Kanthoruwa

Cyber Threat Analyst

Cybersecurity·Colombo 7·Posted Aug 7, 2026

Threat Hunter

Company: Sri Lanka CERT

Role Summary

Founded in 2006, the Sri Lanka Computer Emergency Readiness Team (Sri Lanka CERT) is Sri Lanka's National CERT which has the mandate to protect the nation's cyber space. Sri Lanka CERT is currently seeking a passionate and committed individual to join its team as a Threat Hunter of Malware Analysis and Threat Hunting (MATH Lab).

Job Responsibilities

  • Advanced hunt campaigns - Design ATT&CK tactic based hunts and lead long data science assisted sweeps.
  • Content lifecycle & QA - Own the detection content backlog: peer review, regression testing, false positive tuning, and SLA tracking.
  • Blue Red exercises - Coordinate purple team drills using CALDERA / Atomic Red Team; measure detection coverage and MITRE D3FEND mappings.
  • Knowledge & coverage transfer - Conduct fortifying threat intel briefings; guide Associates through methodology and ensure cause write ups.
  • Cross discipline forensics - Perform host memory & artifact analysis with Velociraptor, KAPE, and Volatility to confirm hunt leads.
  • Conduct proactive threat hunting operations to identify and neutralize threats before they cause harm.
  • Develop and refine hypotheses based on the latest threat intelligence and internal data.
  • Utilize advanced tools and techniques to analyze network traffic, logs, and endpoints for signs of compromise.
  • Collaborate with the malware analysis team to understand and counteract emerging threats.
  • Develop and maintain custom detection rules and scripts to automate threat hunting activities.
  • Produce detailed reports and recommendations based on findings from threat hunting activities.
  • Keep up-to-date with the latest developments in threat hunting methodologies and tools.

Experience Requirement

  • Five (05) years or above industry experience in the field of information and Cyber security or relevant of out which 02 years should be in a threat hunting, security analysis or a similar role at supervisory level within a reputed private sector cyber-security service provider, public corporation, statutory board, fully government owned company, or a reputed commercial establishment, after obtaining the first Degree.

Variety of Skills

  • Deep understanding of Windows internals (WMI, LSASS, ETW), AD security (BloodHound, Kerberoasting), and Linux audit/EBPF telemetry.
  • Advanced scripting automation (Python, Go, or PowerShell), REST API integration (Elastic, MISP).
  • Incident command experience, strong suspicion analysis presentation.
  • Strong knowledge of TTPs used by advanced threat actors.
  • Provenance in threat hunting, security analysis, or a related field.
  • Proficiency in scripting languages (e.g., Python, PowerShell).
  • Experience with SIEM and EDR tools.
  • Excellent analytical and investigative skills.
  • Both Sinhala and English language proficiency.
  • Passionate about mastering the latest Cyber Threat Intelligence (CTI) tools and contributing to proactive cyber defense initiatives.

Educational and Professional Qualifications

  • A Bachelor's Degree (SLQF 5 or 6) in Information Security, Cyber-Security, Computer Science, Information Technology or any other relevant field to the post, obtained from a local or foreign university, recognized by the University Grants Commission (UGC) in Sri Lanka.
  • Should hold a verifiable Cyber-security certification, preferably CEH, CHFI, GIAC GCTI, GCIA, GCIH, GMON, MITRE ATT&&CK Cyber Threat Horizon Graduat,