GoTyme is a joint venture between the Gokongwei Group, one of the biggest conglomerates in the Philippines, and the Singapore-headquartered digital banking group Tyme. This venture combines the trusted Gokongwei brand, customer base, and distribution ecosystem with Tyme’s globally proven digital banking technology and hands-on experience building South Africa’s leading digital bank, TymeBank, one of the fastest-growing digital banks in the world today.
At GoTyme, we have embarked on a journey to democratize financial services and bring next-level banking to the Philippines. We seek individuals who share our belief that the game is worth changing, to join our growing team of GoTymers as we build, launch, and scale a bank that empowers all Filipinos to navigate a path to financial freedom.
About the role
We are seeking a Senior Cyber Security Engineer to join our cybersecurity team, operating with an AI- and automation-first mindset. This role goes beyond monitoring and response and requires technical leadership, deep investigative expertise, and the ability to design, improve, and scale security controls across cloud, endpoint, and identity environments.
The successful candidate will act as a subject-matter expert, leading complex investigations, driving proactive threat detection, mentoring junior engineers, and partnering with technology and business teams to continuously strengthen the organisation’s security posture.
Security Monitoring, Engineering & Analysis
Lead advanced monitoring and analysis of security events across AWS, Azure, and endpoint platforms
Design, enhance, and optimise detection logic using CloudTrail, GuardDuty, Security Hub, Azure Sentinel, Defender, and EDR/XDR tools
Proactively identify security gaps, misconfigurations, and control weaknesses across cloud and SaaS environments
Develop and maintain automated detection and response workflows using scripting and SOAR principles
Perform deep analysis of DLP alerts, ensuring protection of sensitive and regulated data
Incident Response, Forensics & Crisis Management
Act as a lead investigator for high-severity security incidents
Drive end-to-end incident response activities, including containment, eradication, and recovery
Conduct advanced host, cloud, and log-based forensic analysis
Produce executive-level incident reports, root-cause analyses, and post-incident improvement plans
Support tabletop exercises, incident simulations, and continuous improvement of IR playbooks
Threat Detection, Hunting & Intelligence
Lead proactive threat hunting activities using behavioural analytics and threat intelligence
Map detections to MITRE ATT&CK and continuously improve coverage
Perform advanced malware analysis and support reverse-engineering efforts when required
Translate threat intelligence into actionable detections and preventive controls
Stay ahead of emerging attack techniques, cloud-native threats, and identity-based attacks
Identity, Access & Privileged Security
Oversee monitoring and investigation of privileged access and identity-based threats
Lead IAM security reviews and contribute to least-privilege and zero-trust initiatives
Investigate anomalous authentication behaviour and insider-risk indicators
Partner with IAM teams to strengthen identity security architecture and controls
Security Engineering, Architecture & Enablement
Contribute to the design and improvement of cloud and enterprise security architectures
Define security requirements for new platforms, services, and integrations
Support compliance initiatives aligned to ISO 27001, SOC 2, NIST, PCI DSS and internal risk frameworks
Mentor junior engineers and analysts, providing technical guidance and review
Influence security strategy through technical insight and data-driven recommendations
Requirements
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field
7–10+ years of hands-on experience in cybersecurity engineering, SOC, or security operations roles
Demonstrated experience leading complex security investigations and incident response
Proven ability to design, tune, and maintain security detections at scale
Experience mentoring or technically leading other security practitioners
Deep expertise in AWS security services (CloudTrail, GuardDuty, Config, Security Hub)
Strong experience with Azure security tooling (Sentinel, Defender, Security Center)
Advanced knowledge of EDR/XDR platforms and endpoint telemetry
Hands-on experience with SIEM, SOAR, and log analytics platforms
Strong understanding of networking, IAM, authentication protocols, and attack vectors
Proficiency in Python, PowerShell, or Bash for automation and analysis
Experience applying threat hunting and detection engineering methodologies
Familiarity with AI-driven security tooling and prompt-based analysis
GoTyme is a joint venture between the Gokongwei Group, one of the biggest conglomerates in the Philippines, and the Singapore-headquartered digital banking group Tyme. This venture combines the trusted Gokongwei brand, customer base, and distribution ecosystem with Tyme’s globally proven digital ban...
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the Philippines.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the Philippines, connecting you to thousands of jobs fast!
Find the best jobs in the Philippines, apply in 1 click and get a job today!