Career141

Lead Security Analyst

Summary

Colombo,

Sri Lanka

On-Site

LKR

400000

-

700000

Full-time

Category

Other

Share job

Roles & Responsibilities

As a Senior Security Analyst, you will play a key role within the expanding IT Security team, responsible for monitoring networks and endpoints to detect and respond to malicious or anomalous activity. Working closely with the IT Security Manager and broader team, you will lead the design, implementation, and maintenance of security tools, frameworks, and processes to strengthen the organization’s security posture.

You will review and assess security incidents, determining their risk and priority, and act as an escalation point for less experienced analysts.

In addition, you will be actively engaged in the software development lifecycle, advising development teams on secure coding practices and security architecture to ensure all internal tools and applications are built with security-by-design principles.

Mandatory Skill set

  • Microsoft Sentinel (Azure Sentinel)
  • SAST / DAST (Static Application Security Testing / Dynamic Application Security Testing)
  • Code Scanning (Application Security Scanning) / SEC OPS / Secure Dev Practices
  • Penetration Testing
  • Security Standards – ISO
  • IAM (Identity and Access Management) Cloud – Azure
  • OAuth (Open Authorization) / Tokenization /SSD

Key responsibilities & Accountabilities:

  • Design, implement, and maintain security tools and processes to continuously strengthen CLIENT’s IT security posture.

  • Provide expert guidance to development teams on secure coding practices and security architecture throughout the software development lifecycle.

  • Conduct comprehensive security reviews of software prior to release to ensure compliance with CLIENT’s security standards and requirements.

  • Serve as an escalation point for complex security investigations and incident resolutions, providing technical support and direction to junior team members.

  • Develop and maintain Standard Operating Procedures (SOPs), policies, and documentation governing information security practices and protocols.

  • Collaborate with IT teams to review and address findings from vulnerability assessments, penetration tests, and security audits, ensuring timely risk mitigation and remediation.

  • Analyze and assess identified vulnerabilities to determine their potential impact on CLIENT’s systems and infrastructure.

  • Stay current with emerging cybersecurity trends, threats, and technologies, proactively recommending improvements where necessary.

  • Support incident management processes by reviewing reported issues, assessing risk and urgency, and guiding the team toward effective and timely resolution.

Skills & Ability

  • Analytical Thinking: Demonstrates excellent problem-solving skills with the ability to assess complex security challenges and recommend effective solutions.

  • Attention to Detail: Maintains a meticulous approach when analyzing incidents, reviewing vulnerabilities, or assessing risks to ensure accuracy and completeness.

  • Leadership & Mentorship: Acts as a team leader and point of escalation for less experienced analysts, providing guidance, technical direction, and knowledge sharing.

  • Security Detection & Monitoring: Oversees monitoring of systems and networks for malicious or anomalous activity using advanced detection tools and methods.

  • Incident Response: Leads and coordinates the response to security incidents, ensuring timely containment, eradication, and recovery while minimizing business impact.

  • SIEM Proficiency: Demonstrates hands-on expertise in SIEM platforms such as Azure Sentinel, including rule configuration, alert tuning, and incident correlation.

  • Vulnerability Management: Conducts and manages vulnerability assessments, tracks remediation efforts, and collaborates with IT teams to mitigate identified risks.

  • Secure Software Development: Provides security guidance throughout the software development lifecycle (SDLC), promoting secure-by-design principles and best practices.

Pre Requisites

  • 10+ years of experience in the Cybersecurity industry, with a strong background in security operations, monitoring, and risk management.

  • Proficient in Windows and Active Directory administration, including Azure Active Directory.

  • Hands-on experience with Microsoft Office 365 and Azure environments, including security configuration and management.

  • Strong understanding of networking concepts, including TCP/IP and other common network protocols.

  • Experience with Secure Access Service Edge (SASE) solutions — Cato Networks preferred, though not mandatory.

  • Familiarity with established security standards and frameworks (e.g., ISO 27001, NIST, CIS).

  • Microsoft certifications (such as AZ-500, SC-200, or MS-500) are advantageous but not required.

Apply now

Please enable JavaScript in your browser to complete this form.
Click or drag a file to this area to upload.

Hospitality

General Manager

LKR

-

1000000

Sri Lanka

Hospitality

On-Site

November 7, 2025

Other

Senior Security Automation Engineer

LKR

850000

-

Sri Lanka

Other

On-Site

November 7, 2025

Other

Lead Security Analyst

LKR

-

700000

Sri Lanka

Other

On-Site

November 6, 2025

Other

Administrative Coordinator

LKR

65000

-

85000

Sri Lanka

Other

On-Site

November 6, 2025