CBSL takes fight to dark web: To hire Red Team Specialist to test defences, track cyber fraud

Tuesday, 29 September 2026 03:16 -     - {{hitsCtrl.values.hits}}


 Contract hire to simulate attacks, hunt threats and track ransomware, phishing and fraud campaigns on dark web

 Applicants must be under 30 as at 31 Oct. with at least four years’ red team or penetration testing experience

The Central Bank of Sri Lanka (CBSL) is recruiting a Red Team Specialist on contract to test its cyber defences by simulating attacks on its own systems and to hunt for threats before they cause damage, according to a vacancy notice.

A red team attacks an organisation’s systems in the way a real adversary would, so that weaknesses can be found and fixed before criminals exploit them.

The specialist will run breach and attack simulations using the MITRE ATT&CK framework, a publicly available catalogue of the tactics and techniques used by hackers. The role includes working with the CBSL’s detection team to turn known attacker methods into alerts with few false alarms, using techniques that include machine learning.

The specialist will also track ransomware groups, phishing kits, and fraud campaigns on the dark web and open sources, and create indicators of compromise, the digital traces that signal a system may have been breached. The role involves supporting incident response teams on containment and recovery during security incidents, and briefing senior management on emerging threats.

Applicants need at least four years’ experience in red teaming or penetration testing, which involves authorised, simulated attacks on systems. They also need either a Bachelor’s or Master’s degree in Information Security or a related field specialised in information security, from an institution recognised by the University Grants Commission, or one or more of eight listed certifications, including Offensive Security Certified Professional (OSCP) and Certified Ethical Hacker (CEH).

Applicants must be below 30 years of age as at 31 October 2026. Leadership experience, participation in bug bounty programs, which pay researchers for reporting security flaws, and in Capture the Flag hacking competitions will be considered an advantage.

The post is offered on contract for not more than three years, with negotiable pay and contributions to the Employees’ Provident Fund and Employees’ Trust Fund. Applications must be submitted through the CBSL careers page by 31 October 2026, and shortlisted candidates will be called for interviews.

The recruitment comes after a separate cyber fraud at the Finance Ministry for which the CBSL has drawn much flak. 

The Ministry lost $ 2.5 million after cybercriminals diverted debt repayments due to Export Finance Australia, part of a $ 22.9 million external debt repayment, through 10 transactions made between December 2025 and January 2026, using emails that altered the creditor’s bank details. 

The Criminal Investigation Department (CID) had recorded statements from 21 individuals, Public Security Minister Ananda Wijepala told Parliament on 7 May. In June, the International Monetary Fund (IMF) granted Sri Lanka a waiver after the missed payment breached a performance criterion under its Extended Fund Facility, describing the breach as minor.

COMMENTS