Desbloquea este perfil
Regístrate gratis como reclutador para ver el CV completo, los datos de contacto y contactar al candidato.
Competencias
Experiencia
Senior Banking Assistant - Information Security GRC
Nations Trust Bank PLC
2023-03 -
Ensures compliance with regulatory requirements for technology risk management, payment‑related mobile applications and SWIFT CSP, coordinating internal and external audits. Leads ISO 27001 internal and surveillance audits, updates ISMS policies and drives KPI dashboard and cyber scorecard reporting aligned with Zero Trust principles. Conducts third‑party vendor due‑diligence, risk assessments and develops security training modules for staff and vendors. Reviews SOC 2 reports for cloud service providers and oversees PCI DSS V4.01 compliance using a prioritized approach.
Senior Operations Assistant - Information Systems Audit
Citizens Development Business Finance PLC
2022-12 - 2023-03
Prepared control checklists based on the Personal Data Protection Act and performed ISO 27001 ISMS review follow‑up activities. Executed IT general control audits, quarterly spot audits of server and generator rooms, and application control testing for savings, fixed deposits and cash‑back loans. Analyzed system logs of critical applications and supported audit reporting.
Operations Assistant - Information Systems Audit
Citizens Development Business Finance PLC
2022-05 - 2022-12
Prepared regulatory framework checklists for technology risk management and resilience in licensed banks. Conducted ISO 27001 ISMS reviews, created asset inventories, and performed IT general control audits. Tested application controls on lending modules and carried out quarterly spot audits of server, switch and generator rooms.
Information Security Trainee Analyst - GRC
KPMG Sri Lanka
2019-01 - 2019-08
Implemented and reviewed security standards, policies and procedures for software development companies, financial institutions and manufacturing firms. Provided consultancy for ISO/IEC 27001:2013 ISMS implementation and performed ISO 27001 audits and audit reviews. Conducted Nessus scans for VAPT projects, reviewed PCI DSS compliance checklists and assisted in preparing risk assessment reports.
Information Security Internship
KPMG Sri Lanka
2018-07 - 2019-01
Developed client‑facing ISO/IEC 27001:2013 implementations and performed Nessus vulnerability scans on client servers for VAPT engagements. Reviewed PCI DSS compliance checklists, assisted in report generation and risk assessments, and studied GDPR, business continuity planning and disaster recovery processes.
Idiomas
English
fluent
Ultima actualizacion: hace 1 día