16th Floor, AIA Tower, 8767 Paseo de Roxas, Makati City, National Capital Region, Philippines Hybrid Full-time

Avaloq is hiring a Security Engineer

We are looking for a proactive Security Engineer who possesses hands-on experience in building, configuring, deploying, and operating security controls, with a special emphasis on Oracle Cloud Infrastructure (OCI). The ideal candidate is capable of transforming security requirements into automated, repeatable, and functional solutions, prioritising practical execution over theoretical expertise. There is a strong focus on GitOps methodologies, Infrastructure as Code, and secure-by-default engineering principles. Key Responsibilities Data Security: Deploy and manage DLP policies across endpoints, cloud, and network to prevent unauthorized data movement. Continuously refine DLP rules to reduce false positives. Endpoint Security: Deploy and manage endpoint security agents at scale across servers, VMs, and containers. Operate host-based intrusion detection, and log collection with tuned alerting. Configure antivirus/antimalware schedules, exclusions. Build automated response playbooks. Network Security: Tune IDS/IPS, WAF policies, and rate-limiting rules. Conduct firewall rule audits to eliminate overly permissive access and enforce least privilege. Cryptography & Certificate Management: Automate the full certificate lifecycle (generate, deploy, rotate, revoke) across all services. Configure encryption in transit and at rest using cloud-native and third-party KMS. Manage secrets management solutions with rotation, access policies, and CI/CD integration. Cloud Security & Secure-by-Default Configuration (OCI Preferred): Create secure-by-default templates (Terraform modules, cloud policies, guardrails) so all new resources meet security baselines. Operationalise OCI-native security services: Cloud Guard, Security Zones, Vulnerability Scanning, Bastion, WAF, and IAM compartment policies. Harden cloud resources (compute, storage, databases) and enforce tagging compliance. Remediate misconfigurations through code and automation, not just detection. GitOps Practices & Automation: Use GitHub as the single source of truth for all security configurations and infrastructure changes (version-controlled). Write and maintain Terraform modules (OCI provider) for security infrastructure provisioning. Enforce GitHub repository governance (branch protection, code owners, merge policies). Build CI/CD pipelines via GitHub Actions for terraform plan/apply, static analysis, policy-as-code enforcement, and automated security scans. Manage Terraform state securely (remote backends, state locking, encryption, RBAC). Script automation (Python/Bash) for log parsing, bulk changes, compliance reporting, and alert enrichment.
Job Details
Location 16th Floor, AIA Tower, 8767 Paseo de Roxas, Makati City, National Capital Region, Philippines
Work mode Hybrid
Employment Full-time
Category Security
Posted 5 months ago
or drop your CV first
About company
Avaloq logo
Avaloq is an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and wealth managers, investment managers, as well as retail and neo banks.
All jobs at Avaloq Visit website