About the job Engineer - IT Security
WE ARE HIRING: Engineer – IT Security
Location: Colombo, Sri Lanka
Employment Type: Full-Time
Work Arrangement: Onsite
Industry: Banking & Financial Services
About the Role
Our client is seeking a skilled and security-focused Engineer – IT Security to join its IT Security & Compliance function. The role is responsible for strengthening application security, conducting vulnerability assessments, supporting secure software development practices, and ensuring security compliance across applications, APIs, and infrastructure.
The ideal candidate will possess hands-on experience in application security testing, vulnerability management, and DevSecOps practices, with a strong understanding of modern cybersecurity threats and mitigation strategies.
Key Responsibilities
- Conduct web and mobile application security testing using SAST and DAST methodologies.
- Perform Vulnerability Assessment and Penetration Testing (VAPT) on applications, APIs, and supporting infrastructure.
- Execute security testing within CI/CD pipelines to ensure automated vulnerability scanning and compliance validation.
- Conduct security reviews of applications, APIs, and integrations to ensure adherence to security standards and regulatory requirements.
- Coordinate vulnerability management activities, including risk assessment, prioritization, remediation tracking, and validation.
- Work closely with development and infrastructure teams to implement secure coding and DevSecOps best practices.
- Monitor emerging cybersecurity vulnerabilities, threats, and security advisories relevant to applications and infrastructure.
- Prepare technical reports and executive summaries highlighting identified risks, vulnerabilities, and recommended mitigation measures.
- Support continuous improvement initiatives related to application security and compliance.
- Provide security guidance throughout the software development lifecycle.
Requirements
- Bachelor's Degree in Information Security, Cybersecurity, Computer Science, or a related field.
- 2-3 years of experience in application security testing, VAPT, and vulnerability management.
- Hands-on experience with SAST and DAST tools such as Checkmarx, Burp Suite, OWASP ZAP, Fortify, or similar solutions.
- Experience with network and infrastructure security technologies, including Firewalls, Web Application Firewalls (WAF), SIEM platforms, and vulnerability scanners.
- Exposure to CI/CD security testing using Jenkins, GitLab CI, Azure DevOps, GitHub Actions, or similar platforms.
- Strong knowledge of OWASP Top 10, secure coding principles, and application threat modeling.
- Professional certifications such as CEH, OSCP, Security+, GWAPT, or eJPT will be an added advantage.
- Knowledge of scripting and automation using Python, PowerShell, or Bash will be considered a plus.
- Strong analytical, problem-solving, and investigative skills.
- Excellent communication and collaboration abilities.
- High attention to detail and a proactive approach to security.
Ready to take your career to new heights?
We're InTalent Asia, your go-to recruitment partner in Sri Lanka, and we've got an exciting opportunity for you!
Our client is looking for a skilled individual to fill the role of Engineer – IT Security.
Apply now and see how you can be the perfect fit for this exclusive position!
#InTalentAsia #CareerOpportunity #JobVacancy #ITSecurityEngineer #CyberSecurity #InformationSecurity #VAPT #ApplicationSecurity #DevSecOps #OWASP #VulnerabilityManagement #PenetrationTesting #SecureCoding #BankingTechnology #CareerGrowth #ElevateYourCareer