AppSec Jobs
← Back to all jobs

Metrobank

Application Security Engineer

Metro ManilaPosted 2 weeks agoWebsite
Apply on LinkedIn →

At a Glance

CI/CDOWASPSASTDASTCISSPCISM

Responsibilities

  • Based on the approved IT security systems and application security architecture, develops detailed designs for implementation.
  • Formulate, review and maintain IT security policies, technical standards, internal ISD procedures and guidelines related to securing the information processing environment, IT facilities and connected third party services/providers of the Bank.
  • Provide support to CPSD and SQRD, serve as the security subject matter expert related to application security. Identify security design gaps in existing application systems and proposed architectures and recommend changes or enhancements.
  • Evaluate cost-effective solutions and prepare the business case for IT security projects.
  • Manage the testing of technical controls and monitors its implementation.
  • Define and document security tool/device standard configuration parameters. Ensures that application security tools are securely configured and functions effectively and efficiently.
  • Perform regular security configuration reviews, ensure efficacy of controls and use is optimized.
  • Monitor and if necessary, assist ITG administrators in ensuring problems of security devices/systems are timely resolved.
  • Review and/or evaluate vendor performance as part of VPRC process.
  • Review installation and changes to CI/CD pipeline.
  • Manages the implementation of baseline system security standards for application development.
  • Collaborates and coordinates with other ISD Departments to ensure that holistic ISD service is provided to internal customers.
  • Establish disaster recovery strategy of security tools implemented and ensures it is regularly tested for effectiveness.
  • Stay up to date with latest security technology and trends, vulnerabilities and threats.
  • Guide Infrastructure Security Specialists; review their work.
  • Proactively works with the SAID Head in implementing programs for the continuous improvement of the bank's information security plans and strategies.
  • Perform other information security governance, risk and compliance related duties and responsibilities as directed by the SAID Head.

Requirements

OWASPCI/CDCISSPSASTDAST
  • Graduate of any college degree in Computer Science or Information Security, or related technical field of expertise.
  • Extensive/in-depth knowledge and understanding of secure coding principles and OWASP Top 10.
  • Working experiences with designing/architecting CI/CD pipeline.
  • Certification may include SANS GIAC, CISSP, CISM, GWAPT, or equivalent.
  • At least 3+ years' experience in designing, implementing and maintaining application security solutions such as SAST, DAST, IAST, etc.
  • Analytical and risk identification skills to analyze a variety of information security related risk situations and develop recommendations on the best course of action
  • Scripting and programming – computer programming and scripting skills is an advantage.
  • Strong written and oral communication skills to write technical reports on their assessments and communicate potential security weaknesses.
  • Should also be abreast with security best practices and knowledge of common and emerging security threats.
  • Self-starter, result-orientated in terms of disposition for corrective action to drive the remediation to reduce the risk exposure of the bank.
  • Have good teamwork and collaboration skills: good team players with the ability to lead security initiatives.
  • Good project management skills to lead and manage accomplishments of assigned tasks/projects within the predetermined time-frame
  • Good communication skills: to effectively articulate and explain complex security topics in simple language and easy to understand concepts.

About Metrobank

Metropolitan Bank & Trust Company, commonly known as Metrobank, is a leading universal bank in the Philippines, founded in 1962. Headquartered in Makati, it has grown to become the second largest private universal bank in the country, employing around 14,000 professionals. Metrobank offers a wide range of banking and financial services, including corporate, commercial, and consumer banking, credit card services, remittances, investment banking, and microfinancing. With a strong domestic and international presence, Metrobank operates over 940 branches and more than 2,300 ATMs across the Philippines, along with over 30 international branches and offices. The bank serves a diverse clientele, including large corporations, small-to-medium enterprises, high net-worth individuals, and retail customers. Metrobank has achieved significant financial success, reporting a net income of PHP 23.6 billion in the first half of 2024, and has received numerous awards for its services, including recognition as the Most Recommended Retail Bank in the Philippines.

Industry

banking

Employees

14,000

277 engineers

Revenue

$2.7B

Website

Visit →

Security at Metrobank

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

Metrobank's AppSec mission is to "Develop and enforce security plans and standards; ensures that application security best practices are executed and implemented."Their approach to developer enablement includes reviewing "installation and changes to CI/CD pipeline."The risk philosophy involves providing "risk assessment support to CPSD and SQRD related to architecture for security concerns."A stated goal is to "Maintain and mature the security tools to ensure effective prevention and detection of incidents."Information on developer enablement versus strict gating beyond CI/CD pipeline review is not publicly available.

Security Team

The Chief Information Security Officer (CISO) leads Metrobank's Information Security Division. A Board-level IT Steering Committee provides governance and oversight for the Bank's IT resources. Key public-facing AppSec leaders and the estimated team size are not publicly available. As of, there are 6 active AppSec job postings. Common skill patterns include "Full knowledge and understanding of OWASP Top 10 Application Security best practices"and "At least 3+ years' experience in designing, implementing and maintaining application security solutions such as SAST, DAST, IAST, etc."

Key Initiatives

The status of a Security Champions Program is not publicly available. For "Shift Left"practices, Metrobank reviews "installation and changes to CI/CD pipeline."Their vulnerability management process includes the Information Security Division conducting "annual penetration tests on all critical systems."Details on triage and remediation, such as SLAs or MTTR, are not publicly available. Secure SDLC artifacts involve managing "the implementation of baseline system security standards for application development."Information on recent initiatives (last 6 months) is not publicly available.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn