Skip to content
View induwaran's full-sized avatar

Block or report induwaran

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
induwaran/README.md

Induwara Nanayakkara

Engineer — Cloud and Application Security

Cloud Security | Application Security | DevSecOps

Engineer focused on securing applications, cloud environments, and delivery pipelines through practical AppSec and DevSecOps engineering. Currently at Innov8 Pvt Ltd (May 2023 → Present), working across application, API, cloud, and infrastructure security with development, infrastructure, and security teams.

Independent security labs · synthetic vulnerabilities only · no customer or confidential data.

📍 Sri Lanka · Portfolio · LinkedIn · Email


About

I implement and operate enterprise security capabilities — from SAST / DAST / SCA and pipeline security to cloud security posture and vulnerability management. My work includes hands-on platform implementation, CI/CD integration, and technical evaluations / proof-of-concepts in enterprise environments.

Previously in IT Risk & Security Operations at Allianz Insurance Lanka Limited within a regulated (BFSI) environment. BSc (Hons) Computer Networks and Security — Wrexham Glyndŵr University.


Security Engineering Focus

Area What I work on
Application Security SAST, DAST, SCA, API & Mobile AppSec — finding and fixing weaknesses in code, dependencies, and APIs
Cloud Security CSPM / CNAPP, posture hardening, workload security — AWS & Azure
DevSecOps CI/CD security, GitHub-native scanning, policy gates, shift-left automation
Security Automation Pipeline integration, API-driven tooling, Python / Bash scripting
Vulnerability Management Exposure assessment, prioritisation, remediation workflows
Security Architecture Solution design, POCs, and integration across app ↔ cloud ↔ infra

Technical Stack

Category Technologies
Cloud AWS, Microsoft Azure
Application Security SAST, DAST, SCA, API Security, Mobile Application Security, RASP
DevSecOps GitHub, GitHub Actions, CI/CD, Security Automation, Pipeline Security
Cloud Security CSPM, CNAPP, Cloud Security Architecture, Workload Protection
Platforms (hands-on / lab) Veracode — SAST / SCA / DAST · Wiz — CNAPP · Prisma Cloud — CSPM · Zimperium — Mobile · Pentera — Validation · Tenable — Exposure Management
Engineering Node.js / Express, Python, Docker, SQLite, Microsoft Entra ID (OIDC)

Vendor platforms listed as professional hands-on experience and lab experimentation — not product ownership.


Featured Engineering Work

🔬 veracode-sast-sca-dast-lab — Independent AppSec Lab → Repository

What it is: Intentionally vulnerable Node.js / Express application (OWASP Top 10) built to test SAST, SCA, and DAST together, with CI/CD security gates and authenticated scanning. Every vulnerability is synthetic and ships with a secure alternative.

Security problem it addresses: Teams need a safe, reproducible target to validate that SAST / SCA / DAST tooling and pipeline policies actually find what they claim — before enforcing them on production code.

Architecture

graph TD
  Dev[Developer + GitHub] --> Repo[veracode-sast-sca-dast-lab<br/>src / package.json / tests]
  Repo --> Render[Render Free Web Service<br/>Node.js + /health + Entra ID SSO]
  Repo --> SAST[Veracode SAST<br/>source scan]
  Repo --> SCA[Veracode SCA<br/>package.json / lockfile]
  Render --> DAST[Veracode DAST<br/>HTTPS URL]
  Entra[Microsoft Entra ID<br/>OIDC Auth Code Flow] --> Render
Loading

Stack: Node.js 20, Express, EJS, node:sqlite, Entra ID OIDC, Docker, GitHub Actions (template) Demonstrates: Secure SDLC, shift-left scanning, SCA pinning at vulnerable versions, authenticated DAST with synthetic lab accounts, runtime safety guards (SSRF gated to own origin, exec allowlist, path-traversal jail), Docker / Render deployment.

Disclaimer: Independent lab for security engineering. Not an official Veracode product. Do not expose to real data. See SECURITY-TESTING.md for scope and limitations.


How I Approach Security

A repeatable lifecycle I use in enterprise engagements — security as a process, not a single tool:

Understand → Assess → Design → Evaluate → Validate → Implement → Improve

Map assets and risk → evaluate posture (SAST / DAST / CSPM) → design controls that fit real delivery workflows → POC against success criteria → validate with testing → integrate into cloud & CI/CD → monitor and raise the baseline.

Generalised enterprise work (no customer data):

  • Cloud Security & CSPM — multi-cloud posture visibility and continuous compliance monitoring
  • Code & CI/CD Security — GitHub-integrated SAST / SCA with policy gates
  • Runtime Protection (RASP) — production hardening in BFSI environments
  • AppSec Evaluations — structured POCs with technical success criteria

Details on the Portfolio — grouped under generalised case studies.


Currently Exploring

  • Cloud security posture automation and CNAPP workflows
  • Strengthening DevSecOps pipelines (policy-as-code, IaC scanning)
  • Security automation with Python and GitHub-native tooling
  • Application and API security validation at scale

Listed as active interests — not claimed as shipped products.


Connect


© Induwara Nanayakkara · Engineer — Cloud and Application Security · Cloud Security | Application Security | DevSecOps · Labs contain synthetic vulnerabilities for controlled testing only.

Popular repositories Loading

  1. Veracode-Demo Veracode-Demo Public

    Fork reference — Veracode VeraDemo (Blab-a-Gag) — intentionally vulnerable Java app for SAST/DAST comparison

    Java 1

  2. veracode veracode Public

    Fork reference — Veracode GitHub Workflow Integration — repo scanning pipeline reference

    JavaScript

  3. Portfolio Portfolio Public

    Portfolio site — Engineer, Cloud and Application Security — Cloud Security | Application Security | DevSecOps

    HTML

  4. Check-llm-compatibility Check-llm-compatibility Public

    Lab utility — Ubuntu LLM compatibility benchmark (Ollama/llama.cpp/vLLM) — Python + Bash

    Python

  5. veracode-sast-sca-dast-lab veracode-sast-sca-dast-lab Public

    Independent AppSec lab — vulnerable Node.js/Express app for Veracode SAST+SCA+DAST (OWASP Top 10) — synthetic, containerised

    JavaScript

  6. induwaran induwaran Public

    Profile README — Engineer, Cloud and Application Security