{"id":2166846,"url":"https://alion.io/job/manulife-application-security-engineer-secure-developmentsecrets-management","title":"Application Security Engineer (Secure Development/Secrets Management)","company":{"id":6650,"name":"Manulife","domain":"manulife.com","url":"https://alion.io/company/manulife","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":99,"open_postings":102,"ghost_share":0,"stale_share":0.196,"repost_share":0.059,"time_to_fill_p50_days":20,"computed_at":"2026-10-10T05:45:15Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Manila, Philippines"],"countries":["PH"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":22000,"max_usd":50000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1824},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Azure","optional":false},{"name":"C#","optional":false},{"name":"CI/CD","optional":false},{"name":"GitGuardian","optional":false},{"name":"GitHub","optional":false},{"name":"GitHub Actions","optional":false},{"name":"HashiCorp Vault","optional":false},{"name":"Java","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"Snyk","optional":false},{"name":"Vault","optional":false},{"name":"Threat Modeling","optional":true}],"status":"live","first_seen_at":"2026-10-09T10:26:14Z","employer_posted_date":"2026-10-09","last_verified_at":"2026-10-11T15:51:01Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"We are looking for an Application Security Engineer (Secure Development and Secrets Management) to join the Global Cybersecurity Services (GCS) - Application Security Rapid Lab Team. In this role, you will partner with Application Security teams, developers, and business stakeholders to advance enterprise secrets remediation and secure software development initiatives. The candidate should have working knowledge of designing and implementing secure solutions that eliminate hard-coded secrets, strengthen application security controls, and integrate applications with approved enterprise platforms such as Azure Key Vault and HashiCorp Vault. The candidate may support these activities based on business and project needs. The ideal candidate combines strong software engineering fundamentals with hands-on application security experience and can clearly communicate remediation strategies, architecture decisions, and technical contributions.\nHave the skills and experience for the job? Learn more about it below!\nPosition Responsibilities:\nApplication Security and Secrets Remediation: Assess applications for hard-coded secrets, credentials, certificates, API keys, and configuration risks; support the definition and implementation of secure migration approaches using Azure Key Vault, HashiCorp Vault, or equivalent approved platforms.\nSecure Software Development: Design, develop, and maintain secure backend services, APIs, reusable components, libraries, and utilities using Java, Python, C#, or equivalent technologies, applying secure-by-design and Secure SDLC principles.\nAutomation and Integration: Contribute to the development of scalable automation and automated remediation capabilities, integrate security controls into CI/CD pipelines, and help reduce manual remediation effort across multiple applications.\nSecurity Assessment and Remediation: Analyze and prioritize findings from SAST, DAST, SCA, secrets scanning, penetration testing, code reviews, and other assessments; support risk-based remediation with minimal business impact.\nArchitecture and Preventive Controls: Participate in solution and architecture reviews, recommend secure patterns, and address root causes to reduce recurring security risks.\nStakeholder Engagement: Participate in discovery, requirements gathering, solution design, and technical reviews. Communicate security risks, trade-offs, remediation plans, and implementation guidance to technical and non-technical stakeholders across global teams.\nRequired Qualifications:\nBachelor’s degree in Computer Science, Software Engineering, Computer Engineering, Information Technology, Cybersecurity, or a related technical discipline.\nMinimum of five years of software engineering experience, including secure application development and vulnerability remediation using Java, Python, C#, or equivalent technologies.\nProven experience developing backend applications, APIs, reusable components, automation utilities, and security-focused tools or frameworks.\nHands-on experience applying Secure SDLC principles and secure coding practices across design, development, testing, deployment, and maintenance.\nExperience triaging and remediating findings from SAST, DAST, SCA, secrets scanning, penetration testing, code reviews, and vulnerability assessments.\nWorking knowledge of secrets management, credential lifecycle management, and application integration using Azure Key Vault, HashiCorp Vault, or equivalent enterprise platforms.\nKnowledge of securely managing API keys, tokens, certificates, database credentials, and other application secrets, including remediation and rotation practices.\nStrong understanding of application security, OWASP Top 10, vulnerability management, API security, backend architecture, object-oriented programming, design patterns, and reusable component design.\nHands-on experience with GitHub, GitHub Actions, GitGuardian, Snyk, CI/CD pipelines, modern development environments, and security testing or vulnerability management platforms.\nDemonstrated ability to explain technical designs, architecture decisions, security trade-offs, remediation approaches, and individual project contributions.\nAbility to work independently, manage complex technical challenges, and collaborate effectively with developers, architects, executives, and business stakeholders.\nExcellent verbal and written communication, problem-solving, customer focus, and stakeholder management skills.\n Amenable to work at UP Ayala Technohub, Quezon City under a hybrid setup (three days a week).\nAmenable to work on a fixed late mid-shift or night-shift schedule based on business requirements.\nPreferred Qualifications:\nExperience supporting enterprise Application Security, Secrets Management, DevSecOps, or Platform Security programs.\nExperience in financial services, insurance, or another regulated industry, including work with globally distributed and multicultural teams.\nKnowledge of Microsoft Azure, cloud-native security controls, workload identity, identity integration, certificate management, secrets rotation, and CI/CD security controls.\nRelevant certifications such as ISC2 CSSLP, CompTIA Security+, GIAC GSEC, GIAC GWEB, GIAC GWAPT, HashiCorp Certified: Vault Associate, GitHub Advanced Security, GitHub Actions, or an equivalent industry credential.\nRelevant training in secure coding, Secure SDLC, OWASP Top 10, threat modeling, application security architecture, vulnerability remediation, and defensive web application security.\nProduct or platform training in Azure Key Vault, HashiCorp Vault, GitHub Advanced Security, GitHub Actions, GitGuardian, Snyk, secrets detection and remediation, and CI/CD security.\nExposure to or hands-on experience with AI-assisted software development, security automation, or the responsible use of generative AI to support secure coding, vulnerability analysis, remediation, testing, and developer workflows.\nExperience contributing to process improvement initiatives, including identifying automation opportunities, simplifying workflows, addressing root causes, defining measurable outcomes, and improving the efficiency and scalability of Application Security services.\nWhen you join our team:\nWe’ll empower you to learn and grow the career you want. \nWe’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words. \nAs part of our global team, we’ll support you in shaping the future you want to see.\nAbout Manulife and John Hancock\nManulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.\nManulife is an Equal Opportunity Employer\nAt Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.\nIt is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact .\nWorking Arrangement\nHybrid","description_format":"text","description_chars":8046,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Philippines","iso":"PH","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Application Security","Commercial & Retail Banks","Asset Management & Funds","Health Insurance & Benefits"],"lifecycle":[{"event":"open","at":"2026-10-09T10:26:14Z"}],"visa":[],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":0,"expected_fill_days":20,"reasons":["conf:3","velocity","win:early","comp:brand"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/manulife-application-security-engineer-secure-developmentsecrets-management","json_url":"https://alion.io/job/manulife-application-security-engineer-secure-developmentsecrets-management.json","meta":{"generated_at":"2026-10-11T18:54:36Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler_verified","counted_by":"address","units_charged":1,"used_today":5172,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":6650},"rest":"https://alion.io/mcp/rest/get_company?id=6650"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fmanulife-application-security-engineer-secure-developmentsecrets-management"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fmanulife-application-security-engineer-secure-developmentsecrets-management"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fmanulife-application-security-engineer-secure-developmentsecrets-management"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/manulife-application-security-engineer-secure-developmentsecrets-management\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fmanulife-application-security-engineer-secure-developmentsecrets-management"}]}