</> ENTERPRISE SECURITY ENGINEERING DOSSIER
SYS_STATUS: VERIFIED · ACTIVE ON SRI LANKA (UTC +5:30)
Induwara Nanayakkara - Engineer, Cloud and Application Security
[ PROFILE ] VERIFIED Colombo · Engineer, Cloud and AppSec
verified_user Engineer · Cloud & AppSec

Hi, I'm Induwara Nanayakkara.

Building and securing modern cloud, application, and software delivery environments through practical security engineering and DevSecOps.

pin_drop Based in Sri Lanka event_available Available for select advisory & engineering
CORE DOMAINS: Cloud Security Application Security DevSecOps Architecture Review
ENGINEERING TOPOLOGY How Security Fits Modern Engineering
LIVE FLOW

Security designed as an embedded, frictionless discipline that strengthens every stage from the local editor to active runtime defense.

01
CODE & REPO · Dev Ergonomics
SAST & SCA embedded right in PR workflows; pre-commit secrets hygiene.
02
CI/CD PIPELINE · Automated Guardrails
GitHub Actions scans, container image signing, and IaC policy verification.
03
CLOUD WORKLOAD · Multi-Cloud Estate
CSPM & CNAPP across AWS & Azure to catch drift and misconfigurations early.
04
RUNTIME DEFENSE · BFSI Self-Protection
RASP telemetry & live API guardrails actively neutralizing exploit attempts.
tune POLICY_DRIFT: ZERO-TOLERANCE INNOV8_PROD_SPEC
01 / PROFILE Human & Engineering Philosophy

About me

I am a Engineer specializing in cloud security, application security, and DevSecOps, currently working at Innov8 Pvt Ltd.

My work centers on hands-on implementation of enterprise security solutions — from securing multi-cloud environments and workloads to embedding security controls into software development and CI/CD workflows.

Day to day, I perform application security assessments using SAST and DAST methodologies, implement and administer security platforms such as Veracode, Prisma Cloud, and Zimperium, and collaborate with development, infrastructure, and security teams to establish practical secure development practices.

format_quote

"I care about security that enables delivery rather than blocking it. Pragmatic telemetry, shared developer responsibility, and verifiable posture over bureaucratic friction."

Before my current role, I worked in IT Risk and Security Operations at Allianz Insurance Lanka Limited, gaining invaluable experience within a highly regulated financial and insurance services environment.

TECHNICAL SNAPSHOT
CORE FOCUS
Cloud Security Application Security DevSecOps
CLOUD PLATFORMS
Microsoft Azure Amazon Web Services (AWS)
SECURITY METHODOLOGIES
SAST DAST SCA RASP CSPM
SECTOR & SCOPE
Enterprise Scale BFSI Regulations Production Engineering
02 / EXPERIENCE Production Engineering Record

Career timeline

2023 — PRESENT · CURRENT

Engineer – Cloud and AppSec

Innov8 Pvt Ltd · Sri Lanka

FULL-TIME ACTIVE
  • check_circle Implement and manage DevSecOps and cloud security solutions across enterprise environments.
  • check_circle Perform application security assessments using SAST and DAST methodologies.
  • check_circle Implement and administer security platforms including Veracode, Prisma Cloud, and Zimperium.
  • check_circle Secure cloud environments and workloads across Microsoft Azure and AWS.
  • check_circle Integrate security controls and scanning tools into GitHub and CI/CD workflows.
  • check_circle Monitor and improve cloud security posture management (CSPM) and vulnerability management processes.
  • check_circle Conduct security validations and provide recommendations that improve application and cloud security posture.
  • check_circle Collaborate with development, infrastructure, and security teams, automating security processes within pipelines.
Cloud Security AppSec DevSecOps CSPM SAST / DAST Vulnerability Management
PREVIOUS ROLE · REGULATED BFSI

IT Risk and Security Operations

Allianz Insurance Lanka Limited

FINANCIAL SERVICES

Hands-on experience gained in IT Risk and Security Operations within a regulated insurance environment, maintaining compliance, investigating alerts, and executing continuous operational risk assessments.

Risk Operations Security Operations Insurance Compliance
03 / SECURITY EXPERTISE Engineering Disciplines

What I work on

Security engineered as an active, integrated partner to modern product velocity, eliminating friction while elevating operational assurances.

code_blocks DISCIPLINE 01

Application Security

Finding and fixing weaknesses in software before attackers do — across source code, third-party open-source dependencies, APIs, and mobile applications.

SAST DAST SCA RASP API Security Mobile AppSec
cloud_sync DISCIPLINE 02

Cloud Security

Building pervasive visibility and policy controls across multi-cloud environments so misconfigurations, IAM over-permissions, and drift are caught early.

CSPM CNAPP Workload Protection AWS Azure
precision_manufacturing DISCIPLINE 03

DevSecOps

Shifting security left by embedding automated verification directly into delivery pipelines, turning manual security gates into fast developer self-service feedback.

CI/CD Security GitHub Integration Security Automation Policy-as-Code
shield DISCIPLINE 04

Security Engineering

Hardening underlying infrastructure, orchestrating vulnerability remediation pipelines, and governing container baselines and Infrastructure-as-Code configurations.

Vulnerability Management Infrastructure Hardening Container Security IaC Scanning
04 / APPROACH Lifecycle Engineering

How I approach security

A repeatable engineering lifecycle — security as a process, not a single tool.

01

Understand

Map assets, environments, and risk context before acting.

02

Assess

Evaluate posture through SAST, DAST, and cloud posture findings.

03

Design

Define practical controls that fit real delivery workflows.

04

Evaluate

Compare solutions against requirements through structured POCs.

05

Validate

Verify controls actually work using testing and validation tooling.

06

Implement

Integrate security into cloud platforms and CI/CD pipelines.

07

Improve

Monitor results and continuously raise the security baseline.

05 / ARCHITECTURE Defensive Mapping

Where security applies

Hover a capability to highlight the layer it protects. Illustrative architectural model, structured for clarity.

01 USER / IDENTITY LAYER
Identity & Access Governance
02 WEB & MOBILE APPLICATION
DAST RASP Mobile Threat Defense
03 API CONTRACT & GATEWAY
API Security & Token Validation
04 APPLICATION SOURCE CODE
SAST SCA (Dependency Vulnerabilities)
05 CLOUD WORKLOAD & CONTAINERS
CNAPP CSPM Runtime Protection
06 INFRASTRUCTURE & HOSTS
Continuous Vulnerability Management
07 DATA REPOSITORY & STORAGE
Audit Telemetry & Access Monitoring
06 / ECOSYSTEM Platforms & Tooling

Technology ecosystem

Professional platforms with confirmed hands-on production experience, alongside personal lab and research tooling.

APPLICATION & MOBILE

Veracode

HANDS-ON

SAST, DAST, and SCA analysis for identifying and remediating software risk.

Zimperium

HANDS-ON

Mobile threat defense and runtime protection for mobile applications.

CLOUD PLATFORMS

Prisma Cloud

HANDS-ON

CSPM and cloud workload protection across multi-cloud environments.

Wiz

HANDS-ON

Cloud-native application protection with deep posture and workload visibility.

VULN & VALIDATION

Tenable

HANDS-ON

Exposure management and vulnerability assessment across infrastructure.

Pentera

HANDS-ON

Automated security validation testing controls against real attack techniques.

ENGINEERING & LAB

GitHub

HANDS-ON

Integrated security scanning and controls into GitHub-based CI/CD workflows.

Docker / Python

PERSONAL LAB

Containerizing utilities and scripting security automation integrations.

07 / SELECTED WORK Enterprise Engagements

Security engagements

Generalized descriptions of professional engineering engagements. Customer identities, internal assets, and confidential details are intentionally omitted.

W·01 CLOUD SECURITY Cloud Security & CSPM
Case study arrow_downward
Challenge

Limited visibility of misconfigurations and posture gaps across a large multi-cloud estate.

Solution

Onboarded cloud accounts onto a CSPM platform, defined posture policies, and established continuous compliance monitoring.

My Contribution

Hands-on platform implementation and administration, working alongside infrastructure teams to drive remediation.

Outcome

Strengthened cloud security posture and an ongoing posture management practice for the enterprise environment.

Takeaway: Continuous posture visibility turns cloud misconfiguration from incident response into routine hygiene.
CSPM Azure AWS Multi-Cloud
W·02 DEVSECOPS Code Security & CI/CD Security
Case study arrow_downward
Challenge

Security needed to be embedded into the software development lifecycle without slowing delivery or adding friction.

Solution

Integrated code security scanning into GitHub-based CI/CD workflows with automated analysis and policy checks.

My Contribution

Built the integrations, triaged initial findings, and guided development teams through automated remediation.

Outcome

Security scanning became a standard part of the delivery pipeline across enterprise delivery teams.

Takeaway: Pipeline-integrated security scales far better than manual review gates ever can.
SAST SCA GitHub CI/CD Automation
W·03 APPLICATION SECURITY Enterprise RASP
Case study arrow_downward
Challenge

Production applications at a financial-sector organization needed runtime protection against active exploitation attempts.

Solution

Deployed and tuned RASP instrumentation together with the organization's core application and security teams.

My Contribution

Supported implementation, configuration, and validation of the runtime self-protection capability.

Outcome

Runtime self-protection delivered for critical enterprise workloads in the financial sector.

Takeaway: Runtime protection buys critical time in the window between prevention failing and response starting.
RASP Runtime Protection BFSI
W·04 APPSEC EVALUATION Application Security POCs
Case study arrow_downward
Challenge

BFSI organizations needed to evaluate application security solutions against real requirements before investing capital.

Solution

Scoped and executed proof-of-concept engagements with clearly defined, verifiable technical success criteria.

My Contribution

Led technical evaluations and demonstrated solution capabilities directly to security stakeholders and architects.

Outcome

Successful POCs across multiple BFSI organizations supporting informed, defensible investment decisions.

Takeaway: Well-scoped POCs with clear success criteria turn security evaluation into evidence-based decisions.
AppSec Platforms POC Design BFSI Evaluation
08 / LABS Technical Experiments

Labs & experiments

Personal lab: independent learning projects, prototypes, and technical experiments. These are not professional client engagements or production enterprise systems.

LAB·001 EXPERIMENTING

OpenCode

Exploring AI-assisted coding agents and evaluating where they fit into secure developer workflows without introducing hallucinations or supply-chain flaws.

psychology Agentic DevSecOps
LAB·002 EXPERIMENTING

Ollama

Running local language models privately on host hardware to prototype air-gapped security triage, CVE summarization, and automation ideas.

memory Local Inference Security
LAB·003 ONGOING

Python Security Automation

Writing scripts and small tools that automate repetitive audit checks, query cloud vendor REST APIs, and export compliance artifacts.

terminal Automation Utilities
LAB·004 ONGOING

Docker & DevSecOps Pipelines

Containerizing tools and assembling demo CI pipelines with integrated security scanning steps, image linting, and minimal attack surfaces.

inventory_2 Container Guardrails
LAB·005 ONGOING

Git & GitHub Workflows

Practicing protected branch policies, signed commit validation, pull request verification gates, and zero-trust repository hygiene.

merge Workflow Security
09 / EDUCATION

BSc (Hons) Computer Networks and Security

Wrexham Glyndŵr University

Undergraduate degree focused on computer networks, network protocols, defensive systems, and security fundamentals.

school Accredited Academic Qualification
10 / RESUME PRINT-READY SPEC

Curriculum Vitae & Technical Record

A structured, print-ready summary of my experience, technical focus areas, and education. Open it and choose “Save as PDF” in your browser's print dialog.

11 / CONTACT Inquiries & Advisory

Let's connect

The most reliable way to reach me is by email or LinkedIn. I am always open to discussing cloud security, application security, and DevSecOps engineering initiatives.