வேலைவாய்ப்பு–Central Bank of Sri Lanka

RED Team Specialist (on Contract)

Job Reference

CBSLJP01

Employment Type

Contract

Closing Date

15 July 2026 (15 days left)

Age Limit

Not more than 30 years as at Application Closing date 15.07.2026

Remuneration

Negotiable with contribution to EPF and ETF.

Requirements

Educational/Professional Qualifications

  • A Bachelor’s or Master’s Degree in Information Security/Computer Science/ Computer Engineering/Information Technology Specialized in Information Security from a university or a Degree awarding institute recognized by the University Grants Commission

OR

One or more certifications from the following

  • Offensive Security Certified Professional (OSCP)
  • Offensive Security Web Expert (OSWE)
  • Offensive Security Experienced Penetration Tester (OSEP)
  • Certified Ethical Hacker (CEH)
  • Certified Penetration Tester (CPT)
  • eLearn Security Certified Professional Penetration Tester (eCPPT)
  • GIAC Penetration Tester Certification (GPEN)
  • GIAC Web Application Penetration Tester (GWAPT)

Experience:

  • Minimum of four (04) years’ experience in Red Team or Penetration Testing activities, including maintaining advanced operational, technical, and authoritative situational awareness during threat emulation-based exploitation and operations.
  • At least one (01) year of experience in a leadership role (e.g., Team Lead) will be considered an advantage.
  • Participation in Bug Bounty Programs and Capture the Flag (CTF) competitions will be considered an added advantage.
  • Proficiency in programming/scripting languages such as .NET, Python, Bash, and PowerShell.
  • Demonstrated expertise in leading and executing intelligence-led red team engagements, from planning through closure. Skilled in developing and implementing Tactics, Techniques, and Procedures (TTPs) aligned with threat actor profiles, industry frameworks, and best practices.
  • Strong project management skills, including meeting requirements and timelines, preparing documentation, and overseeing risk management aspects throughout the project lifecycle.
  • Excellent written and verbal communication skills with the ability to present technical concepts to non-technical audiences.
May be an image of text that says 'ලංකාම S0 මත MnIR ေောပ် eлa ลิว (ន្រះប ምስናጠር ශ්‍රී ලංකා මහ බැංකුව இலங்கை மத்திய வங்கி CENTRAL BANK OF SRI LANKA CAREER OPPORTUNITIES RED TEAT Specialist (ON CONTRACT) Application Closing Date 15.07.2026 For details: https://www.bsl.gov.lk/en/career Director- Human Resources Central Bank of Sri Lanka, No. 30, Janadhipathi Mawatha, Colombo 01. Telephone 011-2477330 Fax: 011-2477715'

Responsibilities

(a) RED Team Testing / Breach and Attack Simulation (BAS)

Perform analysis of proactive information security incidents & advanced threat actors for further enhancement of Detection Catalog and Hunt missions by leveraging the MITRE ATT&CK Framework Adversarial Tactics, Techniques, Procedures and Common Knowledge.

(b) Proactive Threat Hunting and Threat Intelligence

  • Hunt for and identify threat actor groups and their techniques, tools and processes (e.g.-Using different types of open source intelligence feeds)
  • Work with the detections team to transform attacker TTP’s (Tactics, Techniques & procedures) into viable, low false positive behavioral and signature detections using a variety of techniques including supervised, semi-supervised, and unsupervised Machine Learning with an emphasis on sequential classification and pattern matching
  • Monitor and analyze cybercrime threat reports for a different vertical, a specific attack or APT groups to proactively create IOCs (Indicator of Compromise) for Threat Hunting
  • Use a wide variety of Cyber Threat Intelligence tools & websites, including the dark web
  • Participate in “hunt missions” using cyber threat intelligence, analysis of anomalous log data and results of brainstorming sessions to detect and eradicate threat actors on various networks
  • Develop and implement a threat hunting framework to provide a comprehensive structure for planning, executing, and managing threat hunting initiatives.
  • Continuously enhance threat hunting techniques, processes, and tools to improve the organization’s overall cybersecurity posture.
  • Conduct proactive threat hunting exercises to identify and investigate potential security incidents and suspicious activities within the network.
  • Document all findings, analysis, recommendations and investigation results in a clear and concise manner and generate reports for management and stakeholders.
  • Conduct in-depth analysis of threat actors, their motivations, capabilities, and tactics, and provide insights on potential risks and impacts to the organization’s systems, networks, and data.
  • Produce regular and ad-hoc reports, briefings, and alerts on emerging threats, trends, and risk assessments to relevant stakeholders, including senior management, incident response teams, and other cybersecurity teams. The report shall also provide technical information in a clear and actionable format for various stakeholders.
  • Provide timely and accurate intelligence support during security incidents, assisting incident response teams in understanding the nature and scope of the threat, and providing guidance on containment, remediation and recovery strategies.
  • Track ransomware groups, phishing kits, and fraud campaigns on the dark web and open sources.

Skills Required

  • Enhance internal VAPT and red team capabilities by developing scripts, automating processes and researching the latest exploitation Tactics, Techniques and Procedures (TTPs) used by threat actors.
  • Capability of Organizing and participating in Capture-The-Flag (CTF) events, both internally and externally.
  • Problem solving skills on short timeframes and ability to “think outside the box” & Analytical thinking with the ability to break down a big problem into smaller chunks.

Method of Selection

Candidates who fulfill the required minimum criteria as specified will be shortlisted for the selection interview/s.

How to Apply

Applicants who possess the required qualifications and experience and wish to apply for the above position should submit their applications only through the following link on or before 15.07.2026.

Link: https://www.cbsl.gov.lk/en/careers

Applicants are strictly advised to adhere to the terms and conditions stipulated in the above link when submitting applications.

 

Facebook
Twitter
LinkedIn
WhatsApp

Leave a Reply

Your email address will not be published. Required fields are marked *

Recent Post

psta no
பயங்கரவாதம் என்றால் என்ன?
king-khalid-international-airport-in-riyadh-saudi-arabia-ZP26XTI4CVFERI4HMUEAT6LVXU
சவுதிஅரேபிய விமானநிலையத்தின் மீது தாக்குதல்- அனோஜன் விவகாரத்திற்காக சென்ற குழுவினர் நாடு திரும்ப முடியாத நிலையில்
vaharai prawn
வாகரைப் பிரதேசத்தின் இயற்கை வளங்களையும் மக்களின் வாழ்வாதாரத்தையும் அழிக்கும் இறால் பண்ணை அபிவிருத்தித் திட்டத்தைக் கைவிட வேண்டும்
saudhi airport att
சவுதி தலைநகரில் விமானநிலையத்தின் மீது தாக்குதல் - 12 பேர் பலி
shipsss
இலங்கை கடற்பரப்பிற்கு வெளியே நங்கூரமிட்டுள்ள ஈரானிய கப்பல்களில் இலங்கையர்? அரசாங்கம் தெரிவிப்பது என்ன?
navipillay
நவநீதம் பிள்ளை தனது வாழ்நாள் முழுவதும் ஒடுக்கப்பட்ட புறக்கணிக்கப்பட்ட மக்களின் தளம்பாத குரலாக விளங்கிவந்துள்ளார்- கனேடிய தமிழர் பேரவை
hrw
மரணதண்டனைக்கு எதிரான சர்வதேச தினம் இன்று- சவுதி அரேபியாவில் ஆபத்தான நிலை என மனித உரிமை கண்காணிப்பகம் தெரிவிப்பு
ranil 4455
துறவற ஆடை விவகாரத்தினாலேயே 2019 இல் ஞானசாரருக்கு பொதுமன்னிப்பு வழங்கப்பட்டது – ரணில்
842033602_1124884036890946_153497222328659022_n
நவநீதம் பிள்ளை எண்ணற்ற மக்களின் மனங்களில் அமைதி நீதி மற்றும் உரிமைகளுக்கான சுடரை ஏற்றிவைத்துள்ளார்- கரி ஆனந்தசங்கரி
sanath jaya
அனோஜனுக்கு பொதுமன்னிப்பு வழங்கவேண்டும் - சனத்வேண்டுகோள்