Manager (Information Security) – Sampath Bank Colombo 02
Posted December 15, 2025 by Sampath Bank
Closing Date : December 29, 2025
About the job
REQUIREMENTS:
- Bachelor's Degree in IT, Cybersecurity. Computer Science, or a related field
- 10 years, out of which 03 years must be at a managerial level, with hands-on experience in Information Security and Compliance
- Experience in working in a Security Operations Centre (SoC)/hands-on experience in monitoring Technology Infrastructure Security, Vulnerability Testing and Mobile Security Testing platforms, and Web Security Testing platforms
- Globally recognised certifications, such as OSCP. СЕН. LPT. CISSP. CHFI. etc
- An MSc in Information Security will be considered an added advantage
KEY RESPONSIBILITIES:
- Lead and mentor a multidisciplinary cybersecurity team. training. performance management, and resource planning
- Manage the cybersecurity budget, aligning investment decisions with risk priorities and business objectives, while ensuring cost-effective procurement of tools and services, along with the CISO
- Lead the Governance. Risk, and Compliance (GRC) function, conducting enterprise-wide risk assessments, and ensuring full compliance with regulatory obligations
- Conduct Information Security reviews, as per the annual information security plan, and provide a detailed management report and follow-up remediation with relevant parties
- Formulate, implement and identify oversights in policies, strategies and programs designed to manage IS risk
- Co-ordinate with relevant external and internal stakeholders on IT security audits, special application security assessments, vulnerability assessments and penetration tests
- Support the operation and maintain the Information Security Management System standard ISO 27001. ISo 27035 and PCI DSS frameworks
- Responsible for implementing and maintaining the Security Standard for Information Security Management, as required by the regulator
- Lead Security Operations Centre (SoC) Management, and gather threat intelligence for risk mitigation
- Act as primary contact point for Information Security and Cyber events. investigate security breaches, assess areas of vulnerability and formulate corrective action plans to address issues. along with the CISO
- Evaluate potential business impacts from security breaches and provide strategies and tactical guidance to CISO and higher management
- Co-ordinate with internal and external stakeholders and other interested parties in the event of an incident. and facilitate evidence management processes of Cyber Security incidents
- Ensure Cyber Security Incident Response Policy is documented. tested and practiced for adequacy. and test the Cyber Security Incident Response Capabilities of the Bank in a timely manner
OTHER COMPETENCIES REQUIRED:
- Advance knowledge in attack vectors, threat trends. mitigation strategies, intrusion analysis and incident response
- Ability to take on challenges
- Proven track record, with out-of-the-box thinking. and recommending cost-effective security and control solutions
- Ability to multitask
- Good communication skills
An attractive remuneration package. coupled with a modern and conducive work environment, awaits the right candidate. Please apply online, stating qualifications and experience, on or before the 29th of December 2025. Selection will be strictly on merit. Any form of canvassing will be a definite disqualification. Only shortlisted candidates will be contacted
සෑලකිය යුතුයි : අපි ඔබව මෙම රැකියාව උපුටා ගත් පිටුවට හරවා යවන්නෙමු . අපි ඔබ වෙනුවෙන් ඔබේ CV , තොරතුරු අදාළ ආයතනය වෙත නොයවන බව කරුණාවෙන් සලකන්න
கவனமாக இருக்க வேண்டும் : இந்த வேலை மேற்கோள் காட்டப்பட்டுள்ள பக்கத்திற்கு உங்களை திருப்பி விடுவோம். உங்களுக்கான CV, தகவல்களை சம்பந்தப்பட்ட நிறுவனத்திற்கு நாங்கள் அனுப்ப மாட்டோம் என்பதை நினைவில் கொள்ளவும்
Disclaimer : By clicking the button below, you consent for CareerFirst and partners to use automated technology, including pre-recorded messages, cell phones and texts, and email to contact you at the number and email address provided. This includes if the number is currently on any Do Not Call Lists. This consent is not required to make a purchase. We are redirecting you to the employer's career page. Please note that we are not sending your CV to the employer on your behalf. Privacy Policy.
RELATED JOBS
National Development Bank PLC (NDB)
Closing Date: 2025-12-22
National Development Bank PLC (NDB)
Closing Date: 2026-01-12
Ceylon Petroleum Storage Terminals Limited
Closing Date: 2025-12-26
Litro Gas Limited
Closing Date: 2025-12-28
Nations Trust Bank PLC
Closing Date: 2026-01-10
Therighttalent
Closing Date: 2026-01-10
Cargills Ceylon PLC
Closing Date: 2025-12-18
HCLTech Sri Lanka
Closing Date: 2026-01-10
Dialog Axiata PLC
Closing Date: 2025-12-16
Hatton National Bank (HNB)
Closing Date: 2025-12-31
National Development Bank PLC (NDB)
Closing Date: 2025-12-17
SriLankan Airlines
Closing Date: 2025-12-20
MAS Holdings
Closing Date: 2025-12-16
Hatton National Bank (HNB)
Closing Date: 2026-01-09
John Keells Properties
Closing Date: 2025-12-16
Brandix Lanka Limited
Closing Date: 2026-01-08
Quess Lanka
Closing Date: 2026-01-07
Commercial Bank PLC
Closing Date: 2025-12-20