Skip to content
1R Use Case_on page- Elevating shipment handling
Explore our open vacancies here at CHAMP
businessman hand working with modern technology digital tablet computer and graphics layer effect as business strategy concept

Security Software Engineer

 Location: Philippines

Publish Date:  11/12 /2025

If you apply, please include your CV.

Overview

CHAMP Cargosystems provides the most comprehensive range of integrated IT solutions and distribution services for the air cargo transport chain. Our portfolio spans core management systems, messaging services, and eCargo solutions. These include applications designed to meet customs and security requirements, quality optimization, as well as e-freight and mobility needs. Our products and services are recognized globally under the Cargospot and Traxon brands.

We serve over 200 airlines and GSAs, connecting them with approximately 3,000 forwarders and GHAs worldwide. Our solutions help customers, and their clients, adapt to the critical and ongoing changes in air transport logistics and meet the demands of global trade.

Headquartered in Luxembourg, CHAMP Cargosystems operates offices in Reading, Zurich, Frankfurt, Manila, Singapore, and Atlanta.

We are looking for a Security Software Engineer to join our Security & GRC team.

The role will report to the Security Architect.

Location: Manila, Philippines

 

Responsibilities

We are looking for a motivated Software Developer who is looking to transition into a security-focused role and join our Product Security Team. As a Security Software Engineer, you will leverage your background in software development (primarily Java-based web applications) to identify, remediate, and prevent vulnerabilities in our SaaS products. You will play a key role in embedding security into our agile development lifecycle, working closely with developers, product owners, and external penetration testers.

 

Vulnerability Remediation

  • Analyze penetration testing reports and remediate vulnerabilities in application code.
  • Collaborate with developers to implement secure fixes and improve coding practices.
  • Act as a bridge between external security experts and internal development teams.

 

Offensive Security & Testing

  • Build skills in penetration testing and ethical hacking, focusing on web applications and APIs.
  • Contribute to regular security assessments integrated into CI/CD pipelines.
  • Participate in threat modeling exercises and simulate attacker techniques.

 


Secure Development Governance

  • Help define and enforce secure coding standards for Java and web application development.
  • Propose secure code libraries and reusable components to accelerate secure development.
  • Support the integration of security requirements into user stories and agile sprints.

 


Tooling & Automation

  • Assist in configuring SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) solutions.
  • Contribute to building unit test frameworks with embedded security checks.
  • Support automation of security testing in CI/CD pipelines.

 


Education & Enablement

  • Act as a security champion within development squads, promoting secure coding practices.
  • Share knowledge with peers on threat modeling, secure design, and vulnerability prevention.
  • Grow into a role where you can conduct independent penetration testing and expand scope to infrastructure security.

 

Knowledge, skills, and abilities :

  • Background in software development, ideally with experience in Java web applications.
  • Familiarity with agile/SCRUM methodology and CI/CD pipelines.
  • Strong interest in transitioning into application security and penetration testing.
  • Analytical mindset with problem-solving skills and attention to detail.
  • Excellent communication skills to collaborate with developers, product owners, and security specialists.

Education and Experience:

  • Bachelor’s or Master’s degree in Software Engineering, Cybersecurity, or related field.
  • 4-6 years of experience in software development with hands-on exposure to Java web applications.
  • Exposure to security testing tools (SAST, DAST, vulnerability scanners).
  • Knowledge of secure coding practices and common web application vulnerabilities (OWASP Top 10, CWE/SANS Top 25, STRIDE).
  • Interest in pursuing certifications such as OSCP, CSSLP, or CISSP.

The selected candidate may be subject to the provision of an up-to-date (not older than 3 months) criminal record certificate.

Our culture and values

We believe happy employees create thriving work environments. With over 500 team members from 32 countries, speaking over 30 languages, CHAMP is a uniquely diverse and welcoming place to work. Our globally minded staff collaborates with clients and vendors worldwide from our offices in London, Zürich, Manila, Atlanta, Singapore, and our Headquarters in the Grand Duchy of Luxembourg.
CHAMP Corporate Value Posters - Desktop wallpaper-01
CHAMP Corporate Value Posters - Desktop wallpaper-02-1
CHAMP Corporate Value Posters - Desktop wallpaper-03

 

 

 

 

 

Security: the successful candidate will have to comply with CHAMP Security Requirements (including but not limited to CHAMP’s IT Security Policies, especially the ISMS Policy and the Acceptable Use Policy, mandatory courses, confidentiality and data protection, use of company assets, and incident reporting).

  

CHAMP Cargosystems is an equal opportunity employer and prohibits discrimination and harassment of any kind. We are committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions are based on business needs, job requirements and individual qualifications, without regard to race, ethnic background, religion or belief, family or parental status, or any other status protected by the laws or regulations in the locations where we operate.

Please note that any personal data that you submit along with your application will be processed by CHAMP and may be processed by any of its global entities as necessary. These data will be treated in strict compliance with the applicable data protection legislation (i.e. the Law of 2 August 2002 on the protection of individuals with regard to the processing of personal data, as amended, and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, - the GDPR -, which entered into force on 25 May 2018, as well as any other subsequent regulation).Please follow the link to the CHAMP Candidates Privacy Notice for further information.