Default Avatar
Candidate Name
Senior Information Security Engineer
Sri Lanka
Summary

Senior Information Security Engineer specializing in Governance, Risk, and Compliance (GRC) at Sri Lanka Cert, with a strong technical foundation in cybersecurity operations. I support organizations in identifying, assessing, and managing information security risks while aligning security controls with regulatory, policy, and business requirements.

My work focuses on risk assessments, security audits, control effectiveness reviews, and continuous improvement of information security programs in line with standards such as ISO/IEC 27001 and related frameworks. I actively contribute to strengthening organizational security posture by translating technical risks into clear, actionable insights for management and stakeholders.

Prior to transitioning into GRC, I gained hands-on experience in threat detection, incident response, and security operations, including the deployment and management of EDR solutions to protect environments against advanced malware and ransomware threats. I also have professional experience as a firewall engineer, managing and troubleshooting enterprise security platforms such as FortiGate, Palo Alto, Prisma SASE, and Sophos, while working closely with vendors to resolve high-impact issues under time constraints.

This blend of operational security and GRC expertise allows me to bridge the gap between technical teams and governance requirements. I am a collaborative professional and effective communicator, committed to building resilient, compliant, and risk-aware organizations.

Work experience
01/01/2026
Senior Information Security Engineer
01/02/2024
01/12/2025
Engineer - Systems & Security
01/07/2023
01/02/2024
Associate Engineer - Systems & Security
Education & certifications
01/01/2018
01/03/2022
Bachelor's degree
Cyber/Computer Forensics and Counterterrorism
Open to relocate
Skills
Cybersecurity Cyber Threat Intelligence Threat Hunting Forensics Vulnerability Assessment Penetration Testing Endpoint Security Endpoint Detection and Response (EDR) EDR Firewalls Governance Risk Management Compliance Azure Active Directory Security Cloud Security Security Auditing Vulnerability Management Qualys ISO 27001 Information Security Risk Assessment

You need to log in as an employer to view full candidate details.