hybrid • Full-Time • 4+ years exp • Pune
JavaScript
Java
TypeScript
Java
Spring Boot
Databases
PostgreSQL
Oracle
Cassandra
Frontend
RxJS
Angular
Sass
NgRx
Mobile
Clean Architecture
DevOps
OpenShift
CI/CD
Docker
Kubernetes
Apply
≈ $13k – $34k per year (Estimated) • Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Manila
Python
JavaScript
SQL
PowerShell
AI/ML
Anomaly Detection
Machine Learning
DevOps
TCP/IP
DNS
DHCP
Management
Microsoft Office
Apply
≈ $21k – $49k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Manila
AI/ML
AI Agents
Mobile
Material Design
DevOps
GCP
Azure
AWS
Kubernetes
Cybersecurity
MITRE ATT&CK
STRIDE
Threat Modeling
OWASP
Management
Agile
Apply
≈ $16k – $38k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Manila
Python
PowerShell
DevOps
Unix
Cybersecurity
Burp Suite
Snyk
CWE
CVSS
OWASP
Apply
Cybersecurity Manager 20 days ago
≈ $16k – $37k per year (Estimated) • In office • Full-Time • 3+ years exp • Manila
Cybersecurity
Zero Trust
DLP
Analytics
Power BI
Management
Confluence
ServiceNow
Agile
Apply
≈ $15k – $36k per year (Estimated) • Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Manila
Cybersecurity
Qualys Cloud Platform
CIS Benchmarks
Analytics
Power BI
Management
ServiceNow
Apply
≈ $17k – $44k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Makati
PowerShell
Bash
DevOps
Terraform
CI/CD
Jenkins
Git
Ubuntu
IAM
Linux
Apply
Hybrid • Full-Time • 10+ years exp • Makati
Apply
≈ $9k – $23k per year (Estimated) • Hybrid • 1+ year exp • Bachelor's Degree • Makati
Apply
≈ $28k – $65k per year (Estimated) • In office • Full-Time • 15+ years exp • Bachelor's Degree • Makati
Apply
IT Asset Analyst 1 day ago
≈ $16k – $36k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Makati
Management
ServiceNow
ITIL
ITSM
Service Desk
Apply
See all jobs
This is one of many
1,285,480 more open roles from verified company boards, updated every day.