{"id":1950410,"url":"https://alion.io/job/manulife-application-security-enablement-engineer","title":"Application Security Enablement Engineer","company":{"id":6650,"name":"Manulife","domain":"manulife.com","url":"https://alion.io/company/manulife","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":99,"open_postings":74,"ghost_share":0,"stale_share":0.216,"repost_share":0.068,"time_to_fill_p50_days":20,"computed_at":"2026-10-06T05:45:30Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Makati, Philippines"],"countries":["PH"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":23000,"max_usd":54000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1567},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Kubernetes","optional":true}],"status":"live","first_seen_at":"2026-10-06T09:50:05Z","employer_posted_date":"2026-10-06","last_verified_at":"2026-10-07T00:04:44Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"The Asia CISO function is responsible for ensuring effective cybersecurity risk management, regulatory compliance, and secure technology enablement across all Asia markets. This role sits within the regional cybersecurity leadership team and is accountable for application security enablement across the software development lifecycle. It serves as the bridge between global application security strategy and regional execution, driving outcomes through strong partnership and influence across application development, engineering, and architecture teams in both regional and market environments.\nDeliver application security engineering and enablement capabilities across Asia, embedding secure development practices into the software development lifecycle (SDLC) and enabling adoption of enterprise security standards. This role focuses on driving vulnerability assessment, prioritization and remediation, centralized exception review, threat modeling, and SME support to strengthen application security posture.\nPosition Responsibilities:\nHelp drive adoption of enterprise application security standards across applications, platforms, and cloud environments\nEnable automation for vulnerability detection, remediation, exception review and reporting to improve efficiency and consistency.\nProvide actionable, risk-based technical guidance and training to developers on secure design and coding standards (e.g., OWASP).\nPartner with architects, product owners, and development teams during design and planning phases to embed secure-by-design principles.\nConduct and validate application security testing (automated and manual), including intake and validation of findings from external penetration tests and bug bounty programs.\nAccountabilities:\nIndividual Accountabilities:\nSupport vulnerability management processes, including triage, exception review, remediation, and reporting.\nConduct application and architecture-level Threat Modeling for new applications, major enhancements, and high-risk changes.\nSupport uplift of Threat Modeling maturity by defining templates, playbooks, and reusable threat libraries for common platforms and patterns.\nSupport to scale workstreams such as secrets, SCA, SAST, DAST vulnerability remediation.\nPartner with development teams to integrate security expectations into CI/CD pipelines and DevSecOps workflows.\nValidate and contextualize findings from automated tools, penetration tests, and external assessments where design-level issues are identified.\nKey Shared Accountabilities:\nPartner with Global Application Security on standards, tooling and continuous improvement\nCollaborate with CIO, engineering, and architecture teams to ensure consistent adoption and accountability\nAlign with Vulnerability Management function on remediation prioritization and risk treatment\nSupport audit, regulatory, and control assurance activities\nRequired Qualifications:\nMinimum 5+ years in application security or software development roles with a focus on secure coding and DevSecOps.\nStrong understanding of application security principles, SDLC, and CI/CD pipelines. \nStrong understanding of application penetration testing\nKnowledge of secure coding standards and frameworks (e.g., OWASP Top 10, NIST).\nExcellent collaboration and communication skills to engage developers and stakeholders.\nPreferred Qualifications:\nHands-on experience with security tools (e.g., Secrets, SCA, SAST, Container security, DAST) and automation frameworks.\nFamiliarity with cloud-native application security concepts.\nCertifications: OSCP, CISSP or preferred equivalent.\nAdditional certifications such as Advanced application testing certifications (OSWP, GIAC GWAPT, INE eWPTX) are considered an advantage.\nTooling and Technology Coverage:\nIn addition to SAST, DAST, and SCA, familiarity with complementary controls such as WAF and NAC were relevant to application-layer protection.\nPractical exposure to API security, Kubernetes and container platforms, Infrastructure as Code (IaC), hybrid cloud environments, and penetration testing or vulnerability scanning toolchains.\nWhen you join our team:\nWe’ll empower you to learn and grow the career you want.\nWe’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.\nAs part of our global team, we’ll support you in shaping the future you want to see.\nAbout Manulife and John Hancock\nManulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.\nManulife is an Equal Opportunity Employer\nAt Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.\nIt is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact .\nWorking Arrangement\nHybrid","description_format":"text","description_chars":5956,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Commercial & Retail Banks","Asset Management & Funds","Health Insurance & Benefits"],"lifecycle":[{"event":"open","at":"2026-10-06T09:50:05Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":20,"reasons":["conf:0","win:early","comp:brand"],"computed_at":"2026-10-07T00:35:33Z"},"pay":null,"html_url":"https://alion.io/job/manulife-application-security-enablement-engineer","json_url":"https://alion.io/job/manulife-application-security-enablement-engineer.json","meta":{"generated_at":"2026-10-07T00:35:33Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1025,"day_limit":5000,"remaining_today":3975,"minute_limit":60,"resets_at":"2026-10-08T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":6650},"rest":"https://alion.io/mcp/rest/get_company?id=6650"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fmanulife-application-security-enablement-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fmanulife-application-security-enablement-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fmanulife-application-security-enablement-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/manulife-application-security-enablement-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fmanulife-application-security-enablement-engineer"}]}