The Central Bank of Sri Lanka is recruiting a Red Team Specialist — a cybersecurity professional whose job is to simulate real-world attacks against the bank’s own systems and hunt for intruders already inside them.

The post is a contract role of no more than three years, aimed at strengthening the regulator’s threat intelligence, network defence and breach simulation capabilities, EconomyNext reported.

What the job involves

According to the vacancy notice published on the bank’s website, the specialist will run intelligence-led red team engagements and proactive “hunt missions” across the bank’s networks.

Duties listed include:

Red teaming is the practice of having an in-house unit behave like an attacker — probing systems for weaknesses before an outside adversary finds them.

Terms

Applicants need a bachelor’s or master’s degree in information security, computer science, computer engineering or IT from a UGC-recognised institution, or one or more offensive-security certifications, including OSCP, CPT, eCPPT, GPEN or GWAPT.

Remuneration is listed as negotiable, with EPF and ETF contributions. Applications close on 31 October 2026 and must be submitted through the bank’s careers portal.

One condition is unusual for a specialist security post: candidates must be under 30 years of age as at 31 October 2026, a ceiling that sits awkwardly against the depth of offensive-security experience the role describes.

Context

Central banks are high-value targets for financially motivated attackers, and the notice says the bank faces heightened risk from increasingly complex financial fraud campaigns.

The recruitment follows the bank’s call last week for expressions of interest in an enterprise data solution to strengthen its data management and analytics — two moves in a week pointing to a broader technology build-out at the regulator.

Not reported

The notice does not say whether the bank currently operates an in-house red team, how large its security function is, or whether the recruitment follows any specific incident.