Application Security Engineer (Threat Modeling)

Manulife Insurance Malaysia
Long Island City, New York, US
Full-time

Application Security Engineer (Threat Modeling)

Please read the information in this job post thoroughly to understand exactly what is expected of potential candidates.

We are a leading financial services provider committed to making decisions easier and lives better for our customers and colleagues around the world.

From our environmental initiatives to our community investments, we lead with values throughout our business. To help us stand out, we help you step up, because when colleagues are healthy, respected and meaningfully challenged, we all thrive.

Discover how you can grow your career, make impact and drive real change with our Winning Team today.

Working Arrangement : Hybrid

Job Description :

We are looking for Application Security Engineer (Threat Modeling) who will be directly reporting to the Manulife ETS Cyber Assessment Application Security Team.

Our group consists of highly motivated and experienced professionals located across different Manulife locations such as Manila and North America.

As part of the ETS Global Cyber Security, we are responsible for identifying, classifying, monitoring, remediating and / or mitigating security vulnerabilities on applications, network and APIs across the organization.

Have the skills and knowledge for the job? Learn more about the opening below!

Key Responsibilities :

  • Strategic Cybersecurity : Contribute to the strategic guidance on the design of cybersecurity measures for complex systems and networks, incorporating product security strategies such as design principles and security architecture.
  • Security Review : Perform and coordinate in-depth security reviews, pinpoint potential vulnerabilities, and suggest comprehensive remediation strategies by utilizing threat modeling methodologies and threat assessment frameworks.
  • Security Insights : Provide sound analysis on the security implications of introducing new systems or interfaces within our ecosystem, based on application security best practices, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) implementation.
  • Security Architecture Evaluation : Assess proposed security architectures and designs to ensure they meet both current and future security needs, reviewing data flow diagrams for applications / system architectures and identifying potential threats as part of the threat modeling process.

Qualifications :

  • University / College graduate with at least 2 years of experience related to Application Security and Threat Modeling.
  • Must have a background in application development / technology management.
  • Good experience in application security architecture.
  • Comprehensive understanding of security principles and their business implications.
  • Broad knowledge of networking concepts.
  • Good background in secure software development methodologies.
  • Familiarity with various application security testing approaches and implementation.
  • Understanding of penetration testing concepts.
  • Knowledge of industry trends, regulatory requirements, and their impact on security architecture.
  • Advocate constant learning from both success and failure, encouraging openness to change and continuous improvement.
  • Recognizable organizational and problem-solving abilities that enable you to manage through creative abrasion.
  • Proven stakeholder management skills and able to effectively articulate risk posture, technical vision, possibilities, and outcomes through strong verbal and written communication.
  • Self-driven, able to meet objectives with minimal managerial oversight / supervision.
  • Amenability and readiness to work onsite and from home anytime (dependent on business need and / or current external environment / situation).

People Leader Role : No

Learn more about opportunities with us at jobs.manulife.com.

Manulife is an Equal Opportunity Employer

At Manulife / John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals.

We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.

Who is MBPS?

Manulife Business Processing Services (MBPS) is a global shared service center providing administrative, finance, investments, contact center, information technology, underwriting, actuarial, and marketing services to Manulife and John Hancock companies around the world.

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services group that helps people make their decisions easier and lives better.

With our global headquarters in Toronto, Canada, we operate as Manulife across our offices in Asia, Canada, and Europe, and primarily as John Hancock in the United States.

We provide financial advice, insurance, and wealth and asset management solutions for individuals, groups, and institutions.

J-18808-Ljbffr

2 days ago
Related jobs
Promoted
VirtualVocations
Queens, New York

Product Security Engineer - Application Security (Remote). ...

Promoted
Blackbird.AI
New York, New York

We are seeking a highly skilled Principal Application Security Engineer to join our team. As the Principal Application Security Engineer, you will:. Minimum of 10 years of experience in application security engineering. Your expertise will be instrumental in helping us achieve key security certifica...

Promoted
VirtualVocations
New York, New York

A company is looking for a Security Threat Intelligence Engineer to join their Technology Practice Group in a remote capacity. ...

Promoted
GuidePoint Security, LLC
Queens, New York
Remote

Solid working knowledge of application security fundamentals including the OWASP Top 10, threat modeling, and implementing secure coding practices throughout the Software Development Lifecycle (SDLC). Past experience as an application security practitioner or software engineer. GuidePoint Security p...

Promoted
VirtualVocations
New York, New York

A company is looking for an Application Security Engineer to enhance the security of their software applications. ...

Promoted
Blackbird
Queens, New York

We are seeking a highly skilled Principal Application Security Engineer to join our team. As the Principal Application Security Engineer, you will:. Minimum of 10 years of experience in application security engineering. A diverse team of AI experts, threat intelligence analysts, and national securit...

Promoted
Amazon
Queens, New York

Minimum of 3 years of experience with at least two of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, penetration testing, cloud security, mobile security, and network security. Security Engineer II, Application Se...

Promoted
Capital One
New York, New York

We are looking for an experienced security engineer to join our Capital One Application Security team. Principal Associate, Application Security Engineer. As a Capital One Security team member, you will help secure our applications for our customers while working on cutting edge security products fo...

MedReview
New York, New York

You will be responsible for the strategic implementation of security measures to protect MedReview’s applications and data, while mentoring junior engineers and shaping our security posture as well as identifying and removing bottlenecks for your teammates, both in process and technology As a ...

Cisco
New York, New York

You must be highly accomplished in the areas of application security concepts, cloud security concepts, and more specifically the entire Cloud Application Security Development and Deployment lifecycle. The Cloud & AppSec Incubation Solutions Engineer at Cisco is a member of a best-in-class technical...