Lead / Associate Lead Security Engineer

We are seeking a motivated and detail-oriented Lead / Associate Lead Security Engineer to join our Cyber Security team in Colombo, Sri Lanka.

As a Lead / Associate Lead Security Engineer,

you will provide technical leadership for security engineering across the organisation. You will set technical direction, own critical security capabilities, drive cross-team security initiatives, and mentor engineers at all levels. You are accountable for the maturity and effectiveness of security engineering, balancing risk, delivery, and engineering realities.

This is a technical leadership role, not a people-management role—though it carries significant influence and mentorship responsibility.

Duties and Accountabilities

Technical Strategy & Ownership

  • Define and drive the technical direction for security engineering

  • Own critical security domains and capabilities end-to-end (AppSec, CloudSec, CI/CD security, vulnerability management)

  • Set standards, patterns, and guardrails that scale across teams

  • Make and own high-impact, risk-based security decisions

Cross-Team Leadership

  • Lead security initiatives spanning multiple engineering teams

  • Act as the senior security point of contact for engineering leadership

  • Influence architecture and design across the organization

  • Align security efforts with business and delivery priorities

Engineering & Automation

  • Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security)

  • Improve signal quality, coverage, and developer experience

  • Ensure security platforms are reliable, scalable, and maintainable

Risk, Incident & Compliance

  • Lead response and root-cause analysis for significant security incidents

  • Identify systemic risks and drive long-term remediation

  • Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP)

  • Coordinate external engagements (e.g. penetration testing vendors)

Mentorship & Capability Building

  • Mentor engineers and emerging leads (including Associate Security Leads)

  • Raise the overall security capability of engineering teams

  • Champion a strong, pragmatic security culture

What Success Looks Like

  • Security engineering direction is clear, pragmatic, and adopted

  • Critical risks are proactively identified and addressed

  • Engineering teams trust and act on security guidance

  • Security maturity improves measurably across the org

  • Engineers grow under your mentorship

Required Skills & Experience

  • Typically 5+ years in security engineering, software engineering, or platform engineering

  • Proven track record owning security capabilities or programmes at scale

  • Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, Architecture)

  • Strong hands-on engineering and automation background

  • Demonstrated technical leadership and cross-team influence

Scope & Expectations

  • Technical leadership role, accountable for security engineering outcomes

  • Owns strategy and direction, not just delivery

  • Expected to influence without formal authority

  • Expected to challenge unsafe designs and decisions

  • Not a people-manager role (unless explicitly combined)

Nice to Have

  • Experience leading security in an enterprise product environment

  • Track record influencing engineering-wide standards

  • Experience mentoring senior engineers and leads

  • Relevant advanced certifications (not mandatory)

Core Required Qualifications

  • Demonstrated experience in security engineering with hands-on involvement in automated security solutions.
  • Working knowledge of DevSecOps principles and practices.
  • Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions, or equivalent).
  • Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash).
  • Solid understanding of common vulnerabilities (e.g., OWASP Top Ten) and remediation approaches.
  • Strong communication and collaboration skills with ability to engage cross-functional teams.
  • Familiarity with containerisation tools (e.g., Docker, Kubernetes).
  • Knowledge of security standards (e.g., NIST, ISO 27001, CIS).

Preferred Qualifications

  • 5+ years of experience in security engineering, software engineering, or platform engineering.
  • Proven track record owning security capabilities or programmes at scale.
  • Deep expertise across multiple security domains (AppSec, CloudSec, CI/CD security, Architecture).
  • Advanced proficiency in security automation, tooling strategy, and infrastructure-as-code security.
  • Demonstrated technical leadership and ability to influence cross-team decisions without formal authority.
  • Experience leading security incident response and root-cause analysis.
  • Track record mentoring engineers and emerging security leads.
  • Experience influencing engineering-wide security standards and practices.
  • Relevant advanced certifications (e.g., CISSP, CCSK, or equivalent).

We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available