

Commercial Bank
Senior Engineer (IT Security & Compliance)
Contact us to remove this listing
- Full Time
- Colombo, Sri Lanka
- Negotiable LKR / Month

Commercial Bank
Senior Engineer (IT Security & Compliance) – Commercial Bank
Job Overview
Commercial Bank of Ceylon PLC is inviting applications for the position of Senior Engineer – IT Security & Compliance. The bank is seeking an experienced cybersecurity professional to strengthen its Governance, Risk, and Compliance (GRC) framework, ensure regulatory compliance, and enhance enterprise-wide IT security across its operations and subsidiaries.
Position Details
Job Title: Senior Engineer – IT Security & Compliance
Company: Commercial Bank of Ceylon PLC
Employment Type: Full-Time
Industry: Banking & Financial Services
Job Category: IT Jobs, Cyber Security Jobs, Information Security Jobs, Banking Jobs, Private Jobs
Job Location: Sri Lanka
Company Overview
Commercial Bank of Ceylon PLC is Sri Lanka’s most awarded bank and the first Sri Lankan bank to be listed among the Top 1000 Banks in the World. Renowned for innovation, digital transformation, and customer-focused financial solutions, the bank offers excellent career opportunities for talented professionals committed to technological excellence.
Qualifications & Requirements
Applicants should possess the following qualifications and experience:
- Bachelor’s Degree in Information Security, Computer Science, Information Technology, or a related field with specialization in Cyber Security.
- Minimum 5 years of experience in technology risk management, preferably in:
- Licensed Commercial Banks (LCB)
- Licensed Specialized Banks (LSB)
- Licensed Finance Companies (LFC)
- Global auditing firms serving financial sector clients.
- Proven experience working with Central Bank of Sri Lanka (CBSL) regulatory frameworks.
- Professional certifications such as:
- CISA
- CompTIA Security+
- ISO 27001 Lead Auditor/Implementer
- ITIL Foundation
- (Any of these will be an added advantage.)
- Advanced knowledge of:
- PCI DSS
- ISO 27001
- NIST Cyber Security Framework (CSF)
- CBSL Guidelines
- SWIFT Security Framework
- Ability to guide IT operations teams in aligning with Governance, Risk, and Compliance (GRC) standards.
Key Responsibilities
The selected candidate will be responsible for:
- Deploying and continuously improving the enterprise IT Governance Framework across local and overseas operations.
- Conducting annual gap assessments of the IT Governance Framework and addressing compliance deficiencies.
- Mapping governance controls to regulatory requirements including COBIT, ISO 27001, and NIST CSF.
- Developing, reviewing, and maintaining IT policies, Standard Operating Procedures (SOPs), and security guidelines.
- Performing end-to-end technology risk assessments covering critical information systems, cloud environments, and third-party vendors.
- Ensuring compliance with the CBSL Regulatory Framework on Technology Risk Management and Resilience and the Personal Data Protection Act (PDPA) No. 9 of 2022.
- Maintaining and updating the IT Asset and IT Risk Registers while facilitating regulatory risk control assessments.
- Supporting security controls including:
- User access management
- Privilege reviews
- Data encryption
- Security governance
- Tracking audit findings, vulnerabilities, and regulatory gaps while driving mitigation plans within agreed service levels.
- Managing software license inventories and proactively addressing compliance deviations.
- Handling information security due diligence requests and security questionnaires from clients and third parties.
Required Skills
- Information Security
- Cyber Security
- IT Governance
- Risk Management
- IT Compliance
- ISO 27001
- COBIT
- NIST Cyber Security Framework (CSF)
- PCI DSS
- SWIFT Security Framework
- IT Risk Assessment
- Governance, Risk & Compliance (GRC)
- Internal Controls
- Regulatory Compliance
- Cloud Security
- Vendor Risk Management
- Data Protection
- Security Auditing
- Information Security Policies
- Stakeholder Management
Salary & Benefits
Commercial Bank offers:
- Attractive remuneration package aligned with leading financial institutions.
- Career growth in Sri Lanka’s most awarded bank.
- Exposure to enterprise-scale cybersecurity and governance projects.
- Opportunities for continuous professional development and certification.
- Dynamic and technology-driven working environment.
How to Apply
Interested candidates should submit their application through the Commercial Bank Careers Portal by visiting the bank’s corporate website and navigating to:
Careers → Open Positions → Senior Engineer – IT Security & Compliance
Important Notes
- Company: Commercial Bank of Ceylon PLC
- Position: Senior Engineer – IT Security & Compliance
- Industry: Banking & Financial Services
- Experience Required: Minimum 5 years
- Applications must be submitted through the bank’s official careers portal.
- Only shortlisted candidates will be contacted.
Ready to apply?
Senior Engineer (IT Security & Compliance)
⏰ Deadline: August 2, 2026
More Opportunities
Related Job Vacancies


Assistant Manager (Branch Operations)
PMF Finance PLC

Associate (Business Administration)
Assetline Finance PLC

Associate (Cash Office)
Assetline Finance PLC

Associate Manager
Assetline Finance PLC

Executive Officer (Customer On Boarding Operations)
Union Bank


Executive (Finance Reporting)
Union Bank of Colombo PLC