Cloud Security | Application Security | DevSecOps
Engineer focused on securing applications, cloud environments, and delivery pipelines through practical AppSec and DevSecOps engineering. Currently at Innov8 Pvt Ltd (May 2023 → Present), working across application, API, cloud, and infrastructure security with development, infrastructure, and security teams.
Independent security labs · synthetic vulnerabilities only · no customer or confidential data.
📍 Sri Lanka · Portfolio · LinkedIn · Email
I implement and operate enterprise security capabilities — from SAST / DAST / SCA and pipeline security to cloud security posture and vulnerability management. My work includes hands-on platform implementation, CI/CD integration, and technical evaluations / proof-of-concepts in enterprise environments.
Previously in IT Risk & Security Operations at Allianz Insurance Lanka Limited within a regulated (BFSI) environment. BSc (Hons) Computer Networks and Security — Wrexham Glyndŵr University.
| Area | What I work on |
|---|---|
| Application Security | SAST, DAST, SCA, API & Mobile AppSec — finding and fixing weaknesses in code, dependencies, and APIs |
| Cloud Security | CSPM / CNAPP, posture hardening, workload security — AWS & Azure |
| DevSecOps | CI/CD security, GitHub-native scanning, policy gates, shift-left automation |
| Security Automation | Pipeline integration, API-driven tooling, Python / Bash scripting |
| Vulnerability Management | Exposure assessment, prioritisation, remediation workflows |
| Security Architecture | Solution design, POCs, and integration across app ↔ cloud ↔ infra |
| Category | Technologies |
|---|---|
| Cloud | AWS, Microsoft Azure |
| Application Security | SAST, DAST, SCA, API Security, Mobile Application Security, RASP |
| DevSecOps | GitHub, GitHub Actions, CI/CD, Security Automation, Pipeline Security |
| Cloud Security | CSPM, CNAPP, Cloud Security Architecture, Workload Protection |
| Platforms (hands-on / lab) | Veracode — SAST / SCA / DAST · Wiz — CNAPP · Prisma Cloud — CSPM · Zimperium — Mobile · Pentera — Validation · Tenable — Exposure Management |
| Engineering | Node.js / Express, Python, Docker, SQLite, Microsoft Entra ID (OIDC) |
Vendor platforms listed as professional hands-on experience and lab experimentation — not product ownership.
🔬 veracode-sast-sca-dast-lab — Independent AppSec Lab → Repository
What it is: Intentionally vulnerable Node.js / Express application (OWASP Top 10) built to test SAST, SCA, and DAST together, with CI/CD security gates and authenticated scanning. Every vulnerability is synthetic and ships with a secure alternative.
Security problem it addresses: Teams need a safe, reproducible target to validate that SAST / SCA / DAST tooling and pipeline policies actually find what they claim — before enforcing them on production code.
Architecture
graph TD
Dev[Developer + GitHub] --> Repo[veracode-sast-sca-dast-lab<br/>src / package.json / tests]
Repo --> Render[Render Free Web Service<br/>Node.js + /health + Entra ID SSO]
Repo --> SAST[Veracode SAST<br/>source scan]
Repo --> SCA[Veracode SCA<br/>package.json / lockfile]
Render --> DAST[Veracode DAST<br/>HTTPS URL]
Entra[Microsoft Entra ID<br/>OIDC Auth Code Flow] --> Render
Stack: Node.js 20, Express, EJS, node:sqlite, Entra ID OIDC, Docker, GitHub Actions (template)
Demonstrates: Secure SDLC, shift-left scanning, SCA pinning at vulnerable versions, authenticated DAST with synthetic lab accounts, runtime safety guards (SSRF gated to own origin, exec allowlist, path-traversal jail), Docker / Render deployment.
Disclaimer: Independent lab for security engineering. Not an official Veracode product. Do not expose to real data. See
SECURITY-TESTING.mdfor scope and limitations.
A repeatable lifecycle I use in enterprise engagements — security as a process, not a single tool:
Understand → Assess → Design → Evaluate → Validate → Implement → Improve
Map assets and risk → evaluate posture (SAST / DAST / CSPM) → design controls that fit real delivery workflows → POC against success criteria → validate with testing → integrate into cloud & CI/CD → monitor and raise the baseline.
Generalised enterprise work (no customer data):
- Cloud Security & CSPM — multi-cloud posture visibility and continuous compliance monitoring
- Code & CI/CD Security — GitHub-integrated SAST / SCA with policy gates
- Runtime Protection (RASP) — production hardening in BFSI environments
- AppSec Evaluations — structured POCs with technical success criteria
Details on the Portfolio — grouped under generalised case studies.
- Cloud security posture automation and CNAPP workflows
- Strengthening DevSecOps pipelines (policy-as-code, IaC scanning)
- Security automation with Python and GitHub-native tooling
- Application and API security validation at scale
Listed as active interests — not claimed as shipped products.
- Portfolio: https://induwaran.github.io/Portfolio/ — enterprise framing and case studies
- LinkedIn: https://www.linkedin.com/in/induwara-nanayakkara-6953a422b
- GitHub: https://github.com/induwaran — labs and engineering work lives here
- Email: induwarananayakkara26@gmail.com
© Induwara Nanayakkara · Engineer — Cloud and Application Security · Cloud Security | Application Security | DevSecOps · Labs contain synthetic vulnerabilities for controlled testing only.
