738,400open jobs
44,340companies
105,262added this week
Browse all
Salary
$21k – $46k per year (Estimated)
Location
Remote/Hybrid (Manila, Philippines)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Sep 24, 2026. Manulife scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Manulife is a Canadian insurance and asset management group founded in Toronto in 1887, with the first Canadian prime minister as its founding president. It sells life and health insurance, annuities and retirement products in Canada, the United States under the John Hancock brand and across a dozen Asian markets, and runs Manulife Investment Management as a global asset manager for institutional and retail clients. Headquartered in Toronto and listed in Toronto, New York and Hong Kong, it earns a growing share of its profit in Asia and has been reducing its exposure to legacy long-term care liabilities through reinsurance transactions.

We are looking for an experienced Application Security Engineer specializing in Threat Modeling to join our Global Cybersecurity Services (GCS) Team. In this individual-contributor role, you will serve as a trusted security partner to engineering, architecture, product, and risk teams. You will identify design risks early, translate them into practical security requirements, and help ensure agreed mitigations are implemented throughout the software development lifecycle. The role requires sound technical judgment, strong facilitation skills, and the ability to explain complex security risks clearly to both technical and business stakeholders.

Key Responsibilities:

  • Independently lead threat modeling engagements for applications, APIs, cloud services, third-party integrations, and significant technology changes from early design through implementation.
  • Work with engineering and architecture teams to define scope and document system components, assets, data flows, entry points, trust boundaries, dependencies, and key assumptions.
  • Apply an appropriate threat modeling approach, such as STRIDE, attack trees, abuse cases, PASTA, or LINDDUN, based on the system, risk, and business context.
  • Assess threats using likelihood, impact, exploitability, asset criticality, existing controls, and business context; document clear, defensible risk decisions.
  • Translate identified threats into practical security requirements, design recommendations, test criteria, and remediation actions, and track them through closure or formal risk acceptance.
  • Provide governance and quality oversight at key stages of the threat modeling process, confirming that scope, assets, threats, mitigations, and supporting evidence are complete and aligned with security standards.
  • Embed threat modeling into architecture reviews, agile delivery, change management, security testing, penetration testing, and other Secure SDLC activities.
  • Maintain and improve standards, templates, threat libraries, secure design patterns, and reusable mitigation guidance; identify opportunities for automation and self-service adoption.
  • Coach delivery teams, review the quality and coverage of threat models, identify recurring design risks, and communicate outcomes, exceptions, and trends to technical and business stakeholders.
  • Produce accurate service metrics and reporting that demonstrate delivery performance, adoption, quality, mitigation follow-through, and measurable risk reduction.

Required Qualifications:

  • Bachelor’s degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.
  • At least five years of relevant experience across threat modeling, application security, security architecture, secure software development, cloud security, or a related discipline.
  • Demonstrated experience leading collaborative threat modeling or secure design reviews for applications, APIs, cloud-native systems, distributed architectures, or third-party integrations.
  • Ability to analyze architectures and data flows, identify trust boundaries and attack paths, prioritize material threats, and translate findings into testable requirements and practical mitigations.
  • Practical knowledge of at least one established threat modeling method, such as STRIDE, attack trees, abuse cases, PASTA, or LINDDUN, with the ability to select and adapt methods for different engagements.
  • Working knowledge of application and API security, identity and access management, data protection, cloud and network architecture, containers, distributed systems, and common attack techniques.
  • Familiarity with relevant standards and frameworks, including OWASP guidance, MITRE ATT&CK, and the NIST Secure Software Development Framework.
  • Experience incorporating threat modeling into architecture governance, Secure SDLC activities, security testing, penetration testing, remediation, and risk acceptance processes.
  • Strong analytical, facilitation, technical-writing, and stakeholder-management skills, with the ability to work independently and communicate risk clearly to technical and business audiences.
  • Amenable to work at UP Ayala Technohub, Quezon City, under a hybrid arrangement with three onsite days per week.
  • Amenable to work a fixed late mid-shift or night-shift schedule based on business requirements.

Preferred Qualifications:

  • Experience supporting an enterprise threat modeling, application security, product security, or security architecture program, preferably in financial services, insurance, or another regulated industry.
  • Experience assessing modern architectures, including Microsoft Azure, AWS, Google Cloud, Kubernetes, microservices, event-driven systems, APIs, mobile applications, or AI-enabled solutions.
  • Experience creating reusable threat libraries, reference threat models, secure design patterns, architecture decision records, or mitigation guidance.
  • Experience with threat modeling or diagramming tools such as Microsoft Threat Modeling Tool, OWASP Threat Dragon, IriusRisk, pytm, Visio, or comparable solutions.
  • Knowledge of privacy threat modeling, software supply-chain risks, AI and agentic-system risks, cloud shared-responsibility models, or emerging attack techniques.
  • Experience improving adoption through developer enablement, self-service approaches, automation, quality criteria, metrics, or maturity assessments.
  • A relevant security or architecture certification, such as ISC2 CSSLP or CISSP, Microsoft Azure Security Engineer Associate, GIAC Defensible Security Architecture, SABSA, TOGAF, or an equivalent credential.

What Success Looks Like:

  • Threat modeling engagements are completed on time, with clear scope, strong technical coverage, and decisions that stakeholders can act on.
  • Material design risks are identified early and translated into practical requirements that are tracked to closure or documented risk acceptance.
  • Threat models remain current as architectures change, and mitigation evidence is complete, traceable, and aligned with governance expectations.
  • Delivery teams increasingly apply repeatable threat modeling practices through effective coaching, reusable guidance, and self-service resources.
  • Recurring design risks and service trends are converted into measurable improvements to standards, tooling, automation, and the Secure SDLC.

When you join our team:

  • We’ll empower you to learn and grow the career you want.
  • We’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words.
  • As part of our global team, we’ll support you in shaping the future you want to see.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.

Manulife is an Equal Opportunity Employer

At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].

Working Arrangement

Hybrid
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
738,400 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Manila
$15k – $35k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Mandaluyong
PowerShell
DevOps
Azure
Windows
Cybersecurity
Microsoft Defender
Microsoft Defender for Cloud
Active Directory
Analytics
Power BI
Management
Power Apps
OneDrive
Service Desk
Microsoft Office
Apply
$16k – $38k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Manila
Python
PowerShell
DevOps
Unix
Cybersecurity
Burp Suite
Snyk
CWE
CVSS
OWASP
Apply
$13k – $30k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Philippines
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
SIEM
DLP
Apply
$20k – $40k per year (Estimated) • In office • 3+ years exp • Irkutsk
DevOps
Windows Server
Linux
Windows
DNS
DHCP
VPN
Cybersecurity
Kaspersky
Apply
$23k – $46k per year (Estimated) • In office • 2+ years exp • Novosibirsk
Python
PowerShell
Bash
DevOps
Linux
Windows
TCP/IP
VPN
Cybersecurity
Nessus
ISO 27001
Ghidra
OpenVAS
VirusTotal
IBM QRadar
SIEM
DLP
Kaspersky
Apply
$16k – $38k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Manila
Python
PowerShell
DevOps
Unix
Cybersecurity
Burp Suite
Snyk
CWE
CVSS
OWASP
Apply
In office • Full-Time • Bachelor's Degree • Singapore
Management
Agile
Scrum
Apply
$70k – $176k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Singapore
Management
Agile
Scrum
Apply
$15k – $39k per year (Estimated) • In office • Full-Time • Malaysia
AI/ML
Edge AI
DevOps
GCP
Azure
AWS
Management
Agile
Apply
Reporter Rockhampton 12 hours ago
$72k – $201k per year (Estimated) • Remote/Hybrid • Full-Time • Australia
Management
Agile
Apply
$16k – $38k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Manila
Python
PowerShell
DevOps
Unix
Cybersecurity
Burp Suite
Snyk
CWE
CVSS
OWASP
Apply
$15k – $36k per year (Estimated) • In office • Full-Time • 3+ years exp • Manila
Cybersecurity
Zero Trust
DLP
Analytics
Power BI
Management
Confluence
ServiceNow
Agile
Apply
$15k – $35k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • Manila
Cybersecurity
Qualys Cloud Platform
CIS Benchmarks
Analytics
Power BI
Management
ServiceNow
Apply
Security Engineer 4 months ago
$16k – $37k per year (Estimated) • In office • Full-Time • 3+ years exp • Makati
Python
JavaScript
AI/ML
LLM
Red Teaming
DevOps
GCP
Azure
AWS
Cybersecurity
Burp Suite
Metasploit
OWASP ZAP
ISO 27001
OWASP Top 10
PCI DSS
SOC 2
OWASP ASVS
STRIDE
Threat Modeling
OWASP
Apply
Penetration Tester 4 months ago
$12k – $30k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Manila
Apply
$6k – $15k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Manila
DevOps
Windows
Management
Microsoft Office
Apply
$13k – $33k per year (Estimated) • In office • 1+ year exp • Manila
Apply
$12k – $35k per year (Estimated) • In office • 4+ years exp • Bachelor's Degree • Manila
SQL
Apply
$17k – $37k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Manila
Apply
$17k – $43k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Manila
Management
Google Sheets
Apply
See all jobs
This is one of many
738,400 more open roles from verified company boards, updated every day.