Application Security Enablement Engineer
Core
Drive application security enablement across Asia markets by embedding secure development practices into the SDLC and partnering with engineering teams to strengthen application security posture.
Role type
Application Security Enablement Engineer
Builds
Secure application development workflows and risk-based security controls across cloud environments
Domain
Financial Services / Application Security
Required skills
Application security principles, SDLC integration, CI/CD pipeline security, vulnerability assessment, threat modeling, secure coding standards (OWASP), penetration testing, risk-based guidance
Preferred skills
Security automation frameworks, cloud-native security concepts, container security, API security, Infrastructure as Code (IaC), hybrid cloud environments
Technologies
SAST, DAST, SCA, WAF, NAC, Kubernetes, Container platforms, Penetration testing tools, Vulnerability scanning toolchains
Responsibilities
Drive adoption of enterprise application security standards across applications and platforms; Enable automation for vulnerability detection, remediation, and exception review; Provide technical guidance and training to developers on secure design and coding; Partner with architects and development teams to embed secure-by-design principles; Conduct and validate application security testing including intake of external penetration test and bug bounty findings; Support vulnerability management processes including triage and reporting; Conduct application and architecture-level Threat Modeling for new applications and high-risk changes (via careerplan.io/jobs/JR26100250-application-security-enablement-engineer-at-manulife)
Seniority
Mid-Senior, hands-on IC
