
Hover or tap a row for full statistics (EUR / month on this chart).
Salary analysis
Compared with the selected benchmark ("Market Average: Security Engineer"), this listing's salary midpoint is about 92% lower. The offer sits below the benchmark range (€6,000–€7,950). The offer's range width is broadly in line with the benchmark. This benchmark is based on 2 comparable listings.
| Market | Lower bound (25th percentile) | Median | Upper bound (75th percentile) |
|---|---|---|---|
| Market Average: Security Engineer | €6,000/per month | €6,875/per month | €7,950/per month |
| Pay in our data — not quoted in ad (Senior) | €500/per month | €573/per month | €646/per month |
We are seeking a motivated and detail-oriented Lead / Associate Lead Security Engineer to join our Cyber Security team in Colombo, Sri Lanka. As a Lead / Associate Lead Security Engineer, you will provide technical leadership for security engineering across the organisation. You will set technical direction, own critical security capabilities, drive cross-team security initiatives, and mentor engineers at all levels. You are accountable for the maturity and effectiveness of security engineering, balancing risk, delivery, and engineering realities. This is a technical leadership role, not a people-management role—though it carries significant influence and mentorship responsibility. Duties and Accountabilities Technical Strategy & Ownership - Define and drive the technical direction for security engineering - Own critical security domains and capabilities end-to-end (AppSec, CloudSec, CI/CD security, vulnerability management) - Set standards, patterns, and guardrails that scale across teams - Make and own high-impact, risk-based security decisions Cross-Team Leadership - Lead security initiatives spanning multiple engineering teams - Act as the senior security point of contact for engineering leadership - Influence architecture and design across the organization - Align security efforts with business and delivery priorities Engineering & Automation - Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security) - Improve signal quality, coverage, and developer experience - Ensure security platforms are reliable, scalable, and maintainable Risk, Incident & Compliance - Lead response and root-cause analysis for significant security incidents - Identify systemic risks and drive long-term remediation - Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP) - Coordinate external engagements (e.g. penetration testing vendors) Mentorship & Capability Building - Mentor engineers and emerging leads (including Associate Security Leads) - Raise the overall security capability of engineering teams - Champion a strong, pragmatic security culture Required Skills & Experience - Typically 5+ years in security engineering, software engineering, or platform engineering - Proven track record owning security capabilities or programmes at scale - Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, Architecture) - Strong hands-on engineering and automation background - Demonstrated technical leadership and cross-team influence Qualifications Core Required Qualifications - Demonstrated experience in security engineering with hands-on involvement in automated security solutions. - Working knowledge of DevSecOps principles and practices. - Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions, or equivalent). - Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash). - Solid understanding of common vulnerabilities (e.g., OWASP Top Ten) and remediation approaches. - Strong communication and collaboration skills with ability to engage cross-functional teams. - Familiarity with containerisation tools (e.g., Docker, Kubernetes). - Knowledge of security standards (e.g., NIST, ISO 27001, CIS).
Job Details
Responsibilities
- Define and drive the technical direction for security engineering
- Own critical security domains and capabilities end-to-end (AppSec, CloudSec, CI/CD security, vulnerability management)
- Set standards, patterns, and guardrails that scale across teams
- Lead security initiatives spanning multiple engineering teams
- Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security)
- Lead response and root-cause analysis for significant security incidents
- Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP)
- Mentor engineers and emerging leads
Requirements
- Typically 5+ years in security engineering, software engineering, or platform engineering
- Proven track record owning security capabilities or programmes at scale
- Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, Architecture)
- Strong hands-on engineering and automation background
- Demonstrated technical leadership and cross-team influence
- Working knowledge of DevSecOps principles and practices
- Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions)
- Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash)
- Solid understanding of common vulnerabilities (e.g., OWASP Top Ten)
- Familiarity with containerisation tools (e.g., Docker, Kubernetes)
- Knowledge of security standards (e.g., NIST, ISO 27001, CIS)
Skills & Technologies
Benefits & Perks

Related Opportunities
Discover more opportunities that match your interests and skills