Lead Agentic Security Engineer
IFS · Colombo, WESTERN PROVINCE, Sri Lanka
About The Role
As a Lead Agentic Security Engineer, you will provide technical leadership for security engineering across the organization. You will set technical direction, own critical security capabilities, drive cross-team security initiatives, and mentor engineers at all levels. You are accountable for the maturity and effectiveness of security engineering, balancing risk, delivery, and engineering realities.
This is a technical leadership role, not a people-management role — though it carries significant influence and mentorship responsibility.
Duties and accountabilities
Technical strategy and ownership
- Define and drive the technical direction for security engineering.
- Own critical security domains and capabilities end to end (AppSec, CloudSec, CI/CD security, vulnerability management).
- Set standards, patterns, and guardrails that scale across teams.
- Make and own high-impact, risk-based security decisions.
Cross-team leadership
- Lead security initiatives spanning multiple engineering teams.
- Act as the senior security point of contact for engineering leadership.
- Influence architecture and design across the organization.
- Align security efforts with business and delivery priorities.
Engineering and automation
- Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security), including AI-assisted and AI-augmented tooling for triage, correlation, and remediation guidance.
- Evaluate and apply AI and generative AI tools — for example AI-assisted code review, AI-powered vulnerability triage, and LLM-based threat and log analysis — to improve signal quality, coverage, and developer experience, while validating their output rather than trusting it blindly.
- Ensure security platforms are reliable, scalable, and maintainable.
- Build the team's fluency with AI-assisted engineering tools (e.g., AI coding assistants, AI-enabled security scanners) and set guardrails for their safe, effective use, including awareness of AI/LLM-specific risks such as prompt injection, model and data supply-chain exposure, and sensitive-data leakage.
Risk, incident, and compliance
- Lead response and root-cause analysis for significant security incidents.
- Identify systemic risks and drive long-term remediation.
- Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP).
- Coordinate external engagements (e.g., penetration testing vendors).
Mentorship and capability building
- Mentor engineers and emerging leads (including Associate Security Leads).
- Raise the overall security capability of engineering teams, including fluent, responsible use of AI-assisted tools.
- Champion a strong, pragmatic security culture.
What success looks like
- Security engineering direction is clear, pragmatic, and adopted.
- Critical risks are proactively identified and addressed.
- Engineering teams trust and act on security guidance.
- Security maturity improves measurably across the organization, including effective adoption of AI-assisted security tooling.
- Engineers grow under your mentorship.
- Typically 5+ years in security engineering, software engineering, or platform engineering.
- Proven track record owning security capabilities or programs at scale.
- Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, architecture).
- Strong hands-on engineering and automation background.
- Demonstrated technical leadership and cross-team influence.
- Practical fluency with AI tools in an engineering context — for example AI coding assistants, AI-assisted security scanning and triage, or LLM-based analysis — and the judgment to validate their output rather than trust it blindly.
Scope and expectations
- Technical leadership role, accountable for security engineering outcomes.
- Owns strategy and direction, not just delivery.
- Expected to influence without formal authority.
- Expected to challenge unsafe designs and decisions.
- Not a people-manager role (unless explicitly combined).
Nice to have
- Experience leading security in an enterprise product environment.
- Track record influencing engineering-wide standards.
- Experience mentoring senior engineers and leads.
- Experience applying AI/LLM tools to security engineering (e.g., AI-assisted threat modeling, AI-powered vulnerability correlation) and awareness of securing AI-enabled applications and pipelines.
- Relevant advanced certifications (not mandatory).
Qualifications
Core required qualifications
- Demonstrated experience in security engineering with hands-on involvement in automated security solutions.
- Working knowledge of DevSecOps principles and practices.
- Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions, or equivalent).
- Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash).
- Comfort working with AI-assisted development and security tools (e.g., AI coding assistants, AI-driven SAST/DAST/SCA triage) as part of the day-to-day toolkit, with the judgment to review and validate AI-generated output.
- Solid understanding of common vulnerabilities (e.g., OWASP Top 10) and remediation approaches.
- Strong communication and collaboration skills with the ability to engage cross-functional teams.
- Familiarity with containerization tools (e.g., Docker, Kubernetes).
- Knowledge of security standards (e.g., NIST, ISO 27001, CIS).
Preferred qualifications
- 5+ years of experience in security engineering, software engineering, or platform engineering.
- Proven track record owning security capabilities or programs at scale.
- Deep expertise across multiple security domains (AppSec, CloudSec, CI/CD security, architecture).
- Advanced proficiency in security automation, tooling strategy, and infrastructure-as-code security, including experience integrating AI-based tools into automated pipelines.
- Demonstrated technical leadership and ability to influence cross-team decisions without formal authority.
- Experience leading security incident response and root-cause analysis.
- Track record mentoring engineers and emerging security leads.
- Experience influencing engineering-wide security standards and practices, including guidance on the responsible use of AI tools (e.g., secure use of AI coding assistants, AI/LLM application security).
- Relevant advanced certifications (e.g., CISSP, CCSK, or equivalent).
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
