Lead / Associate Lead Security Engineer
IFS · Colombo, Western Province, Sri Lanka
About The Role
We are seeking a motivated and detail-oriented Lead / Associate Lead Security Engineer to join our Cyber Security team in Colombo, Sri Lanka.
As a Lead / Associate Lead Security Engineer ,
you will provide technical leadership for security engineering across the organisation. You will set technical direction, own critical security capabilities, drive cross-team security initiatives, and mentor engineers at all levels. You are accountable for the maturity and effectiveness of security engineering , balancing risk, delivery, and engineering realities.
This is a technical leadership role , not a people-management role—though it carries significant influence and mentorship responsibility.
Duties and Accountabilities
Technical Strategy & Ownership
- Define and drive the technical direction for security engineering
- Own critical security domains and capabilities end-to-end (AppSec, CloudSec, CI/CD security, vulnerability management)
- Set standards, patterns, and guardrails that scale across teams
- Make and own high-impact, risk-based security decisions
Cross-Team Leadership
- Lead security initiatives spanning multiple engineering teams
- Act as the senior security point of contact for engineering leadership
- Influence architecture and design across the organization
- Align security efforts with business and delivery priorities
Engineering & Automation
- Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security)
- Improve signal quality, coverage, and developer experience
- Ensure security platforms are reliable, scalable, and maintainable
Risk, Incident & Compliance
- Lead response and root-cause analysis for significant security incidents
- Identify systemic risks and drive long-term remediation
- Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP)
- Coordinate external engagements (e.g. penetration testing vendors)
Mentorship & Capability Building
- Mentor engineers and emerging leads (including Associate Security Leads)
- Raise the overall security capability of engineering teams
- Champion a strong, pragmatic security culture
What Success Looks Like
- Security engineering direction is clear, pragmatic, and adopted
- Critical risks are proactively identified and addressed
- Engineering teams trust and act on security guidance
- Security maturity improves measurably across the org
- Engineers grow under your mentorship
Required Skills & Experience
- Typically 5+ years in security engineering, software engineering, or platform engineering
- Proven track record owning security capabilities or programmes at scale
- Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, Architecture)
- Strong hands-on engineering and automation background
- Demonstrated technical leadership and cross-team influence
Scope & Expectations
- Technical leadership role , accountable for security engineering outcomes
- Owns strategy and direction , not just delivery
- Expected to influence without formal authority
- Expected to challenge unsafe designs and decisions
- Not a people-manager role (unless explicitly combined)
Nice to Have
- Experience leading security in an enterprise product environment
- Track record influencing engineering-wide standards
- Experience mentoring senior engineers and leads
- Relevant advanced certifications (not mandatory)
 
Core Required Qualifications 
- Demonstrated experience in security engineering with hands-on involvement in automated security solutions.
- Working knowledge of DevSecOps principles and practices.
- Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions, or equivalent).
- Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash).
- Solid understanding of common vulnerabilities (e.g., OWASP Top Ten) and remediation approaches.
- Strong communication and collaboration skills with ability to engage cross-functional teams.
- Familiarity with containerisation tools (e.g., Docker, Kubernetes).
- Knowledge of security standards (e.g., NIST, ISO 27001, CIS).
Preferred Qualifications 
- 5+ years of experience in security engineering, software engineering, or platform engineering.
- Proven track record owning security capabilities or programmes at scale.
- Deep expertise across multiple security domains (AppSec, CloudSec, CI/CD security, Architecture).
- Advanced proficiency in security automation, tooling strategy, and infrastructure-as-code security.
- Demonstrated technical leadership and ability to influence cross-team decisions without formal authority.
- Experience leading security incident response and root-cause analysis.
- Track record mentoring engineers and emerging security leads.
- Experience influencing engineering-wide security standards and practices.
- Relevant advanced certifications (e.g., CISSP, CCSK, or equivalent).
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.
This listing was posted by a verified recruiter at IFS. Report this listing
JobSpring