Cyber Security Engineer – Enterprise Security & Risk Management
Talent Studio · Colombo
Job description
About the role
Our client is looking for a Cyber Security Engineer to strengthen the enterprise security infrastructure and manage IT risk. The role involves implementing security frameworks, protecting network and endpoint assets, and responding to incidents in a fast‑paced technology environment.
Key responsibilities
- Execute and maintain enterprise information security and IT risk management programs aligned with ISO 27001 and CIS frameworks.
- Manage IT networks, servers, user identities, and endpoint devices to ensure optimum security levels.
- Implement and manage security infrastructure including firewalls and Secure Access Service Edge (SASE) solutions.
- Conduct vulnerability assessments and penetration testing of applications and perimeter systems using tools such as OWASP ZAP.
- Support DevSecOps processes and ensure secure configuration of all IT assets.
- Monitor and analyze IT security threats in real‑time and implement mitigation measures.
- Ensure newly acquired technologies comply with IT security regulations and organizational standards.
- Conduct regular vulnerability assessments on online resources and provide periodic IT security updates to the board audit committee.
- Manage information security incidents including investigation, recovery, and preventive actions.
- Participate in architecture and security discussions by providing recommendations on risk, security, and compliance concerns.
- Attend training sessions to expand expertise in advanced and emerging cybersecurity areas.
- Assist in preparing cybersecurity awareness and training materials for employees.
- Provide updates to Compliance Steering Committees and complete assigned action items to avoid non‑conformities.
Required profile
- Bachelor’s degree with specialization in Information Technology or related field.
- 1–3 years of experience in a similar cybersecurity role.
- Hands‑on experience in conducting or supporting application security penetration testing.
- Professional certifications from ISACA, (ISC)², or GIAC (advantage).
- Strong understanding of security controls, cybersecurity frameworks, network security controls, operating systems, and incident response management.
- Excellent planning, organizational, and analytical skills.
- Strong attention to detail and quality‑focused mindset.
Required skills
- ISO 27001 framework
- CIS security frameworks
- Firewalls
- Secure Access Service Edge (SASE) solutions
- OWASP ZAP
- Vulnerability assessment tools
- Penetration testing
- DevSecOps processes
- Network security controls
- Operating systems security
- Incident response management
- Security controls implementation
What we offer
- Opportunity to work in a dynamic and security‑focused technology environment.
- Exposure to enterprise cybersecurity operations and compliance practices.
- Career growth opportunities in cybersecurity, DevSecOps, and information security governance.
- Continuous learning and professional development opportunities.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Sri Lanka.
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 day ago
Expires 1 month from now
8 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Talent Studio
Colombo