Lead / Associate Lead Security Engineer
Ifs- Location
- Colombo, Western Province, Sri Lanka
- Workplace
- —
- Employment
- Full Time
- Salary
- —
Posted 1mo ago
We are seeking a motivated and detail-oriented Lead / Associate Lead Security Engineer to join our Cyber Security team in Colombo, Sri Lanka.
As a Lead / Associate Lead Security Engineer,
you will provide technical leadership for security engineering across the organisation. You will set technical direction, own critical security capabilities, drive cross-team security initiatives, and mentor engineers at all levels. You are accountable for the maturity and effectiveness of security engineering, balancing risk, delivery, and engineering realities.
This is a technical leadership role, not a people-management role—though it carries significant influence and mentorship responsibility.
Duties and Accountabilities
Technical Strategy & Ownership
- Define and drive the technical direction for security engineering
- Own critical security domains and capabilities end-to-end (AppSec, CloudSec, CI/CD security, vulnerability management)
- Set standards, patterns, and guardrails that scale across teams
- Make and own high-impact, risk-based security decisions
Cross-Team Leadership
- Lead security initiatives spanning multiple engineering teams
- Act as the senior security point of contact for engineering leadership
- Influence architecture and design across the organization
- Align security efforts with business and delivery priorities
Engineering & Automation
- Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security)
- Improve signal quality, coverage, and developer experience
- Ensure security platforms are reliable, scalable, and maintainable
Risk, Incident & Compliance
- Lead response and root-cause analysis for significant security incidents
- Identify systemic risks and drive long-term remediation
- Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP)
- Coordinate external engagements (e.g. penetration testing vendors)
Mentorship & Capability Building
- Mentor engineers and emerging leads (including Associate Security Leads)
- Raise the overall security capability of engineering teams
- Champion a strong, pragmatic security culture
What Success Looks Like
- Security engineering direction is clear, pragmatic, and adopted
- Critical risks are proactively identified and addressed
- Engineering teams trust and act on security guidance
- Security maturity improves measurably across the org
- Engineers grow under your mentorship
Required Skills & Experience
- Typically 5+ years in security engineering, software engineering, or platform engineering
- Proven track record owning security capabilities or programmes at scale
- Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, Architecture)
- Strong hands-on engineering and automation background
- Demonstrated technical leadership and cross-team influence
Scope & Expectations
- Technical leadership role, accountable for security engineering outcomes
- Owns strategy and direction, not just delivery
- Expected to influence without formal authority
- Expected to challenge unsafe designs and decisions
- Not a people-manager role (unless explicitly combined)
Nice to Have
- Experience leading security in an enterprise product environment
- Track record influencing engineering-wide standards
- Experience mentoring senior engineers and leads
- Relevant advanced certifications (not mandatory)
Core Required Qualifications
- Demonstrated experience in security engineering with hands-on involvement in automated security solutions.
- Working knowledge of DevSecOps principles and practices.
- Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions, or equivalent).
- Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash).
- Solid understanding of common vulnerabilities (e.g., OWASP Top Ten) and remediation approaches.
- Strong communication and collaboration skills with ability to engage cross-functional teams.
- Familiarity with containerisation tools (e.g., Docker, Kubernetes).
- Knowledge of security standards (e.g., NIST, ISO 27001, CIS).
Preferred Qualifications
- 5+ years of experience in security engineering, software engineering, or platform engineering.
- Proven track record owning security capabilities or programmes at scale.
- Deep expertise across multiple security domains (AppSec, CloudSec, CI/CD security, Architecture).
- Advanced proficiency in security automation, tooling strategy, and infrastructure-as-code security.
- Demonstrated technical leadership and ability to influence cross-team decisions without formal authority.
- Experience leading security incident response and root-cause analysis.
- Track record mentoring engineers and emerging security leads.
- Experience influencing engineering-wide security standards and practices.
- Relevant advanced certifications (e.g., CISSP, CCSK, or equivalent).
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.
Skills
- SAST
- SCA
- DAST
- ISO 27001
- SOC 2
- FedRAMP
- Bitbucket
- Jenkins
- GitLab
- GitHub Actions
- Python
- Bash
- OWASP
- Docker
- Kubernetes
- NIST
- CISSP
More jobs at Ifs
All 150Principal Product Designer, AI Experiences
Ifs · Itasca, Illinois, United States · today
Senior Software Engineer, AI Agents
Ifs · Düsseldorf, North Rhine-Westphalia, Germany · today
Senior Software Engineer, AI Agents
Ifs · Krakow, Lesser Poland, Poland · today
Senior Software Engineer, AI Agents
Ifs · Madrid, Madrid, Spain · today
Senior Software Engineer, AI Agents
Ifs · Staines-upon-Thames, England, United Kingdom · today
Similar roles
Software Engineer (React / .NET)
Ifs · Colombo, Western Province, Sri Lanka · 3d ago
DevSecOps Engineer (IGT1)
Ifs · Port City, Western Province, Sri Lanka · 8d ago
Applied AI Engineer - IFS Loops
Ifs · Colombo, Western Province, Sri Lanka · 14d ago
Associate Lead - Quality Assurance Engineer
Acumatica · Colombo, WP, Sri Lanka · 18d ago
Application Support Consultant - L1 Finance
Acumatica · Colombo, WP, Sri Lanka · 18d ago
Application Support Consultant - L1 (Platform)
Acumatica · Colombo, WP, Sri Lanka · 18d ago