730,610open jobs
43,655companies
102,906added this week
Browse all
Salary
$16k – $38k per year (Estimated)
Location
Remote/Hybrid (Manila, Philippines)
Seniority
Middle · 3+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Sep 24, 2026. Manulife scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Manulife is a Canadian insurance and asset management group founded in Toronto in 1887, with the first Canadian prime minister as its founding president. It sells life and health insurance, annuities and retirement products in Canada, the United States under the John Hancock brand and across a dozen Asian markets, and runs Manulife Investment Management as a global asset manager for institutional and retail clients. Headquartered in Toronto and listed in Toronto, New York and Hong Kong, it earns a growing share of its profit in Asia and has been reducing its exposure to legacy long-term care liabilities through reinsurance transactions.

We are looking for an experienced Application Security Engineer to serve as the quality-assurance point for penetration testing deliverables across applications and APIs. In this individual-contributor role, you will independently review reports and findings before release, confirm that risk ratings and supporting evidence are sound, and help application teams move findings through remediation and closure. You will work closely with penetration testers, vulnerability management leads, and technology stakeholders to maintain consistent reporting standards, improve testing quality, and provide clear, risk-based guidance.

Key Responsibilities:

  • Perform final quality reviews of penetration test reports before release, ensuring findings are technically accurate, reproducible, supported by sufficient evidence, within the approved scope, and written for both technical and business audiences.
  • Validate affected assets, exploitation paths, business impact, duplicate findings, and false positives; challenge conclusions when the evidence does not support the stated risk.
  • Review and calibrate severity ratings using CVSS, exploitability, asset criticality, business impact, environmental context, and existing compensating controls.
  • Confirm that test scope, methodology, coverage, assumptions, limitations, and conclusions are complete and clearly documented; work with testers to address gaps before reports are issued.
  • Provide practical, risk-based remediation guidance and help application teams understand the issue, expected corrective action, and evidence required for closure.
  • Track open findings and agreed remediation dates, coordinate retesting, validate corrective actions, and document closure decisions or residual risks.
  • Triage newly disclosed or emerging vulnerabilities to determine relevance, potential exposure, required validation, and appropriate escalation.
  • Support day-to-day Burp Suite and Snyk operations, including access requests, scan configuration, issue triage, troubleshooting, scheduling, reporting, and coordination with platform owners.
  • Maintain quality standards, review checklists, reporting templates, and operating procedures; identify recurring defects and recommend improvements to testing, reporting, and aftercare processes.
  • Produce accurate status updates and quality metrics, and escalate material risks, overdue actions, or delivery concerns to the appropriate stakeholders.

Required Qualifications:

  • Bachelor’s degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.
  • At least three years of relevant experience in penetration testing, application security, vulnerability assessment, vulnerability management, or security quality assurance.
  • Hands-on experience reviewing penetration test reports, validating technical evidence, assessing exploitability and business impact, assigning or challenging severity ratings, and confirming remediation through retesting.
  • Strong knowledge of web application and API security, common attack techniques, authentication and authorization weaknesses, OWASP testing practices, CVSS, CWE, and vulnerability classification.
  • Practical experience with Burp Suite Professional or comparable web and API security testing tools.
  • Working knowledge of SAST, DAST, SCA, open-source vulnerability management, DevSecOps pipelines, and the end-to-end vulnerability management lifecycle.
  • Strong analytical judgment and attention to detail, with the ability to distinguish material risk from low-value noise and make defensible, evidence-based decisions.
  • Clear written and verbal communication skills, including the ability to explain technical risk and remediation expectations to technical and non-technical stakeholders.
  • Ability to manage competing priorities, follow through on commitments, and work effectively with globally distributed teams.
  • Amenable to a hybrid work arrangement at UP Ayala Technohub, Quezon City, with three onsite days per week.
  • Amenable to a fixed late mid-shift or night-shift schedule based on business requirements.

Preferred Qualifications:

  • Experience performing or reviewing penetration tests for web applications, APIs, mobile applications, cloud environments, or networks, including assessments delivered by third-party providers.
  • Experience in enterprise application security or vulnerability management within financial services, insurance, or another regulated industry.
  • Familiarity with OWASP WSTG, PTES, NIST SP 800-115, or comparable penetration testing and reporting standards.
  • Experience using vulnerability management or issue-tracking platforms to manage evidence, ownership, remediation dates, exceptions, retesting, and closure.
  • Experience with Snyk administration or enterprise application security tooling, including onboarding, scan configuration, troubleshooting, reporting, and stakeholder support.
  • Ability to automate data processing, quality checks, workflow updates, dashboards, or reports using Python, PowerShell, Unix shell, VBA, or a similar scripting language.
  • A relevant certification such as OSCP, OSWE, CREST CCT/CRT, GIAC GWAPT/GPEN, CompTIA PenTest+, or an equivalent credential.

What Success Looks Like:

  • Penetration test reports are complete, technically defensible, consistent, and ready for stakeholders on time.
  • Findings are accurately prioritized, clearly explained, and supported by evidence that enables timely remediation.
  • Retesting and closure decisions are traceable, risk-based, and aligned with established standards.
  • Recurring quality issues are identified and converted into practical improvements to testing, reporting, and aftercare processes.
  • undefined

When you join our team:

We’ll empower you to learn and grow the career you want. We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words. As part of our global team, we’ll support you in shaping the future you want to see.

Manulife is an Equal Opportunity Employer At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law. It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].

Working Arrangement

Hybrid
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
730,610 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Manila
$21k – $46k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Manila
AI/ML
AI Agents
Mobile
Material Design
DevOps
GCP
Azure
AWS
Kubernetes
Cybersecurity
MITRE ATT&CK
STRIDE
Threat Modeling
OWASP
Management
Agile
Apply
$34k – $101k per year (Estimated) • Remote/Hybrid • Bachelor's Degree • Bari
Python
JavaScript
TypeScript
SQL
Python
SQLAlchemy
FastAPI
Databases
Redis
AI/ML
Fine-tuning
LLM
Red Teaming
Machine Learning
Frontend
Tailwind CSS
React.js
DevOps
Rest API
CI/CD
Git
Cybersecurity
OWASP
Apply
$79k – $209k per year (Estimated) • In office • Internship • Portland
DevOps
Linux
Windows
Cybersecurity
PCI DSS
OWASP
Management
SharePoint
Microsoft Office
Apply
$46k – $96k per year (Estimated) • Remote (Colombia) • Full-Time • Master's Degree • Colombia
DevOps
Azure
SLI/SLO/SLA
IAM
Cybersecurity
NIST CSF
CVSS
SIEM
DLP
Apply
$30k – $35k per year • Remote/Hybrid • Bachelor's Degree • Milan
Python
JavaScript
TypeScript
SQL
Python
SQLAlchemy
FastAPI
Databases
Redis
AI/ML
Fine-tuning
LLM
Red Teaming
Machine Learning
Frontend
Tailwind CSS
React.js
DevOps
Rest API
CI/CD
Git
Cybersecurity
OWASP
Apply
In office • Full-Time • Bachelor's Degree • Singapore
Apply
$21k – $46k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Manila
AI/ML
AI Agents
Mobile
Material Design
DevOps
GCP
Azure
AWS
Kubernetes
Cybersecurity
MITRE ATT&CK
STRIDE
Threat Modeling
OWASP
Management
Agile
Apply
In office • Full-Time • Bachelor's Degree • Singapore
Management
Agile
Scrum
Apply
$70k – $176k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Singapore
Apply
$70k – $176k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Singapore
Management
Agile
Scrum
Apply
$12k – $27k per year (Estimated) • In office • Full-Time • Manila
Apply
In office • Full-Time • Bachelor's Degree • Manila
Management
Microsoft Office
Apply
In office • Full-Time • Manila
Apply
In office • Full-Time • Manila
Apply
Remote/Hybrid • Full-Time • 1+ year exp • Manila
Marketing
Salesforce
Apply
See all jobs
This is one of many
730,610 more open roles from verified company boards, updated every day.