
Website Security Engineer
Posted Jul 1

Posted Jul 1
This is a fully remote position, open to applicants in Sri Lanka.
• Take proactive measures to oversee security functions on WordPress-based websites, ensuring timely security updates to uphold a fortified environment.
• Supervise centralized server logs, Web Application Firewalls (WAF), and malware alerts to detect and mitigate threats before they escalate.
• Serve as the main internal contact during website product security incidents, leading containment efforts, remediation processes, and comprehensive post-mortem analyses.
• Create and enforce a "Security Gold Standard" checklist for all new site launches and third-party integrations.
• Convert intricate technical logs and security posture data into actionable insights for leadership teams.
• Collaborate with internal stakeholders to deliver transparent updates and assist client-facing teams with sensitive security communications.
• At least 2 years of experience in security, with a focus on website security best practices.
• Demonstrated history of proactive threat identification and the maintenance of Indicators of Compromise (IoCs).
• Experience in leading security incident responses, including containment and post-incident reviews.
• Knowledge of digital compliance standards such as GDPR and CPRA.
• Strong capability to interpret complex technical concepts and convey them as clear, actionable advice for non-technical teams.
• Relevant certifications such as CEH, Security+, OSCP, or SSCP are highly desirable.
• Comprehensive health and wellness benefits.
• Opportunities for professional development and certifications.
• Flexible working hours and remote work options.
• Collaborative and inclusive work environment.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.