application Security OfficerAXA
Salary: Agreement
Work form: Full time
Posting Date: 29/01/2026
Deadline: 27/11/2021
Job Purpose:
The mission consists in filling the role of Application Security Office and Vulnerability Expert for regular qualification of application vulnerability, timely monitoring, collecting, analysing application vulnerability data and delivering vulnerability mitigation recommendation to the IT Teams.
The sources of information include but are not limited to Web Application Firewall (WAF) alerts, security scanner reports, published vulnerabilities from vendors and internal/external threat intelligence sources. The position will also support incident handling for application vulnerabilities.
Job Scope: * Lead the application security function in Asia and work closely with Global CyberDefense teams across the world.
Identify the vulnerability severity on our applications from Various automated tools like Qualys (DAST) and SCA - J-Frog XRAY
Analyze the impact of Security bulletins on our applications (using the application component inventory)
Prioritize the patches required and Coordinate with other security team members [Qualys Scan Execution team and Center of Excellence / WAF...] to run further scans and WAF patches
Track and record decisions made on how to treat the vulnerabilities
Oversight and coordinate all work related to application vulnerability management in Asia
Analyzing structured and unstructured datasets from various sources to analyses vulnerabilities and produce remediation recommendations
Prioritize the emergency of vulnerability remediation activities
Provide technical advisory to IT Production or Development Teams to effectively remediate vulnerabilities
Ensure timely follow up for remediation of vulnerabilities
Recommend compensatory measures when remediation takes time and the vulnerability exposure windows is not acceptable in regard to the threat level
Report on mitigation status and threat exposure
Own the application vulnerability management process and strive to optimize it
Assist in investigation of security issues by reviewing the results of WAF alerts and other vulnerability identification (vulnerability scanning, penetration testing, etc.)
Consult on incident handling which includes implementation of containment, protection and remediation activities
Perform manual testing using tool such as Burp suite
Flexible in supporting stream lining application security process and SSDLC and
Support initiative for improving overall application security maturity
Coordinate with Infra Security team for SCA vulnerabilities, identified through Qualys VM process.
Supporting Cloud migration project from application security standpoint and setting up the new process
Qualifications
At least 10 years' experience in Information Risk and Security management / consulting.
Experience in roll out of SSDLC and Application security for enterprise products /Application
Strong experience in SAST/DAST/SCA roll out.
Strong understanding of performing penetration tests, vulnerability assessments and infrastructure security reviews for the web and mobile applications.
Hands-on experience working with Qualys WAS and other application vulnerability scanning / pen test tools.
Help Penetration testing team to high light gap and qualities check of Vulnerabilities.
Strong experience on manual testing of vulnerabilities like Burpsuite ( OSCP skill set preferred)
Preferred Experience in J-Frog XRAY
Familiarity with the OWASP framework and application security best practices.
Experienced in secure application coding and application security scanning
Security Certificates in CISSP, CISA, CISM or equivalent is a great plus.
Strong technical understanding of threat and vulnerability scanning solutions, processes and systems
Knowledge and hands-on experience of WAF and virtual patching
Strong Knowledge of patch management
Knowledge of the legal and regulatory environment within which financial organisations operate (e.g. Singapore MAS)
In depth knowledge of applying Security controls to technology operational services
Strong communication skills, both written and verbal (English), to communicate effectively across a wide range of stakeholders. Proven ability to explain security issues in business language and business issues in security language
Capable of producing high quality output with a strong focus on attention to detail following design and delivery methods, tools and standards
Bachelors in Computer Science engineering or related fields
Experience
Demonstrable experience of designing / implementing / improving / managing / governing threat and vulnerability management service especially in applications
Demonstrable experience of continuous improvement of Security threat and vulnerability services
Demonstrable experience of effective incident management support
Demonstrable experience of project management in security projects preferred
Skills
Excellent communication skills
Ability to understand and communicate the requirements of business departments to the information technology department and vice versa
Excellent verbal and written English communication and presentation skills
Excellent inter-personal
AXA
The mission consists in filling the role of Application Security Office and Vulnerability Expert for regular qualification of application vulnerability, timely monitoring, collecting, analysing application vulnerability data and delivering vulnerability mitigation recommendation to the IT Teams.
The sources of information include but are not limited to Web Application Firewall (WAF) alerts, security scanner reports, published vulnerabilities from vendors and internal/external threat intelligence sources. The position will also support incident handling for application vulnerabilities.
Job Scope: * Lead the application security function in Asia and work closely with Global CyberDefense teams across the world.
Identify the vulnerability severity on our applications from Various automated tools like Qualys (DAST) and SCA - J-Frog XRAY
Analyze the impact of Security bulletins on our applications (using the application component inventory)
Prioritize the patches required and Coordinate with other security team members [Qualys Scan Execution team and Center of Excellence / WAF...] to run further scans and WAF patches
Track and record decisions made on how to treat the vulnerabilities
Oversight and coordinate all work related to application vulnerability management in Asia
Analyzing structured and unstructured datasets from various sources to analyses vulnerabilities and produce remediation recommendations
Prioritize the emergency of vulnerability remediation activities
Provide technical advisory to IT Production or Development Teams to effectively remediate vulnerabilities
Ensure timely follow up for remediation of vulnerabilities
Recommend compensatory measures when remediation takes time and the vulnerability exposure windows is not acceptable in regard to the threat level
Report on mitigation status and threat exposure
Own the application vulnerability management process and strive to optimize it
Assist in investigation of security issues by reviewing the results of WAF alerts and other vulnerability identification (vulnerability scanning, penetration testing, etc.)
Consult on incident handling which includes implementation of containment, protection and remediation activities
Perform manual testing using tool such as Burp suite
Flexible in supporting stream lining application security process and SSDLC and
Support initiative for improving overall application security maturity
Coordinate with Infra Security team for SCA vulnerabilities, identified through Qualys VM process.
Supporting Cloud migration project from application security standpoint and setting up the new process
Qualifications
At least 10 years' experience in Information Risk and Security management / consulting.
Experience in roll out of SSDLC and Application security for enterprise products /Application
Strong experience in SAST/DAST/SCA roll out.
Strong understanding of performing penetration tests, vulnerability assessments and infrastructure security reviews for the web and mobile applications.
Hands-on experience working with Qualys WAS and other application vulnerability scanning / pen test tools.
Help Penetration testing team to high light gap and qualities check of Vulnerabilities.
Strong experience on manual testing of vulnerabilities like Burpsuite ( OSCP skill set preferred)
Preferred Experience in J-Frog XRAY
Familiarity with the OWASP framework and application security best practices.
Experienced in secure application coding and application security scanning
Security Certificates in CISSP, CISA, CISM or equivalent is a great plus.
Strong technical understanding of threat and vulnerability scanning solutions, processes and systems
Knowledge and hands-on experience of WAF and virtual patching
Strong Knowledge of patch management
Knowledge of the legal and regulatory environment within which financial organisations operate (e.g. Singapore MAS)
In depth knowledge of applying Security controls to technology operational services
Strong communication skills, both written and verbal (English), to communicate effectively across a wide range of stakeholders. Proven ability to explain security issues in business language and business issues in security language
Capable of producing high quality output with a strong focus on attention to detail following design and delivery methods, tools and standards
Bachelors in Computer Science engineering or related fields
Experience
Demonstrable experience of designing / implementing / improving / managing / governing threat and vulnerability management service especially in applications
Demonstrable experience of continuous improvement of Security threat and vulnerability services
Demonstrable experience of effective incident management support
Demonstrable experience of project management in security projects preferred
Skills
Excellent communication skills
Ability to understand and communicate the requirements of business departments to the information technology department and vice versa
Excellent verbal and written English communication and presentation skills
Excellent inter-personal
AXA
Other Info
Philippines
Permanent
Full-time
Permanent
Full-time
Submit profile
AXA
About the company
AXA jobs
Makati City, Metro Manila
Position application Security Officer recruited by the company AXA at , Joboko automatically collects the salary of , finds more jobs on Application Security Officer or AXA company in the links above