VAPT Engineer
Our client, a global technology and digital solutions company, is looking for a VAPT Engineer to join their cybersecurity team on a 1-Year Project-Based Contract, with the possibility of extension based on business requirements and project needs.
The successful candidate will be responsible for identifying and assessing security vulnerabilities across applications, APIs, networks, cloud environments, and infrastructure through comprehensive vulnerability assessments and penetration testing.
This role is suited for a hands-on cybersecurity professional with a strong interest in ethical hacking, offensive security, and vulnerability management, who can help strengthen the organization's overall cybersecurity posture.
Key Responsibilities
-
Perform Vulnerability Assessment and Penetration Testing (VAPT) across:
-
Web applications
-
Mobile applications
-
APIs
-
Internal and external networks
-
Cloud environments
-
IT infrastructure
-
-
Conduct both manual and automated security testing.
-
Identify, validate, and exploit security vulnerabilities in controlled testing environments.
-
Assess the severity and potential impact of identified vulnerabilities.
-
Provide practical remediation recommendations to relevant technical teams.
-
Prepare detailed technical reports and executive summaries of assessment findings.
-
Collaborate with development, infrastructure, and security teams to validate remediation efforts.
-
Perform security re-testing following remediation.
-
Support security audits and compliance assessments when required.
-
Stay up to date with emerging cybersecurity threats, attack techniques, vulnerabilities, and security testing tools.
-
Contribute to improving security testing methodologies and processes.
Qualifications
-
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
-
At least 3 years of hands-on experience in vulnerability assessment, penetration testing, or offensive security.
-
Proven experience conducting vulnerability assessments and penetration testing across web applications, APIs, networks, cloud-hosted applications, and infrastructure.
-
Strong understanding of:
-
OWASP Top 10
-
Web application security
-
API security
-
Network security
-
Authentication and authorization mechanisms
-
Application session management
-
Mobile application security
-
-
Hands-on experience with security testing tools such as:
-
Burp Suite
-
Nmap
-
Metasploit
-
Nessus
-
Wireshark
-
OpenVAS
-
-
Experience with manual penetration testing and exploit validation.
-
Good knowledge of Linux and Windows environments.
-
Scripting experience using Python, Bash, PowerShell, or similar languages.
-
Understanding of secure coding concepts and application security principles.
-
Knowledge of modifying, adapting, and compiling exploit code.
-
Strong technical documentation and report-writing skills.
-
Knowledge of DevSecOps and integrating security practices into CI/CD pipelines.
Preferred Qualifications
-
Relevant cybersecurity certifications such as:
-
OSCP
-
CEH
-
eJPT
-
GWAPT
-
CISSP
-
SANS certifications
-
GXPN
-
-
Experience in one or more of the following:
-
Mobile application security testing
-
Cloud security
-
Red Team activities
-
Source code review
-
DevSecOps
-
-
Participation in ethical hacking programs, Bug Bounty programs, Capture the Flag (CTF) competitions, or similar activities.
-
Experience working in regulated or security-sensitive environments.
Nice to Have
-
Knowledge of secure SDLC practices and cybersecurity compliance frameworks.
-
Experience working in fast-paced production environments with strict security and remediation timelines.
-
Exposure to large-scale enterprise applications and technology environments.
What We Offer
-
Opportunity to work on hands-on cybersecurity and offensive security projects.
-
Exposure to a broad range of applications, infrastructure, and security technologies.
-
Opportunity to strengthen expertise in VAPT, application security, and cloud security.
-
Collaborative environment with opportunities for continuous learning and development.
-
Potential for contract extension based on business and project requirements.
Work Setup
-
Fully onsite for the first 3 months
-
Hybrid setup thereafter – 3 days onsite per week
-
1-Year Project-Based Contract, with potential for extension depending on business and project requirements.
Due to the high volume of applications we are experiencing, our team will only be in touch with you if your application is shortlisted.
About the job
Contract Type: Perm
Specialism: Tech & Transformation
Focus: Cyber Security
Industry: Financial Services
Salary: PHP60000 - PHP70000 per month
Workplace Type: Hybrid
Experience Level: Associate
Location: Makati
FULL_TIMEJob Reference: 0F1U9X-2269AC24
Date posted: 7 October 2026
Consultant: Cyrene Villanueva
philippines tech-transformation/cyber-security 2026-10-07 2026-12-06 financial-services Makati National Capital Region PH PHP 60000 70000 70000 MONTH Robert Walters https://www.robertwalters.com.ph https://www.robertwalters.com.ph/content/dam/robert-walters/global/images/logos/web-logos/square-logo.png true