About the job Senior Engineer - IT Security
WE ARE HIRING: Senior Security Operations Engineer
Location: Colombo, Sri Lanka
Employment Type: Full Time
Industry: Banking & Financial Services
Role Overview
We are seeking a highly skilled and proactive Senior Security Operations Engineer to join a leading cybersecurity and IT Security & Compliance function. The successful candidate will be responsible for strengthening security monitoring, threat detection, incident response, security automation, and advanced threat hunting capabilities while supporting the organization's cyber resilience strategy. This role requires a cybersecurity professional with strong expertise in SIEM, XDR, SOAR, detection engineering, threat intelligence, incident response, and security operations. The ideal candidate will play a key role in designing advanced detection capabilities, enhancing security automation, and supporting the continuous evolution of enterprise cyber defense mechanisms.
Key Responsibilities
Security Operations & Detection Engineering
- Lead the design, development, and maintenance of advanced security detection and response frameworks across enterprise environments.
- Develop, tune, and optimize advanced SIEM and XDR detection logic to identify sophisticated cyber threats and attacker tactics.
- Create custom correlation rules, use cases, analytics, and detection mechanisms beyond traditional signature-based techniques.
- Continuously improve security visibility by enhancing detection coverage across the enterprise threat landscape.
- Ensure security monitoring solutions remain effective, scalable, and aligned with emerging threats.
Security Automation & SOAR Engineering
- Serve as the lead architect for security automation initiatives across the Security Operations ecosystem.
- Design and implement end-to-end SOAR playbooks and orchestration workflows to automate security response activities.
- Reduce Mean Time to Respond (MTTR) through automated investigation, enrichment, triage, and response processes.
- Integrate security technologies and tools to streamline operational efficiency across the SOC environment.
- Develop custom scripts and automation solutions to eliminate repetitive manual security tasks.
Threat Hunting & Incident Response
- Lead proactive, hypothesis-based threat hunting exercises to identify malicious activity that may evade traditional detection methods.
- Conduct deep-dive forensic investigations and root cause analysis for significant security incidents.
- Act as the senior technical escalation point for critical cybersecurity incidents.
- Identify attacker behaviours, techniques, and indicators of compromise across enterprise environments.
- Develop advanced defensive capabilities based on threat intelligence and investigation findings.
Purple Teaming & Security Improvement
- Collaborate closely with Red Teams to execute Purple Teaming exercises.
- Translate offensive security findings into practical defensive detections and automated controls.
- Validate and enhance monitoring capabilities against evolving adversary tactics and threat scenarios.
- Support continuous improvement initiatives that strengthen organizational cyber defense capabilities.
Platform Management & Optimization
- Oversee onboarding, normalization, and integration of new log sources into security monitoring systems.
- Ensure optimal performance and effectiveness of SIEM, SOAR, XDR, and EDR platforms.
- Monitor security platform health and recommend enhancements to improve operational effectiveness.
- Support log management, data quality, and security telemetry optimization initiatives.
Governance, Reporting & Stakeholder Engagement
- Prepare detailed technical documentation, operational procedures, and security reports.
- Lead post-incident reviews and "lessons learned" sessions to improve detection and response capabilities.
- Translate technical security findings into business risks and actionable recommendations for management.
- Work closely with infrastructure, application, and business teams to drive security control implementation and remediation activities.
- Provide technical guidance and mentoring to SOC analysts and security team members.
Candidate Profile
- Bachelor's Degree in Information Technology, Computer Science, Cybersecurity, or a related discipline.
- Minimum 3–5 years of experience in Information Security.
- At least 3 years of experience in advanced SIEM/XDR administration, Detection Engineering, Threat Hunting, or SOC Tier 2/Tier 3 operations.
- Strong expertise in designing, implementing, and optimizing SIEM, XDR, SOAR, and EDR platforms.
- Proven experience developing custom detection logic, advanced analytics, and correlation rules.
- Hands-on experience with security automation, orchestration, and response engineering.
- Advanced proficiency in Python, PowerShell, Bash, or similar scripting languages.
- Strong understanding of Windows and Linux operating environments.
- Strong knowledge of network and application protocols including TCP/IP, HTTP, HTTPS, TLS, SSH, DNS, and related technologies.
- Deep understanding of the MITRE ATT&CK Framework and MITRE D3FEND methodologies.
- Experience with digital forensics, incident response, threat hunting, and vulnerability management.
- Strong analytical skills and ability to solve complex cybersecurity challenges under pressure.
- Excellent communication skills with the ability to present technical concepts to both technical and non-technical stakeholders.
- Strong stakeholder management and collaboration capabilities.
Professional Certifications
- CEH (Certified Ethical Hacker)
- CHFI (Computer Hacking Forensic Investigator)
- CySA+
- CSXP
- SSCP
- Other relevant cybersecurity certifications will be considered an advantage.
Ready to take your career to new heights?
We're InTalent Asia, your go-to recruitment partner in Sri Lanka, and we've got an exciting opportunity for you!
Our client is looking for a skilled individual to fill the role of Senior Security Operations Engineer.
Apply now and see how you can be the perfect fit for this exclusive position!
#InTalentAsia #CareerOpportunity #JobVacancy #CyberSecurity #SecurityOperations #SIEM #SOAR #ThreatHunting #DetectionEngineering #IncidentResponse #InformationSecurity #CareerGrowth