freehire launches on Product Hunt on 26 August.

Follow →

Lead / Associate Lead Security Engineer

Open 19d

Summary

Leads the security engineering team in Colombo, setting technical direction for AppSec, CloudSec, CI/CD security, and vulnerability management while mentoring engineers and driving automation.

We are seeking a motivated and detail-oriented Lead / Associate Lead Security Engineer to join our Cyber Security team in Colombo, Sri Lanka.

As a Lead / Associate Lead Security Engineer,

you will provide technical leadership for security engineering across the organisation. You will set technical direction, own critical security capabilities, drive cross-team security initiatives, and mentor engineers at all levels. You are accountable for the maturity and effectiveness of security engineering, balancing risk, delivery, and engineering realities.

This is a technical leadership role, not a people-management role—though it carries significant influence and mentorship responsibility.

Duties and Accountabilities

Technical Strategy & Ownership

  • Define and drive the technical direction for security engineering

  • Own critical security domains and capabilities end-to-end (AppSec, CloudSec, CI/CD security, vulnerability management)

  • Set standards, patterns, and guardrails that scale across teams

  • Make and own high-impact, risk-based security decisions

Cross-Team Leadership

  • Lead security initiatives spanning multiple engineering teams

  • Act as the senior security point of contact for engineering leadership

  • Influence architecture and design across the organization

  • Align security efforts with business and delivery priorities

Engineering & Automation

  • Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security)

  • Improve signal quality, coverage, and developer experience

  • Ensure security platforms are reliable, scalable, and maintainable

Risk, Incident & Compliance

  • Lead response and root-cause analysis for significant security incidents

  • Identify systemic risks and drive long-term remediation

  • Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP)

  • Coordinate external engagements (e.g. penetration testing vendors)

Mentorship & Capability Building

  • Mentor engineers and emerging leads (including Associate Security Leads)

  • Raise the overall security capability of engineering teams

  • Champion a strong, pragmatic security culture

What Success Looks Like

  • Security engineering direction is clear, pragmatic, and adopted

  • Critical risks are proactively identified and addressed

  • Engineering teams trust and act on security guidance

  • Security maturity improves measurably across the org

  • Engineers grow under your mentorship

Required Skills & Experience

  • Typically 5+ years in security engineering, software engineering, or platform engineering

  • Proven track record owning security capabilities or programmes at scale

  • Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, Architecture)

  • Strong hands-on engineering and automation background

  • Demonstrated technical leadership and cross-team influence

Scope & Expectations

  • Technical leadership role, accountable for security engineering outcomes

  • Owns strategy and direction, not just delivery

  • Expected to influence without formal authority

  • Expected to challenge unsafe designs and decisions

  • Not a people-manager role (unless explicitly combined)

Nice to Have

  • Experience leading security in an enterprise product environment

  • Track record influencing engineering-wide standards

  • Experience mentoring senior engineers and leads

  • Relevant advanced certifications (not mandatory)

Core Required Qualifications

  • Demonstrated experience in security engineering with hands-on involvement in automated security solutions.
  • Working knowledge of DevSecOps principles and practices.
  • Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions, or equivalent).
  • Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash).
  • Solid understanding of common vulnerabilities (e.g., OWASP Top Ten) and remediation approaches.
  • Strong communication and collaboration skills with ability to engage cross-functional teams.
  • Familiarity with containerisation tools (e.g., Docker, Kubernetes).
  • Knowledge of security standards (e.g., NIST, ISO 27001, CIS).

Preferred Qualifications

  • 5+ years of experience in security engineering, software engineering, or platform engineering.
  • Proven track record owning security capabilities or programmes at scale.
  • Deep expertise across multiple security domains (AppSec, CloudSec, CI/CD security, Architecture).
  • Advanced proficiency in security automation, tooling strategy, and infrastructure-as-code security.
  • Demonstrated technical leadership and ability to influence cross-team decisions without formal authority.
  • Experience leading security incident response and root-cause analysis.
  • Track record mentoring engineers and emerging security leads.
  • Experience influencing engineering-wide security standards and practices.
  • Relevant advanced certifications (e.g., CISSP, CCSK, or equivalent).

We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available