Jobiglo

No results.

Unlock this candidate profile

Sign up free as a recruiter to view the full CV, contact info and reach out to this candidate.

?

3 years of experience

Skills

ISO 27001 implementation GDPR compliance Business Continuity Planning (BCP) Disaster Recovery Planning (DRP) Nessus vulnerability scanning VAPT projects PCI DSS compliance SOC 2 review SWIFT CSP coordination KPI dashboard & cyber scorecards Zero Trust framework Risk assessment & mitigation Audit planning & execution Strong communication Analytical thinking

Experience

Senior Banking Assistant - Information Security GRC

Nations Trust Bank PLC

2023-03 -

Ensures compliance with regulatory requirements for technology risk management, payment‑related mobile applications and SWIFT CSP, coordinating internal and external audits. Leads ISO 27001 internal and surveillance audits, updates ISMS policies and drives KPI dashboard and cyber scorecard reporting aligned with Zero Trust principles. Conducts third‑party vendor due‑diligence, risk assessments and develops security training modules for staff and vendors. Reviews SOC 2 reports for cloud service providers and oversees PCI DSS V4.01 compliance using a prioritized approach.

Senior Operations Assistant - Information Systems Audit

Citizens Development Business Finance PLC

2022-12 - 2023-03

Prepared control checklists based on the Personal Data Protection Act and performed ISO 27001 ISMS review follow‑up activities. Executed IT general control audits, quarterly spot audits of server and generator rooms, and application control testing for savings, fixed deposits and cash‑back loans. Analyzed system logs of critical applications and supported audit reporting.

Operations Assistant - Information Systems Audit

Citizens Development Business Finance PLC

2022-05 - 2022-12

Prepared regulatory framework checklists for technology risk management and resilience in licensed banks. Conducted ISO 27001 ISMS reviews, created asset inventories, and performed IT general control audits. Tested application controls on lending modules and carried out quarterly spot audits of server, switch and generator rooms.

Information Security Trainee Analyst - GRC

KPMG Sri Lanka

2019-01 - 2019-08

Implemented and reviewed security standards, policies and procedures for software development companies, financial institutions and manufacturing firms. Provided consultancy for ISO/IEC 27001:2013 ISMS implementation and performed ISO 27001 audits and audit reviews. Conducted Nessus scans for VAPT projects, reviewed PCI DSS compliance checklists and assisted in preparing risk assessment reports.

Information Security Internship

KPMG Sri Lanka

2018-07 - 2019-01

Developed client‑facing ISO/IEC 27001:2013 implementations and performed Nessus vulnerability scans on client servers for VAPT engagements. Reviewed PCI DSS compliance checklists, assisted in report generation and risk assessments, and studied GDPR, business continuity planning and disaster recovery processes.

Languages

English

fluent

Contact candidate

Last updated: 1 day ago