Senior Information Security Engineer
ZinCaT Technology · Colombo
Job description
About the role
The Senior Information Security Engineer leads advanced threat detection, investigation and major cyber‑incident response for a fast‑growing global SaaS business. Reporting to the SOC Manager, the role combines hands‑on operational work with ownership of SOC transformation, automation and analyst enablement.
Key responsibilities
- Lead end‑to‑end response for high‑priority cyber incidents, acting as senior technical authority from triage through containment, eradication and post‑incident review.
- Perform deep‑dive forensic, malware and log investigations, applying hypothesis‑driven analysis to uncover hidden threats.
- Design and deliver SOC maturity initiatives, including detection engineering, use‑case development, workflow automation and tooling consolidation.
- Build, tune and continuously improve SIEM detection logic and correlation rules (preferably Microsoft Sentinel) to reduce false positives.
- Conduct intelligence‑led threat hunts using MITRE ATT&CK and emerging TTPs, identifying gaps before exploitation.
- Champion automation, SOAR playbooks and AI‑assisted tooling to increase analyst efficiency.
- Mentor Tier 1/2 analysts, coaching investigative techniques and fostering a culture of curiosity.
- Maintain expertise across SOC tooling (SIEM, EDR, SOAR, cloud security) and contribute to tooling strategy and budget planning.
Required profile
- 5+ years experience in a Security Operations Center or cyber‑defense function within a fast‑growth organization.
- Proven track record of building SOC capability and delivering transformation programs (detection engineering, automation, process redesign).
- Hands‑on experience leading major cyber‑incident responses and producing executive‑level post‑incident reports.
- Strong analytical mindset with demonstrated curiosity for root‑cause analysis and emerging threat techniques.
- Excellent written and verbal communication skills, able to brief technical and executive stakeholders during live incidents.
Required skills
- Microsoft Sentinel (SIEM)
- Microsoft Defender for Endpoint (EDR)
- SOAR platforms and playbook development
- KQL query language
- Python scripting
- MITRE ATT&CK framework
- Cloud security (Azure and AWS)
- Automation and AI‑enabled detection tools
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Sri Lanka.
Salary: Senior DevOps Engineer Based on 10 job offers in Sri LankaApply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 4 hours ago
Expires 1 month from now
3 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
ZinCaT Technology
Colombo