Cookies & analytics consent
We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.
Read how we use data in our Privacy Policy and Terms of Service.
🤖 15+ AI Agents working for you. Find jobs, score and update resumes, cover letter, interview questions, missing keywords, and lots more.
Vertiv • Mandaluyong, Metro Manila, Philippines
Role & seniority: Analyst II | Application and Product Security (Senior Pen Tester potential within role duties)
Stack/tools: Security testing across embedded devices and cloud (AWS/Azure); internal testing and auditing; reporting and collaboration with engineering; GitLab issue management; familiarity with memory/dynamic analysis tools and low-level debugging (preferred/advantageous)
Conduct security assessments (embedded systems, mobile/web apps) and threat evaluations; perform pen testing, data bus monitoring, protocol analysis, and reverse engineering as needed
Interface with engineering teams to communicate findings, ensure compliance with security requirements, and help drive remediation and process improvements
Develop and document findings with proofs of concept; contribute to internal testing processes, lead testing activities across regions, and mentor junior resources
3+ years in information, application, and/or embedded product security; strong knowledge of security protocols, cryptography, authentication/authorization
Ability to communicate clearly to diverse stakeholders; proactive risk assessment and incident response involvement
Experience with embedded systems, web/mobile apps security testing, and threat modeling
CISSP, OSWE or equivalent; hands-on experience with IDA Pro, WinDbg, BinWalk, Valgrind, PIN, Panda, S2E; awareness of malware/exploit techniques
Real
Join a High-Performance Culture That Drives Innovation and Excellence At Vertiv, we don’t just hire talent—we cultivate leaders who drive innovation and engage teams to push the limits of what’s possible. As a global leader in critical digital infrastructure, we are scaling up to meet the demands of AI, data centers, and next-gen technology—and we need bold, high-performing individuals like YOU to take us to the next level. Why Vertiv?
High-Performance Culture: We empower you to think big, execute with excellence, and deliver impact. Our performance-driven mindset rewards those who challenge the status quo and drive meaningful change. Over 50 CEO Awards are given annually to recognize top talent moving the needle forward.
Leadership Without Limits: Leadership at Vertiv goes beyond just titles—it’s about accountability, trust, and ownership. Our leaders engage and drive with collaboration, innovation, and customer-centric thinking, setting the foundation for an action-focused culture.
Limitless Growth & Learning: We believe in continuous development. Whether through rotational programs or high-impact projects, you’ll have the opportunity to expand your expertise and grow your career.
A Place for Everyone: Our commitment to inclusion ensures that all employee’s unique strengths and perspectives are valued. Your voice matters, your growth is prioritized, and your success is celebrated.
The Analyst II | Application and Product Security is responsible for conducting security pen testing, monitoring, and auditing within a dynamic global organization. The products under test will have the coverage of embedded devices and cloud services. The Senior Pen Tester should have exposure to embedded devices as well as cloud services (AWS/Azure). Some of the products will be white box tests while others will be total black box engagements. A successful Senior Pen Tester will be able to take the product and evaluate the weak points in the design and implementation and focus in on those weaknesses to find security gaps. All the findings by the Senior Pen Tester will need to be clearly documented and relayed to the design team for mitigation. The Senior Pen Tester will need to be very versatile in their attack vectors and their knowledge of exploits. The ideal candidate will be well experienced in a broad range of attack vectors across a wide spectrum of devices from small, embedded devices to wide and complex cloud ecosystems. They will be responsible for interfacing with engineering teams to conduct security testing, auditing and should be able to explain the findings. They will be responsible for ensuring that engineering teams stay in compliance with the security expectations of the global organization. The Senior Pen Tester will be expected to stay current with the latest security threats and attack vectors that can be deployed against the product portfolio. They should also have experience in communicating clearly and concisely the findings of these activities to an audience. The testing activity and methodology deployed to confirm compliance is guided but expected to be enhanced by the Senior Pen Tester. The Senior Pen Tester will be expected to use their knowledge and experience to further develop internal testing processes and procedures.
Preferred knowledge experience includes Understanding and development experience of embedded systems / software, and web-based applications Linux network device driver/data-path performance exposure Familiarity with compilers, debuggers, disassemblers, and other low-level development and analysis tools Exposure to binary analysis tools such as IDA Pro, WinDbg, BinWalk, Valgrind, PIN, Panda, and S2E Working knowledge of hacking tools and techniques such as memory corruption exploits, rootkits, protocol poisoning, browser-based attacks, DNS poisoning, MetaSploit, nmap, Nessus, etc. Experience with UNIX kernel internals and low-level Windows internals Comfort with reading and understanding of x86 and/or ARM assembly Experience with program analysis techniques such as taint analysis, program slicing, symbolic execution, constraint solving, and dynamic instrumentation An understanding of common cryptographic algorithms and protocols including their weaknesses and attacks against them Ability to extract software/firmware from provided hardware Meaningful experience utilizing git (Github or gitlab) Understanding of network protocols and experience developing packet-level programs Experience with common microcontroller programming tools and debugging interfaces Linux network device driver/data-path performance exposure Exposure to Layer 2, Layer 3 networking, QoS Network and/or application security knowledge (L2/L3 firewall, DPI, IDS, IPS) Knowledge of common malware/botnet exploits and how they are targeted to exploit embedded systems Operating system configuration of Windows, Linux, Android, and iOS Computer boot process including boot loaders Conducting security evaluation and threat assessments of embedded systems, mobile applications, web applications An understanding of common cryptographic algorithms and protocols including their weaknesses and attacks against them Familiarity with compilers, debuggers, disassemblers, and other low-level development and analysis tools Having hands on real-time embedded C/C++ development experience that includes recent lab activities integrating with and debugging on target hardware.
The successful candidate will embrace Vertiv’s Core Principals & Behaviors to help execute our Strategic Priorities.
OUR CORE PRINCIPALS: Safety. Integrity. Respect. Teamwork. Diversity & Inclusion.
OUR STRATEGIC PRIORITIES Customer Focus Operational Excellence High-Performance Culture Innovation Financial Strength OUR BEHAVIORS Think Big and Execute Act With Urgency Own It Drive Continuous Improvement Promote Transparent and Open Communication Learn and Seek Out Development Foster a Customer-First Mindset Lead by Example #LI-DS5
Work Authorization
No calls or agencies please. Vertiv will only employ those who are legally authorized to work in the United States. This is not a position for which sponsorship will be provided. Individuals with temporary visas such as E, F-1, H-1, H-2, L, B, J, or TN or who need sponsorship for work authorization now or in the future, are not eligible for hire.
Equal Opportunity Employer
We promote equal opportunities for all with respect to hiring, terms of employment, mobility, training, compensation, and occupational health, without discrimination as to age, race, color, religion, creed, sex, pregnancy status (including childbirth, breastfeeding, or related medical conditions), marital status, sexual orientation, gender identity / expression (including transgender status or sexual stereotypes), genetic information, citizenship status, national origin, protected veteran status, political affiliation, or disability.