About this role
COMPANY OVERVIEW
Our client is an organization operating within the BPO Industry , focused on providing tech solutions for its partners . The company serves North American, European, and APAC regions and is committed to delivering quality solutions, operational excellence, and sustainable business growth. Additional information about the organization will be shared with selected candidates at the appropriate stage of the recruitment process.
Location: Ortigas
Work Setup: Onsite
Compensation Range: up to ₱60,000
KEY RESPONSIBILITIES
- Conduct vulnerability assessments and penetration testing across web applications, mobile applications, and other relevant technology environments to identify and validate security weaknesses.
- Prepare, document, and submit VAPT reports, periodic assessment reports, and other required security documentation.
- Present assessment findings to stakeholders in a clear and concise manner, providing actionable remediation recommendations.
- Support cybersecurity and non-cybersecurity teams in vulnerability assessments, penetration testing activities, and security-related initiatives.
- Validate, monitor, and track identified vulnerabilities through remediation and closure, including findings from various threat intelligence sources.
- Monitor Common Vulnerabilities and Exposures (CVEs), conduct zero-day vulnerability analysis, and support cloud security assessment activities.
- Contribute to Threat Exposure and Attack Surface Management initiatives to identify, assess, and reduce organizational exposure to security risks.
- Analyze technical vulnerabilities, evaluate potential business impacts, and recommend appropriate mitigation and remediation measures.
##
REQUIRED QUALIFICATIONS
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or another related four-year degree program.
- At least 1 year of hands-on experience in web and/or mobile application vulnerability assessment and penetration testing (VAPT), penetration testing, or security research.
- Strong understanding of the OWASP Top 10 and its application in web application security testing.
- Hands-on experience with open-source and/or commercial security testing tools, such as Kali Linux, Metasploit, Qualys, Nessus, Burp Suite, OWASP ZAP, or equivalent tools.
- Ability to identify and validate vulnerabilities, interpret technical findings, and recommend appropriate remediation measures.
- Strong analytical, problem-solving, technical documentation, and communication skills.
##
PREFERRED QUALIFICATIONS
- Knowledge of Industrial Control Systems (ICS), Operational Technology (OT), DevOps, or related technologies.
- Working knowledge of web and mobile application development, common application architectures, and associated security risks.
- Experience assessing vulnerabilities identified through threat intelligence sources and supporting vulnerability remediation tracking.
- Familiarity with cloud security, CVE monitoring, zero-day vulnerability analysis, and Threat Exposure and Attack Surface Management initiatives.
- Cybersecurity certifications such as Certified Ethical Hacker (CEH), Certified Information Systems Security Professional (CISSP), or other relevant industry certifications.
##
REQUIRED SKILLS & TECHNOLOGIES
- Vulnerability Assessment & Penetration Testing: Web and mobile application VAPT, penetration testing, vulnerability validation, risk assessment, and remediation tracking.
- Security Frameworks: OWASP Top 10 and common application security vulnerabilities.
- Security Testing Tools: Kali Linux, Metasploit, Qualys, Nessus, Burp Suite, OWASP ZAP, and equivalent tools.
- Threat & Vulnerability Management: CVE monitoring, threat intelligence analysis, zero-day vulnerability assessment, and vulnerability lifecycle management.
- Cloud & Infrastructure Security: Cloud security assessment and familiarity with relevant infrastructure security risks.
- Emerging Security Areas: Threat Exposure and Attack Surface Management, with exposure to ICS, OT, or DevOps environments considered an advantage.
- Reporting & Communication: VAPT reporting, technical documentation, stakeholder presentations, and remediation recommendations.
- Core Competencies: Analytical thinking, problem-solving, attention to detail, collaboration, and effective communication with technical and non-technical stakeholders.
ABOUT PAXSIGNA
PaxSigna is a specialist talent solutions division of the Lennor Group focused on Technology, Semiconductor & Electronics, and Advanced Engineering. We partner with startups, growth-stage businesses, and multinational enterprises to connect exceptional talent with transformative opportunities across highly specialized markets.
EQUAL OPPORTUNITY STATEMENT
PaxSigna is committed to fostering an inclusive and equitable recruitment process. All qualified applicants will receive consideration based on their qualifications, experience, capabilities, and business requirements.
DATA PRIVACY NOTICE
By submitting your application, you acknowledge that your personal information may be collected, processed, stored, and shared with authorized stakeholders solely for recruitment-related purposes in accordance with applicable data privacy laws and regulations.
LEGAL NOTICE
PaxSigna is a specialist talent solutions division of the Lennor Group. Recruitment and talent acquisition services are facilitated through Lennor Metier Consulting Philippines, Inc., the group's duly registered operating entity in the Philippines.
