Lead / Associate Lead Security Engineer
- Full-time
Company Description
IFS is a billion-dollar revenue company with 7000+ employees on all continents. Our leading AI technology is the backbone of our award-winning enterprise software solutions, enabling our customers to be their best when it really matters–at the Moment of Service™. Our commitment to internal AI adoption has allowed us to stay at the forefront of technological advancements, ensuring our colleagues can unlock their creativity and productivity, and our solutions are always cutting-edge.
At IFS, we’re flexible, we’re innovative, and we’re focused not only on how we can engage with our customers but on how we can make a real change and have a worldwide impact. We help solve some of society’s greatest challenges, fostering a better future through our agility, collaboration, and trust.
We celebrate diversity and understand our responsibility to reflect the diverse world we work in. We are committed to promoting an inclusive workforce that fully represents the many different cultures, backgrounds, and viewpoints of our customers, our partners, and our communities. As a truly international company serving people from around the globe, we realize that our success is tantamount to the respect we have for those different points of view.
By joining our team, you will have the opportunity to be part of a global, diverse environment; you will be joining a winning team with a commitment to sustainability; and a company where we get things done so that you can make a positive impact on the world.
We’re looking for innovative and original thinkers to work in an environment where you can #MakeYourMoment so that we can help others make theirs. With the power of our AI-driven solutions, we empower our team to change the status quo and make a real difference.
If you want to change the status quo, we’ll help you make your moment. Join Team Purple. Join IFS
Job Description
We are seeking a motivated and detail-oriented Lead / Associate Lead Security Engineer to join our Cyber Security team in Colombo, Sri Lanka.
As a Lead / Associate Lead Security Engineer,
you will provide technical leadership for security engineering across the organisation. You will set technical direction, own critical security capabilities, drive cross-team security initiatives, and mentor engineers at all levels. You are accountable for the maturity and effectiveness of security engineering, balancing risk, delivery, and engineering realities.
This is a technical leadership role, not a people-management role—though it carries significant influence and mentorship responsibility.
Duties and Accountabilities
Technical Strategy & Ownership
Define and drive the technical direction for security engineering
Own critical security domains and capabilities end-to-end (AppSec, CloudSec, CI/CD security, vulnerability management)
Set standards, patterns, and guardrails that scale across teams
Make and own high-impact, risk-based security decisions
Cross-Team Leadership
Lead security initiatives spanning multiple engineering teams
Act as the senior security point of contact for engineering leadership
Influence architecture and design across the organization
Align security efforts with business and delivery priorities
Engineering & Automation
Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security)
Improve signal quality, coverage, and developer experience
Ensure security platforms are reliable, scalable, and maintainable
Risk, Incident & Compliance
Lead response and root-cause analysis for significant security incidents
Identify systemic risks and drive long-term remediation
Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP)
Coordinate external engagements (e.g. penetration testing vendors)
Mentorship & Capability Building
Mentor engineers and emerging leads (including Associate Security Leads)
Raise the overall security capability of engineering teams
Champion a strong, pragmatic security culture
What Success Looks Like
Security engineering direction is clear, pragmatic, and adopted
Critical risks are proactively identified and addressed
Engineering teams trust and act on security guidance
Security maturity improves measurably across the org
Engineers grow under your mentorship
Required Skills & Experience
Typically 5+ years in security engineering, software engineering, or platform engineering
Proven track record owning security capabilities or programmes at scale
Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, Architecture)
Strong hands-on engineering and automation background
Demonstrated technical leadership and cross-team influence
Scope & Expectations
Technical leadership role, accountable for security engineering outcomes
Owns strategy and direction, not just delivery
Expected to influence without formal authority
Expected to challenge unsafe designs and decisions
Not a people-manager role (unless explicitly combined)
Nice to Have
Experience leading security in an enterprise product environment
Track record influencing engineering-wide standards
Experience mentoring senior engineers and leads
Relevant advanced certifications (not mandatory)
Qualifications
Core Required Qualifications
- Demonstrated experience in security engineering with hands-on involvement in automated security solutions.
- Working knowledge of DevSecOps principles and practices.
- Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions, or equivalent).
- Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash).
- Solid understanding of common vulnerabilities (e.g., OWASP Top Ten) and remediation approaches.
- Strong communication and collaboration skills with ability to engage cross-functional teams.
- Familiarity with containerisation tools (e.g., Docker, Kubernetes).
- Knowledge of security standards (e.g., NIST, ISO 27001, CIS).
Preferred Qualifications
- 5+ years of experience in security engineering, software engineering, or platform engineering.
- Proven track record owning security capabilities or programmes at scale.
- Deep expertise across multiple security domains (AppSec, CloudSec, CI/CD security, Architecture).
- Advanced proficiency in security automation, tooling strategy, and infrastructure-as-code security.
- Demonstrated technical leadership and ability to influence cross-team decisions without formal authority.
- Experience leading security incident response and root-cause analysis.
- Track record mentoring engineers and emerging security leads.
- Experience influencing engineering-wide security standards and practices.
- Relevant advanced certifications (e.g., CISSP, CCSK, or equivalent).
Additional Information
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply