As a Lead Agentic Security Engineer, you will provide technical leadership for security engineering across the organization. You will set technical direction, own critical security capabilities, drive cross-team security initiatives, and mentor engineers at all levels. You are accountable for the maturity and effectiveness of security engineering, balancing risk, delivery, and engineering realities.
This is a technical leadership role, not a people-management role — though it carries significant influence and mentorship responsibility.
Duties and accountabilities
Technical strategy and ownership
• Define and drive the technical direction for security engineering.
• Own critical security domains and capabilities end to end (AppSec, CloudSec, CI/CD security, vulnerability management).
• Set standards, patterns, and guardrails that scale across teams.
• Make and own high-impact, risk-based security decisions.
Cross-team leadership
• Lead security initiatives spanning multiple engineering teams.
• Act as the senior security point of contact for engineering leadership.
• Influence architecture and design across the organization.
• Align security efforts with business and delivery priorities.
Engineering and automation
• Drive security automation and tooling strategy (SAST, SCA, DAST, IaC, container security), including AI-assisted and AI-augmented tooling for triage, correlation, and remediation guidance.
• Evaluate and apply AI and generative AI tools — for example AI-assisted code review, AI-powered vulnerability triage, and LLM-based threat and log analysis — to improve signal quality, coverage, and developer experience, while validating their output rather than trusting it blindly.
• Ensure security platforms are reliable, scalable, and maintainable.
• Build the team's fluency with AI-assisted engineering tools (e.g., AI coding assistants, AI-enabled security scanners) and set guardrails for their safe, effective use, including awareness of AI/LLM-specific risks such as prompt injection, model and data supply-chain exposure, and sensitive-data leakage.
Risk, incident, and compliance
• Lead response and root-cause analysis for significant security incidents.
• Identify systemic risks and drive long-term remediation.
• Own security engineering input into compliance efforts (ISO 27001, SOC 2, FedRAMP).
• Coordinate external engagements (e.g., penetration testing vendors).
Mentorship and capability building
• Mentor engineers and emerging leads (including Associate Security Leads).
• Raise the overall security capability of engineering teams, including fluent, responsible use of AI-assisted tools.
• Champion a strong, pragmatic security culture.
What success looks like
• Security engineering direction is clear, pragmatic, and adopted.
• Critical risks are proactively identified and addressed.
• Engineering teams trust and act on security guidance.
• Security maturity improves measurably across the organization, including effective adoption of AI-assisted security tooling.
• Engineers grow under your mentorship.
• Typically 5+ years in security engineering, software engineering, or platform engineering.
• Proven track record owning security capabilities or programs at scale.
• Deep expertise across multiple domains (AppSec, CloudSec, CI/CD security, architecture).
• Strong hands-on engineering and automation background.
• Demonstrated technical leadership and cross-team influence.
• Practical fluency with AI tools in an engineering context — for example AI coding assistants, AI-assisted security scanning and triage, or LLM-based analysis — and the judgment to validate their output rather than trust it blindly.
• Demonstrated experience in security engineering with hands-on involvement in automated security solutions.
• Working knowledge of DevSecOps principles and practices.
• Practical experience with CI/CD tools (e.g., Bitbucket, Jenkins, GitLab, GitHub Actions, or equivalent).
• Proficiency in security platforms, vulnerability management tools, and at least one scripting language (e.g., Python, Bash).
• Comfort working with AI-assisted development and security tools (e.g., AI coding assistants, AI-driven SAST/DAST/SCA triage) as part of the day-to-day toolkit, with the judgment to review and validate AI-generated output.
• Solid understanding of common vulnerabilities (e.g., OWASP Top 10) and remediation approaches.
• Strong communication and collaboration skills with the ability to engage cross-functional teams.
• Familiarity with containerization tools (e.g., Docker, Kubernetes).
• Knowledge of security standards (e.g., NIST, ISO 27001, CIS).
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.
Job details are sourced from the employer's original posting.
Open job postingAbout the company
About IGT1 IGT1 is a rapidly growing offshore technology and talent solutions company based in Port City Colombo. We are a fully owned subsidiary of IGT I Holdings Sweden AB, funded by the three of world’s leading private equity firms; EQT Group, Hg, and TA Associates. We’re also proud to be a sister company of IFS, Sri Lanka’s largest and most established technology company.  At IGT1, we partner with global businesses to provide them with an operation that maximizes efficiency, spurs growth, allows them to develop and deliver world-class product and services, and create long-term value. Our people-first culture champions diversity, teamwork, and continuous learning, creating an environment where talent thrives.  With a team of over 500 professionals and counting, we are always looking for passionate, skilled individuals who want to make a global impact while being part of something extraordinary.  Through our offshore collaboration model, you'll be embedded within the team of one of our esteemed international clients, contributing directly to high-impact, enterprise-level initiatives.  About the client: Sitecore  Sitecore delivers a composable digital experience platform that empowers the world’s smartest and largest brands to build lifelong relationships with their customers. A highly decorated industry leader, Sitecore is the leading company bringing together content, commerce, and data into one connected platform that delivers millions of digital experiences every day. Thousands of blue-chip companies including American Express, Porsche, Starbucks, L’Oréal, and Volvo Cars rely on Sitecore to provide more engaging, personalized experiences for their customers.