Cyber Security Manager – Offensive Security & Threat Management
Nations Trust Bank PLC · Colombo
Job description
About the role
We are looking for a senior cybersecurity leader to head the bank’s Offensive Security, Threat Management and Security Validation functions. The role demands an attacker mindset, hands‑on penetration‑testing expertise and the ability to protect digital banking services across applications, infrastructure and cloud environments.
Key responsibilities
- Lead the bank’s offensive security, threat management and security validation initiatives.
- Design, execute and oversee advanced penetration testing, red‑team operations, adversary emulation, threat hunting and attack‑path analysis.
- Identify exploitable vulnerabilities in web applications, APIs, mobile apps, cloud platforms, Active Directory, databases and network infrastructure.
- Simulate real‑world attack scenarios to assess the effectiveness of controls such as WAF, EDR/XDR, NDR, SIEM, PAM, DLP, MFA and Zero‑Trust solutions.
- Drive vulnerability‑management programs, ensuring timely remediation and validation of fixes.
- Lead cyber‑incident investigations, digital forensics, threat‑intelligence analysis and post‑breach assessments.
- Perform continuous attack‑surface management and monitor emerging threats to banking services and digital channels.
- Establish offensive‑security standards, methodologies and testing frameworks aligned with industry best practices.
- Collaborate with development, infrastructure, cloud and application teams to embed security throughout the technology lifecycle.
- Support regulatory compliance initiatives including ISO 27001, PCI‑DSS, SWIFT CSCF and local cybersecurity requirements.
Required profile
- Minimum 7 years of experience in cybersecurity and information security, with at least 3 years in a leadership or managerial role.
- At least 4 years of hands‑on experience in offensive security, red‑team operations, threat hunting, penetration testing or incident response.
- Proven track record of conducting web‑application, API, mobile, cloud and network security assessments.
- Strong analytical, reporting and stakeholder‑management abilities.
Required skills
- Penetration testing and red‑team methodologies.
- Threat hunting and incident response.
- Vulnerability management and attack‑path analysis.
- MITRE ATT&CK framework knowledge.
- Tools: Burp Suite, Nmap, Metasploit, Nessus, Cobalt Strike, BloodHound, Kali Linux, OWASP ZAP, cloud security assessment tools.
- Security controls: WAF, EDR/XDR, NDR, SIEM, PAM, DLP, MFA, Zero‑Trust architectures.
- Active Directory, Kerberos, IAM, PAM and Zero‑Trust concepts.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Sri Lanka.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 3 weeks from now
15 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Nations Trust Bank PLC
Colombo