Default Avatar
Candidate Name
Senior Analyst - Information Security & Governance
Sri Lanka
Summary

Results-driven Cybersecurity and GRC professional with 4+ years of hands-on experience designing and enforcing information security governance across multi-industry, multinational organizations. Originally trained in aviation human factors — an experience that cultivated a deep understanding of operational risk, crew resource management, and the critical role of human decision-making in high-stakes environments — before transitioning into cybersecurity through a formal MSc specialization. This cross-disciplinary background provides a unique lens on risk management, particularly in regulated and safety-critical industries.
Previously based in Sydney, Australia, with direct hands-on experience implementing and maintaining Essential Eight, ISM, and AESCSF compliance frameworks alongside ISO 27001 certification. Proven track record of
delivering end-to-end compliance programs for PCI DSS, ISO 27001, SOC 2 Type II, and GDPR simultaneously, and leading cross-functional governance teams. Experienced in translating complex regulatory requirements into
actionable security frameworks aligned with TOGAF/SABSA, and in driving collaboration between executive leadership, development teams, and external auditors to achieve measurable improvements in organizational cyber maturity.

Work experience
01/11/2023
21/03/2026
Senior Analyst - Information Security & Governance
01/12/2022
01/03/2023
Associate Information Security Engineer
01/07/2021
01/08/2022
Cyber Security Consultant - GRC
Education & certifications
01/07/2019
01/07/2021
Master's Degree
Information Technology Specializing in Cybersecurity
01/09/2012
01/07/2015
Bachelor's Degree
Psychology
Open to relocate
Skills
Cybersecurity Information Security Network Security Penetration Testing Vulnerability Assessment Incident Response Threat Intelligence Risk Management Compliance Governance Endpoint Security Security Information and Event Management (SIEM) Threat Hunting Security Awareness Training Threat Modeling ISO 27001 Security Risk Assessment Security Compliance Audits Security Incident Management Threat Detection Vulnerability Management Security Risk Management Security Compliance Security Governance Security Awareness Risk Assessment Cyber Threat Intelligence Security Training & Awareness Security Incident Analysis QRadar Analytical Skills Problem Solving Team Collaboration Security Incident Triage Analytics Tools

You need to log in as an employer to view full candidate details.