Skip to content
← Back to job listings

Lead / Associate Lead Security Engineer

IFS · Colombo, Western Province, Sri Lanka

CybersecurityLeadQuick applyfull-time3 days ago

About The Role

We are seeking a motivated and detail-oriented Lead / Associate Lead Security Engineer to join our Cyber Security team in Colombo, Sri Lanka.

As a Lead / Associate Lead Security Engineer ,

you will provide technical leadership for security engineering across the organisation. You will set technical direction, own critical security capabilities, drive cross-team security initiatives, and mentor engineers at all levels. You are accountable for the maturity and effectiveness of security engineering , balancing risk, delivery, and engineering realities.

This is a technical leadership role , not a people-management role—though it carries significant influence and mentorship responsibility.

Duties and Accountabilities

Technical Strategy & Ownership

  • Define and drive the technical direction for security engineering
  • Own critical security domains and capabilities end-to-end (AppSec, CloudSec, CI/CD security, vulnerability management)
  • Set standards, patterns, and guardrails that scale across teams
  • Make and own high-impact, risk-based security decisions

Cross-Team Leadership

  • Lead security initiatives spanning multiple engineering teams
  • Act as the senior security point of contact for engineering leadership
  • Influence architecture and design across the organization
  • Align security efforts with business and delivery priorities

Engineering & Automation

  • Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security)
  • Improve signal quality, coverage, and developer experience
  • Ensure security platforms are reliable, scalable, and maintainable

Risk, Incident & Compliance

  • Lead response and root-cause analysis for significant security incidents
  • Identify systemic risks and drive long-term remediation
  • Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP)
  • Coordinate external engagements (e.g. penetration testing vendors)

Mentorship & Capability Building

  • Mentor engineers and emerging leads (including Associate Security Leads)
  • Raise the overall security capability of engineering teams
  • Champion a strong, pragmatic security culture

What Success Looks Like

  • Security engineering direction is clear, pragmatic, and adopted
  • Critical risks are proactively identified and addressed
  • Engineering teams trust and act on security guidance
  • Security maturity improves measurably across the org
  • Engineers grow under your mentorship

Required Skills & Experience

  • Typically 5+ years in security engineering, software engineering, or platform engineering
  • Proven track record owning security capabilities or programmes at scale
  • Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, Architecture)
  • Strong hands-on engineering and automation background
  • Demonstrated technical leadership and cross-team influence

Scope & Expectations

  • Technical leadership role , accountable for security engineering outcomes
  • Owns strategy and direction , not just delivery
  • Expected to influence without formal authority
  • Expected to challenge unsafe designs and decisions
  • Not a people-manager role (unless explicitly combined)

Nice to Have

  • Experience leading security in an enterprise product environment
  • Track record influencing engineering-wide standards
  • Experience mentoring senior engineers and leads
  • Relevant advanced certifications (not mandatory)

 

Core Required Qualifications 

  • Demonstrated experience in security engineering with hands-on involvement in automated security solutions.
  • Working knowledge of DevSecOps principles and practices.
  • Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions, or equivalent).
  • Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash).
  • Solid understanding of common vulnerabilities (e.g., OWASP Top Ten) and remediation approaches.
  • Strong communication and collaboration skills with ability to engage cross-functional teams.
  • Familiarity with containerisation tools (e.g., Docker, Kubernetes).
  • Knowledge of security standards (e.g., NIST, ISO 27001, CIS).

Preferred Qualifications 

  • 5+ years of experience in security engineering, software engineering, or platform engineering.
  • Proven track record owning security capabilities or programmes at scale.
  • Deep expertise across multiple security domains (AppSec, CloudSec, CI/CD security, Architecture).
  • Advanced proficiency in security automation, tooling strategy, and infrastructure-as-code security.
  • Demonstrated technical leadership and ability to influence cross-team decisions without formal authority.
  • Experience leading security incident response and root-cause analysis.
  • Track record mentoring engineers and emerging security leads.
  • Experience influencing engineering-wide security standards and practices.
  • Relevant advanced certifications (e.g., CISSP, CCSK, or equivalent).

We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.

This listing was posted by a verified recruiter at IFS. Report this listing