1,438,441open jobs
85,144companies
219,560added this week
Browse all
Salary
≈ $21k – $49k per year (Estimated)
Location
Hybrid (Manila, Philippines)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 11, 2026. First seen by Alion on Oct 9, 2026. Manulife scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Manulife is a Canadian insurance and asset management group founded in Toronto in 1887, with the first Canadian prime minister as its founding president. It sells life and health insurance, annuities and retirement products in Canada, the United States under the John Hancock brand and across a dozen Asian markets, and runs Manulife Investment Management as a global asset manager for institutional and retail clients. Headquartered in Toronto and listed in Toronto, New York and Hong Kong, it earns a growing share of its profit in Asia and has been reducing its exposure to legacy long-term care liabilities through reinsurance transactions.

We are looking for an Application Security Engineer (Secure Development and Secrets Management) to join the Global Cybersecurity Services (GCS) - Application Security Rapid Lab Team. In this role, you will partner with Application Security teams, developers, and business stakeholders to advance enterprise secrets remediation and secure software development initiatives. The candidate should have working knowledge of designing and implementing secure solutions that eliminate hard-coded secrets, strengthen application security controls, and integrate applications with approved enterprise platforms such as Azure Key Vault and HashiCorp Vault. The candidate may support these activities based on business and project needs. The ideal candidate combines strong software engineering fundamentals with hands-on application security experience and can clearly communicate remediation strategies, architecture decisions, and technical contributions.

Have the skills and experience for the job? Learn more about it below!

Position Responsibilities:

  • Application Security and Secrets Remediation: Assess applications for hard-coded secrets, credentials, certificates, API keys, and configuration risks; support the definition and implementation of secure migration approaches using Azure Key Vault, HashiCorp Vault, or equivalent approved platforms.
  • Secure Software Development: Design, develop, and maintain secure backend services, APIs, reusable components, libraries, and utilities using Java, Python, C#, or equivalent technologies, applying secure-by-design and Secure SDLC principles.
  • Automation and Integration: Contribute to the development of scalable automation and automated remediation capabilities, integrate security controls into CI/CD pipelines, and help reduce manual remediation effort across multiple applications.
  • Security Assessment and Remediation: Analyze and prioritize findings from SAST, DAST, SCA, secrets scanning, penetration testing, code reviews, and other assessments; support risk-based remediation with minimal business impact.
  • Architecture and Preventive Controls: Participate in solution and architecture reviews, recommend secure patterns, and address root causes to reduce recurring security risks.
  • Stakeholder Engagement: Participate in discovery, requirements gathering, solution design, and technical reviews. Communicate security risks, trade-offs, remediation plans, and implementation guidance to technical and non-technical stakeholders across global teams.

Required Qualifications:

  • Bachelor’s degree in Computer Science, Software Engineering, Computer Engineering, Information Technology, Cybersecurity, or a related technical discipline.
  • Minimum of five years of software engineering experience, including secure application development and vulnerability remediation using Java, Python, C#, or equivalent technologies.
  • Proven experience developing backend applications, APIs, reusable components, automation utilities, and security-focused tools or frameworks.
  • Hands-on experience applying Secure SDLC principles and secure coding practices across design, development, testing, deployment, and maintenance.
  • Experience triaging and remediating findings from SAST, DAST, SCA, secrets scanning, penetration testing, code reviews, and vulnerability assessments.
  • Working knowledge of secrets management, credential lifecycle management, and application integration using Azure Key Vault, HashiCorp Vault, or equivalent enterprise platforms.
  • Knowledge of securely managing API keys, tokens, certificates, database credentials, and other application secrets, including remediation and rotation practices.
  • Strong understanding of application security, OWASP Top 10, vulnerability management, API security, backend architecture, object-oriented programming, design patterns, and reusable component design.
  • Hands-on experience with GitHub, GitHub Actions, GitGuardian, Snyk, CI/CD pipelines, modern development environments, and security testing or vulnerability management platforms.
  • Demonstrated ability to explain technical designs, architecture decisions, security trade-offs, remediation approaches, and individual project contributions.
  • Ability to work independently, manage complex technical challenges, and collaborate effectively with developers, architects, executives, and business stakeholders.
  • Excellent verbal and written communication, problem-solving, customer focus, and stakeholder management skills.
  • Amenable to work at UP Ayala Technohub, Quezon City under a hybrid setup (three days a week).
  • Amenable to work on a fixed late mid-shift or night-shift schedule based on business requirements.

Preferred Qualifications:

  • Experience supporting enterprise Application Security, Secrets Management, DevSecOps, or Platform Security programs.
  • Experience in financial services, insurance, or another regulated industry, including work with globally distributed and multicultural teams.
  • Knowledge of Microsoft Azure, cloud-native security controls, workload identity, identity integration, certificate management, secrets rotation, and CI/CD security controls.
  • Relevant certifications such as ISC2 CSSLP, CompTIA Security+, GIAC GSEC, GIAC GWEB, GIAC GWAPT, HashiCorp Certified: Vault Associate, GitHub Advanced Security, GitHub Actions, or an equivalent industry credential.
  • Relevant training in secure coding, Secure SDLC, OWASP Top 10, threat modeling, application security architecture, vulnerability remediation, and defensive web application security.
  • Product or platform training in Azure Key Vault, HashiCorp Vault, GitHub Advanced Security, GitHub Actions, GitGuardian, Snyk, secrets detection and remediation, and CI/CD security.
  • Exposure to or hands-on experience with AI-assisted software development, security automation, or the responsible use of generative AI to support secure coding, vulnerability analysis, remediation, testing, and developer workflows.
  • Experience contributing to process improvement initiatives, including identifying automation opportunities, simplifying workflows, addressing root causes, defining measurable outcomes, and improving the efficiency and scalability of Application Security services.

When you join our team:

  • We’ll empower you to learn and grow the career you want.
  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we’ll support you in shaping the future you want to see.

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].

Working Arrangement

Hybrid
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,438,441 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Manila
≈ $11k – $25k per year (Estimated) • In office • 3+ years exp • Greater Noida
Databases
SAP HANA
Apply
≈ $15k – $32k per year (Estimated) • In office • 5+ years exp • Bengaluru
DevOps
CI/CD
Cybersecurity
SIEM
Apply
≈ $14k – $30k per year (Estimated) • In office • 5+ years exp • Chennai
Cybersecurity
Ping Identity
Apply
≈ $82k – $178k per year (Estimated) • In office • Full-Time • Sankt Gallen
DevOps
Windows
Cybersecurity
Active Directory
SIEM
Apply
≈ $83k – $181k per year (Estimated) • In office • Full-Time • Cham
DevOps
VPN
Cybersecurity
Palo Alto NGFW
Management
WhatsApp
Apply
≈ $15k – $38k per year (Estimated) • Hybrid • Full-Time • Bachelor's Degree • Chennai
Python
Java
C#
DevOps
Shift-Left
Linux
Windows
Unix
Cybersecurity
Shift-Left Security
PKI
Cryptography
Bouncy Castle
Apply
≈ $24k – $57k per year (Estimated) • Hybrid • Full-Time • 9+ years exp • Bachelor's Degree • Chennai
Python
Java
SQL
Scala
Databases
MySQL
Snowflake
Databricks
Oracle
Apache Iceberg
DynamoDB
MS SQL
Google BigQuery
Amazon Redshift
BigQuery
AI/ML
Hadoop
Spark
DevOps
CI/CD
Docker
Kubernetes
Amazon S3
Analytics
Power BI
ETL/ELT
Informatica
Talend
Management
Agile
Apply
≈ $15k – $37k per year (Estimated) • Hybrid • Full-Time • Bachelor's Degree • Chennai
Python
C#
C#
.NET
DevOps
Shift-Left
Linux
Windows
Unix
Cybersecurity
Shift-Left Security
PKI
Cryptography
Bouncy Castle
Apply
≈ $14k – $34k per year (Estimated) • In office • Full-Time • Saint Petersburg
Python
Bash
DevOps
Ansible
GitLab CI
CI/CD
Docker
Kubernetes
GitLab
Linux
Apply
Data Analyst 2 days ago
≈ $9.5k – $20k per year (Estimated) • Hybrid • Full-Time • Pune
Python
Python
pySpark
AI/ML
Spark
DevOps
Unix
Apply
≈ $23k – $54k per year (Estimated) • In office • Full-Time • 5+ years exp • Makati
DevOps
CI/CD
Kubernetes
Cybersecurity
OWASP Top 10
Threat Modeling
OWASP
Apply
≈ $13k – $34k per year (Estimated) • Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Manila
Python
JavaScript
SQL
PowerShell
AI/ML
Anomaly Detection
Machine Learning
DevOps
TCP/IP
DNS
DHCP
Management
Microsoft Office
Apply
≈ $21k – $49k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Manila
AI/ML
AI Agents
Mobile
Material Design
DevOps
GCP
Azure
AWS
Kubernetes
Cybersecurity
MITRE ATT&CK
STRIDE
Threat Modeling
OWASP
Management
Agile
Apply
≈ $16k – $38k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Manila
Python
PowerShell
DevOps
Unix
Cybersecurity
Burp Suite
Snyk
CWE
CVSS
OWASP
Apply
Cybersecurity Manager 24 days ago
≈ $16k – $37k per year (Estimated) • In office • Full-Time • 3+ years exp • Manila
Cybersecurity
Zero Trust
DLP
Analytics
Power BI
Management
Confluence
ServiceNow
Agile
Apply
≈ $75k – $148k per year (Estimated) • Hybrid • Contractor • 3+ years exp • Manila
Analytics
Power BI
Microsoft Excel
Management
ServiceNow
Outlook
SharePoint
ITSM
Apply
≈ $7k – $20k per year (Estimated) • Remote (Philippines) • Full-Time • 1+ year exp • PhD • Manila
DevOps
Incident Management
VPN
Management
Google Workspace
ITIL
Service Desk
Microsoft Office
Apply
≈ $15k – $32k per year (Estimated) • Hybrid • 3+ years exp • Manila
Management
Microsoft Project
Outlook
Apply
≈ $10k – $25k per year (Estimated) • Remote (Philippines) • Full-Time • Manila
Apply
≈ $8.5k – $20k per year (Estimated) • Hybrid • Full-Time • Manila
Management
Microsoft Office
Apply
See all jobs
This is one of many
1,438,441 more open roles from verified company boards, updated every day.