Engineer - IT Support (Security and Compliance)
ORYSYS Limited
Full-time
Colombo 03, Colombo, Sri LankaThe Engineer – IT Support (Security and Compliance) plays a critical role in safeguarding the digital infrastructure by executing essential security controls and ensuring compliance with regulatory and audit requirements. This is a hands-on technical role, demanding expertise in endpoint protection, patching, antivirus/EDR administration, and IT compliance practices.
Job Role:
· Oversee timely patch deployment across all End-User Computing (EUC) devices in line with the bank’s security policies.
· Administer and maintain antivirus (AV) and Endpoint Detection & Response (EDR) solutionsto ensure a robust endpoint security posture.
· Monitor and analyze EDR alerts, perform first-level investigations, and escalate potential security incidents where necessary.
· Provide technical documentation and support for ISO 20000, ISO 27001, and PCI-DSS audit activities.
· Collaborate with relevant teams to close audit findings by implementing required technical remediation.
· Conduct regular compliance checks on patch levels, AV updates, and EDR coverage; compile and present compliance reports to management.
· Work in close partnership with Information Security, Infrastructure, and Risk units to continuously strengthen endpoint protection.
· Maintain and update logs, trackers, and dashboards related to AV/EDR compliance and endpoint security.
· Ensure strict adherence to IT Security standards, policies, and operational guidelines.
· Provide technical assistance during system hardening, upgrades, and deployment of endpoint security policies.
Job Specifications
· Bachelor’s Degree in Information Technology, Cybersecurity, or Computer Science from a recognized university.
· 2–3 years of proven experience in IT security operations, with a strong focus on endpoint protection, patching, and compliance.
· Proficiency in AV/EDR platforms (e.g., Kaspersky, ManageEngine, or equivalent).
· Good understanding of audit frameworks and regulatory standards such as ISO 27001, ISO 20000, and PCI-DSS.
· Strong analytical and problem-solving skills with the ability to perform under pressure in a compliance-driven environment.
· Excellent reporting and documentation skills.