
Nisal Priyanka
Colombo, Sri Lanka
Nisal Priyanka
Penetration Testing, ISO 27001 & Cloud Security
Category : Cybersecurity
I help businesses find and fix security weaknesses before attackers do. Whether you're a startup or an established company, I offer practical, hands-on security services that are clear, actionable, and business-focused.
What I offer:
๐ Penetration Testing -I simulate real-world attacks on your web applications, APIs, and network infrastructure to uncover vulnerabilities. You get a clear-English report with risk ratings and step-by-step fixes.
โ๏ธ Cloud Security Reviews - I assess your cloud environment (AWS, Microsoft 365 / Entra ID, or Keycloak) to identify misconfigurations, access control gaps, and architecture risks.
๐ ISO 27001 Gap Assessment - Not sure how ready you are for ISO 27001 certification? I'll map your current security posture against the standard, highlight what's missing, and give you a clear roadmap to close the gaps.
Who I work with:
Small to mid-sized businesses, startups, and teams that take security seriously but don't have a full-time security team in-house.
You'll always get:
โ Clear eports
โ Prioritised findings
โ Practical recommendations, not just a list of problems
What I offer:
๐ Penetration Testing -I simulate real-world attacks on your web applications, APIs, and network infrastructure to uncover vulnerabilities. You get a clear-English report with risk ratings and step-by-step fixes.
โ๏ธ Cloud Security Reviews - I assess your cloud environment (AWS, Microsoft 365 / Entra ID, or Keycloak) to identify misconfigurations, access control gaps, and architecture risks.
๐ ISO 27001 Gap Assessment - Not sure how ready you are for ISO 27001 certification? I'll map your current security posture against the standard, highlight what's missing, and give you a clear roadmap to close the gaps.
Who I work with:
Small to mid-sized businesses, startups, and teams that take security seriously but don't have a full-time security team in-house.
You'll always get:
โ Clear eports
โ Prioritised findings
โ Practical recommendations, not just a list of problems
Working hours
- Monday:Not available
- Tuesday:Not available
- Wednesday:Not available
- Thursday:Not available
- Friday:10h00 To 18h30
- 14h00 To 14h30
- Saturday:10h00 To 18h30
- 10h00 To 14h30
- Sunday:12h00 To 20h00
- 16h00 To 16h30
- Not sure how ready you are for ISO 27001:2022 certification? I'll assess your current security posture against all ISO 27001:2022 controls โ giving you a clear picture of where you stand and a p ...
- I will deliver a professional cybersecurity awareness or training session for your team30 $ - Per hourCyber attacks don't just target systems โ they target people. I deliver engaging, practical training sessions designed to educate your team on real-world threats and build a security-conscious c ...
- A comprehensive 95% manual penetration test of your web application - simulating how a real attacker would target your system, going far beyond what automated scanners can find. Scope: * 1 web ...
- Description: I'll scan and assess your Network / web application using industry-leading tools - Nessus Professional, Burp Suite, and Qualys - to identify security weaknesses before attackers ...
I lead security assessments across web, API, LLM, desktop, and infrastructure โ specialising in manual testing of authentication, authorisation, and business logic vulnerabilities. I develop internal security tools including LLM-powered testing assistants, mentor junior engineers, and guide clients through remediation and re-testing. As an ISO 27001:2022 Certified Lead Auditor, I bring both technical depth and compliance expertise to every engagement.
Core Competencies:
Advanced VAPT, IAM Security, ISO 27001:2022 Lead Auditor, LLM Security ,Security Tool Development Malware Analysis, DevOps & Secure SDLC ,Technical Leadership
Core Competencies:
Advanced VAPT, IAM Security, ISO 27001:2022 Lead Auditor, LLM Security ,Security Tool Development Malware Analysis, DevOps & Secure SDLC ,Technical Leadership
contributing to both security and backend development. I gained practical experience in API security testing, web scraping, and backend development, while also working with DevOps practices including CI/CD pipeline setup and management. This role gave me a real-world understanding of how security integrates into modern development workflows
During my internship at Epic Lanka, I worked within a software development environment where I gained practical experience in secure coding practices and mobile application security testing. This role strengthened my understanding of how security is applied throughout the software development lifecycle
During my internship at EY, I gained hands-on experience conducting penetration testing across network infrastructure, web applications, and mobile platforms. Working within a Big 4 professional services environment, I was exposed to industry-standard methodologies and real-world client engagements
Building on my undergraduate foundation, my Master's deepened my expertise in advanced cybersecurity concepts including penetration testing methodologies, cloud security, security governance, and risk management frameworks.
I developed hands-on skills in threat intelligence, incident response, and security architecture design.
The programme also covered compliance standards such as ISO 27001, advanced network security, and research-driven approaches to emerging cyber threats
I developed hands-on skills in threat intelligence, incident response, and security architecture design.
The programme also covered compliance standards such as ISO 27001, advanced network security, and research-driven approaches to emerging cyber threats
During my degree, I built a strong foundation in information security, covering network security, ethical hacking, cryptography, and secure software development. My specialization focused on real-world cybersecurity practices including vulnerability assessment, risk management, digital forensics, and security architecture. Alongside the technical core, I also studied database systems, operating systems, and software engineering
- ๐ฌ๐ง English
Please sign in as a customer to give your feedback


