{"id":1167537,"url":"https://alion.io/job/manulife-application-security-engineer-threat-modeling","title":"Application Security Engineer (Threat Modeling)","company":{"id":6650,"name":"Manulife","domain":"manulife.com","url":"https://alion.io/company/manulife","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":95,"open_postings":67,"ghost_share":0,"stale_share":0.403,"repost_share":0.015,"time_to_fill_p50_days":18,"computed_at":"2026-09-25T05:45:01Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Manila, Philippines"],"countries":["PH"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":21000,"max_usd":46000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1098},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agile","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"OWASP","optional":false},{"name":"STRIDE","optional":false},{"name":"Threat Modeling","optional":false},{"name":"AI Agents","optional":true},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"GCP","optional":true},{"name":"Kubernetes","optional":true},{"name":"Material Design","optional":true}],"status":"live","first_seen_at":"2026-09-24T04:21:28Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-09-25T20:02:02Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"We are looking for an experienced Application Security Engineer specializing in Threat Modeling to join our Global Cybersecurity Services (GCS) Team. In this individual-contributor role, you will serve as a trusted security partner to engineering, architecture, product, and risk teams. You will identify design risks early, translate them into practical security requirements, and help ensure agreed mitigations are implemented throughout the software development lifecycle. The role requires sound technical judgment, strong facilitation skills, and the ability to explain complex security risks clearly to both technical and business stakeholders.\nKey Responsibilities:\nIndependently lead threat modeling engagements for applications, APIs, cloud services, third-party integrations, and significant technology changes from early design through implementation.\nWork with engineering and architecture teams to define scope and document system components, assets, data flows, entry points, trust boundaries, dependencies, and key assumptions.\nApply an appropriate threat modeling approach, such as STRIDE, attack trees, abuse cases, PASTA, or LINDDUN, based on the system, risk, and business context.\nAssess threats using likelihood, impact, exploitability, asset criticality, existing controls, and business context; document clear, defensible risk decisions.\nTranslate identified threats into practical security requirements, design recommendations, test criteria, and remediation actions, and track them through closure or formal risk acceptance.\nProvide governance and quality oversight at key stages of the threat modeling process, confirming that scope, assets, threats, mitigations, and supporting evidence are complete and aligned with security standards.\nEmbed threat modeling into architecture reviews, agile delivery, change management, security testing, penetration testing, and other Secure SDLC activities.\nMaintain and improve standards, templates, threat libraries, secure design patterns, and reusable mitigation guidance; identify opportunities for automation and self-service adoption.\nCoach delivery teams, review the quality and coverage of threat models, identify recurring design risks, and communicate outcomes, exceptions, and trends to technical and business stakeholders.\nProduce accurate service metrics and reporting that demonstrate delivery performance, adoption, quality, mitigation follow-through, and measurable risk reduction.\nRequired Qualifications:\nBachelor’s degree in Computer Science, Software Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.\nAt least five years of relevant experience across threat modeling, application security, security architecture, secure software development, cloud security, or a related discipline.\nDemonstrated experience leading collaborative threat modeling or secure design reviews for applications, APIs, cloud-native systems, distributed architectures, or third-party integrations.\nAbility to analyze architectures and data flows, identify trust boundaries and attack paths, prioritize material threats, and translate findings into testable requirements and practical mitigations.\nPractical knowledge of at least one established threat modeling method, such as STRIDE, attack trees, abuse cases, PASTA, or LINDDUN, with the ability to select and adapt methods for different engagements.\nWorking knowledge of application and API security, identity and access management, data protection, cloud and network architecture, containers, distributed systems, and common attack techniques.\nFamiliarity with relevant standards and frameworks, including OWASP guidance, MITRE ATT&CK, and the NIST Secure Software Development Framework.\nExperience incorporating threat modeling into architecture governance, Secure SDLC activities, security testing, penetration testing, remediation, and risk acceptance processes.\nStrong analytical, facilitation, technical-writing, and stakeholder-management skills, with the ability to work independently and communicate risk clearly to technical and business audiences.\nAmenable to work at UP Ayala Technohub, Quezon City, under a hybrid arrangement with three onsite days per week.\nAmenable to work a fixed late mid-shift or night-shift schedule based on business requirements.\nPreferred Qualifications:\nExperience supporting an enterprise threat modeling, application security, product security, or security architecture program, preferably in financial services, insurance, or another regulated industry.\nExperience assessing modern architectures, including Microsoft Azure, AWS, Google Cloud, Kubernetes, microservices, event-driven systems, APIs, mobile applications, or AI-enabled solutions.\nExperience creating reusable threat libraries, reference threat models, secure design patterns, architecture decision records, or mitigation guidance.\nExperience with threat modeling or diagramming tools such as Microsoft Threat Modeling Tool, OWASP Threat Dragon, IriusRisk, pytm, Visio, or comparable solutions.\nKnowledge of privacy threat modeling, software supply-chain risks, AI and agentic-system risks, cloud shared-responsibility models, or emerging attack techniques.\nExperience improving adoption through developer enablement, self-service approaches, automation, quality criteria, metrics, or maturity assessments.\nA relevant security or architecture certification, such as ISC2 CSSLP or CISSP, Microsoft Azure Security Engineer Associate, GIAC Defensible Security Architecture, SABSA, TOGAF, or an equivalent credential.\nWhat Success Looks Like:\nThreat modeling engagements are completed on time, with clear scope, strong technical coverage, and decisions that stakeholders can act on.\nMaterial design risks are identified early and translated into practical requirements that are tracked to closure or documented risk acceptance.\nThreat models remain current as architectures change, and mitigation evidence is complete, traceable, and aligned with governance expectations.\nDelivery teams increasingly apply repeatable threat modeling practices through effective coaching, reusable guidance, and self-service resources.\nRecurring design risks and service trends are converted into measurable improvements to standards, tooling, automation, and the Secure SDLC.\nWhen you join our team:\nWe’ll empower you to learn and grow the career you want. \nWe’ll recognize and support you in a flexible environment where well-being and inclusion are more than just words. \nAs part of our global team, we’ll support you in shaping the future you want to see.\nManulife is an Equal Opportunity Employer\nAt Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.\nIt is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact .\nAbout Manulife and John Hancock\nManulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.\nManulife is an Equal Opportunity Employer\nAt Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.\nIt is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact .\nWorking Arrangement\nHybrid","description_format":"text","description_chars":9502,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"Philippines","iso":"PH","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Penetration Testing","Application Security","Commercial & Retail Banks","Health Insurance & Benefits"],"lifecycle":[{"event":"open","at":"2026-09-24T04:21:28Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":18,"reasons":["conf:3","velocity","win:early","comp:brand"],"computed_at":"2026-09-25T05:45:01Z"},"pay":null,"html_url":"https://alion.io/job/manulife-application-security-engineer-threat-modeling","json_url":"https://alion.io/job/manulife-application-security-engineer-threat-modeling.json","meta":{"generated_at":"2026-09-26T00:33:35Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":492,"day_limit":5000,"remaining_today":4508,"minute_limit":60,"resets_at":"2026-09-27T00:00:00Z"}}}