Information Security Lead - Corporate Office

Security / Military

About the Employer

Job Description

Information Security Lead (Corporate Office)

Are you an experienced Information Security professional passionate about Cybersecurity, Security Operations and Governance? Join our team and play a key role in strengthening the cyber resilience of a leading financial services organization.

Reporting to the Chief Information Security Officer (CISO), you will lead key Information Security initiatives and work closely with technology teams, business stakeholders, and leading security partners.

Key Responsibilities

  • Lead Information Security governance, including policies, standards, ISMS and regulatory compliance.
  • Lead security assessments and thematic reviews, identifying risks and driving remediation.
  • Drive Vulnerability Management, VAPT and Red Teaming activities and track remediation to closure.
  • Coordinate with the 24x7 SOC, including SIEM monitoring, threat detection, incident escalation and response.
  • Drive Attack Surface Management and external threat monitoring, including phishing, impersonation and exposed asset monitoring.
  • Lead Data Loss Prevention (DLP) initiatives and strengthen data protection controls.
  • Provide Security-by-Design and security advisory support for technology projects, including cloud, applications and APIs.
  • Drive organizational security awareness through targeted training, awareness campaigns, and security simulations.
  • Develop and monitor security KPIs/KRIs and cybersecurity posture reporting for management and governance committees.
  • Support the CISO in cybersecurity strategy, risk management, audits and Board-level reporting.

Qualifications & Experience

  • 3–5 years' experience in Information Security, Cybersecurity, IT Governance, Risk or a related field, with experience in leading or owning security initiatives.
  • Bachelor's Degree in IT, Cybersecurity, Computer Science or a related discipline.
  • Professional certifications such as CISA, CISM, CISSP or ISO 27001 will be an advantage.
  • Good knowledge of SOC, SIEM, EDR, DLP, Vulnerability Management, Firewalls, WAF, Threat Intelligence and security monitoring.
  • Knowledge of ISO 27001, NIST, CIS Controls, MITRE ATT&CK and COBIT.
  • Strong analytical, communication, stakeholder management and problem-solving skills, with the ability to lead initiatives and work independently.

If you are ready to take the next step in your cybersecurity career and work across a broad and evolving cybersecurity environment, send your CV to careers@lbfinance.lk indicating "Information Security Lead" in the subject line, together with details of two non-related referees, within 7 days of publication.

Join us in building a stronger and more resilient cybersecurity capability in the financial services industry.

By submitting your CV, you consent to the processing of your personal data. Your information will be handled with the utmost confidentiality and will not be shared with any third parties. LB Finance PLC, we are committed to upholding our privacy notice and company data protection policy to ensure the highest standards of data security and integrity.