Job Description

Vacancy for the Post of Threat Hunter (01 Position)

Founded in 2006, the Sri Lanka Computer Emergency Readiness Team (Sri Lanka CERT) is Sri Lanka's National CERT which has the mandate to protect the nation's cyber space.

Sri Lanka CERT is currently seeking a passionate and committed individual to join its team as Threat Hunter of Malware Analysis and Threat Hunting (MATH) Lab. This role offers a unique opportunity to contribute to the nation's one of the premier cybersecurity initiatives.

Job Responsibilities

  • Advanced hunt campaigns - Design ATT&CK tactic based hunts and lead month long data science assisted sweeps.
  • Content lifecycle & QA - Own the detection content backlog: peer review, regression testing, false positive tuning, and SLA tracking.
  • Blue vs Red exercises - Coordinate purple team drills using CALDERA / Atomic Red Team; measure detection coverage and MITRE D3FEND mappings.
  • Mentoring & knowledge transfer - Conduct fortnightly threat intel briefings: guide Associates through hunt methodology and root cause write ups.
  • Cross discipline forensics - Perform host memory & artefact analysis with Velociraptor, KAPE, and Volatility to confirm hunt leads.
  • Conduct proactive threat hunting operations to identify and neutralize threats before they cause harm.
  • Develop and refine hypotheses based on the latest threat intelligence and internal data.
  • Utilize advanced tools and techniques to analyze network traffic, logs, and endpoints for signs of compromise.
  • Collaborate with the malware analysis team to understand and counteract emerging threats.
  • Develop and maintain custom detection rules and scripts to automate threat hunting activities.
  • Produce detailed reports and recommendations based on findings from threat hunting activities.
  • Keep up-to-date with the latest developments in threat hunting methodologies and tools.

Experience Requirement

  • Five (05) years or above industry experience in the field of information and Cyber security or relevant out of which 02 years should be in a threat hunting, security analysis or a similar role at supervisory level within a reputed private sector cyber-security service provider, public corporation, statutory board, fully government owned company, or a reputed commercial establishment, after obtaining the first Degree.

Variety of skills

  • Deep understanding of Windows internals (WMI, LSASS, ETW), AD security (BloodHound, Kerberoasting), and Linux auditd/eBPF telemetry.
  • Advanced scripting automation (Python, Go, or PowerShell), REST API integration (Elastic, MISP).
  • Incident command experience, strong presentation abilities.
  • Strong knowledge of TTPs used by advanced threat actors.
  • Proven experience in threat hunting, security analysis, or a related field.
  • Proficiency in scripting languages (e.g., Python, PowerShell).
  • Experience with SIEM and EDR tools.
  • Excellent analytical and investigative skills.
  • Both Sinhala and English language proficiency.
  • Passionate about mastering the latest Cyber Threat Intelligence CTI tools and contributing to proactive cyber defense initiatives.

Educational and Professional Qualifications

  • A Bachelor's Degree (SLQF 5 or 6) in Information Security, Cyber-Security, Computer Science, Information Technology or any other field relevant to the post, obtained from a local or foreign university, recognized by the University Grant Commission (UGC) in Sri Lanka.
  • Should hold a verifiable Cyber-security certification, preferably CEH, CHFI, GIAC GCTI, GCIA, GCH, GMON; MITRE ATT&CK CyberThreat Horizon Graduate; OffSec OSEP, CCNA or any other verifiable relevant certification relevant to the post. Such certifications must be maintained in active status.

What We Offer

  • Opportunity to contribute to the national cybersecurity infrastructure.
  • Hands-on experience with advanced cybersecurity tools and technologies.
  • Competitive remuneration and allowances.
  • Continuous training and career development opportunities.
  • Local and overseas trainings (short term).

Salary will be based on current industry standards and includes travel allowances.

If you are confident that you are the ideal candidate for this position, e-mail your resume with a recent photo and two non-related referees to [email protected] within 14 days of this advertisement, stating Threat Hunter. Only shortlisted candidates will be notified.

Note: This job description is not intended to be all-inclusive. Employees may perform other related duties as negotiated to meet the ongoing needs of Sri Lanka CERT and MATH Lab.

Chief Executive Officer

Sri Lanka Computer Emergency Readiness Team | Coordination Centre

Room 4-112, BMICH, Baudhaloka Mawatha, Colombo 00700

Tel: 011 2691692 / 011 2679888