Or
Nisal Priyanka

Nisal Priyanka

Penetration Testing, ISO 27001 & Cloud Security
📍 Colombo, Sri Lanka · (0) · Member since April 2026
Availability
🏠 Works remotely / from home Yes No
🧰 Travels to client Yes No

Presentation

I help businesses find and fix security weaknesses before attackers do. Whether you're a startup or an established company, I offer practical, hands-on security services that are clear, actionable, and business-focused.

What I offer:
🔍 Penetration Testing -I simulate real-world attacks on your web applications, APIs, and network infrastructure to uncover vulnerabilities. You get a clear-English report with risk ratings and step-by-step fixes.

☁️ Cloud Security Reviews - I assess your cloud environment (AWS, Microsoft 365 / Entra ID, or Keycloak) to identify misconfigurations, access control gaps, and architecture risks.

📋 ISO 27001 Gap Assessment - Not sure how ready you are for ISO 27001 certification? I'll map your current security posture against the standard, highlight what's missing, and give you a clear roadmap to close the gaps.

Who I work with:
Small to mid-sized businesses, startups, and teams that take security seriously but don't have a full-time security team in-house.
You'll always get:
✅ Clear eports
✅ Prioritised findings
✅ Practical recommendations, not just a list of problems
🛠️

Offered services

4 services
📋

Background

Associate Lead Security Engineer
TechCERT · 01/02/2026 – Today
I lead security assessments across web, API, LLM, desktop, and infrastructure — specialising in manual testing of authentication, authorisation, and business logic vulnerabilities. I develop internal security tools including LLM-powered testing assistants, mentor junior engineers, and guide clients through remediation and re-testing. As an ISO 27001:2022 Certified Lead Auditor, I bring both technical depth and compliance expertise to every engagement.

Core Competencies:
Advanced VAPT, IAM Security, ISO 27001:2022 Lead Auditor, LLM Security ,Security Tool Development Malware Analysis, DevOps & Secure SDLC ,Technical Leadership
Senior Information Security Engineer
TechCERT · 01/01/2024 – 01/02/2026
Information Security Engineer
TechCERT · 03/08/2020 – 01/01/2024
Cyber Security Engineer
Yunly International Marketing · 15/03/2019 – 02/08/2020
contributing to both security and backend development. I gained practical experience in API security testing, web scraping, and backend development, while also working with DevOps practices including CI/CD pipeline setup and management. This role gave me a real-world understanding of how security integrates into modern development workflows
Secure Software Engineering Intern
Epic Lanka PVT LTD · 15/08/2018 – 10/03/2019
During my internship at Epic Lanka, I worked within a software development environment where I gained practical experience in secure coding practices and mobile application security testing. This role strengthened my understanding of how security is applied throughout the software development lifecycle
Internship
Ernst & Young - EY · 01/01/2018 – 01/06/2018
During my internship at EY, I gained hands-on experience conducting penetration testing across network infrastructure, web applications, and mobile platforms. Working within a Big 4 professional services environment, I was exposed to industry-standard methodologies and real-world client engagements
MSc in Cyber Security
Sri Lanka Institute of Information Technology - SLIIT · 2021 – 2023
Building on my undergraduate foundation, my Master's deepened my expertise in advanced cybersecurity concepts including penetration testing methodologies, cloud security, security governance, and risk management frameworks.

I developed hands-on skills in threat intelligence, incident response, and security architecture design.

The programme also covered compliance standards such as ISO 27001, advanced network security, and research-driven approaches to emerging cyber threats
BSc (Hons) Information Technology - Specialization in Cyber Security
Sri Lanka Institute of Information Technology - SLIIT · 2015 – 2020
During my degree, I built a strong foundation in information security, covering network security, ethical hacking, cryptography, and secure software development. My specialization focused on real-world cybersecurity practices including vulnerability assessment, risk management, digital forensics, and security architecture. Alongside the technical core, I also studied database systems, operating systems, and software engineering
🇬🇧English
🕐

Working hours

Monday
Closed
Tuesday
Closed
Wednesday
Closed
Thursday
Closed
Friday
From10h00To18h30
From14h00To14h30
Saturday
From10h00To18h30
From10h00To14h30
Sunday ▪ Today
From12h00To20h00
From16h00To16h30

Reviews

No reviews

⚠️
Please as a customer to give your feedback
💬
No reviews yet.
Be the first to share your experience with this professional.