SR
Shehan Rathnayake
Consultant - Cyber Security and Digital Trust at KPMG Sri Lanka
Colombo, Sri LankaWork Experience
Consultant - Cyber Security and Digital Trust
KPMG Sri Lanka
Jan 2025 - Present -5 months
Sri Lanka
- Job Details:Conducted cybersecurity resilience reviews for a banking client based on ISO/IEC 27001, NIST CSF, NIST SP 800-53, and NIST SP 800-160 frameworks. Led teams in conducting regulatory and compliance reviews, supporting stakeholders with guidance to meet sector-specific cybersecurity and regulatory obligations. Led teams and participated in the implementation of ISO/IEC 27001:2022 within the banking sector, including control deployment, documentation, and stakeholder engagement. Led teams in ISO/IEC 27001:2022 internal audits and supported stakeholders in identifying root causes of nonconformities, and planning corrective actions to address them. Led teams and executed third-party security assessments for clients, identifying control weaknesses and providing actionable recommendations. Led teams in conducting information security risk assessments and supported clients with risk treatment planning. Led teams in conducting scenario-based incident response testing to assess organizational preparedness and enhance response capabilities. Led teams in developing information security policies and procedures aligned with international standards and tailored to client environments.
Associate Consultant - Cyber Security and Digital Trust
KPMG Sri Lanka
Jan 2024 - Jan 2025 -1 yr
Sri Lanka
- Job Details:Led teams and conducted information security risk assessments, cybersecurity and information security reviews, and IT general controls reviews across government-critical infrastructure, public sector organizations, and private businesses. Experienced in ISO 27001:2022 implementation and transition engagements across banking, energy, and utilities sectors. Gained experience as an ISO 27001:2022 lead auditor, conducting audits for various sectors such as banking, information technology, and business process outsourcing. Led and conducted regulatory compliance reviews, providing recommendations to stakeholders on how to meet sector-specific cybersecurity and regulatory requirements. Conducted information security risk assessments and third-party security assessments, identifying potential risks and vulnerabilities while recommending strategies to mitigate them. Led and performed user access reviews of clients systems to ensure proper access controls and compliance with internal policies and external regulations. Developed, reviewed, and updated information security policies; delivered awareness training sessions to support client compliance and risk reduction. Conducted business continuity planning (BCP) and disaster recovery planning (DRP) reviews, identifying gaps and providing recommendations.
Trainee Analyst - Cyber Security
KPMG Sri Lanka
Nov 2022 - Dec 2023 -1 yr, 1 month
Sri Lanka
- Job Details:Experienced in ISO 27001 implementation and audits for various business sectors. Experienced in conducting SOC2 Type 2 attestation. Conducted IT general controls reviews for various sectors including financial, manufacturing, technology, retail, hospitality, construction, consulting, agriculture etc.
KPMG Sri Lanka
May 2022 - Nov 2022 -6 months
Sri Lanka
- Job Details:Developed business continuity plans and disaster recovery plans including business impact. Conducted various engagements such as ISO 27001 audits, risk assessments, cybersecurity and information security reviews, IT general control reviews, policy and procedure reviews and privileged user access reviews.
Education
Bachelor's Degree in Cyber Security
Sri Lanka Institute of Information Technology (SLIIT)Jan 2019 - Jan 2022 - 3 yr
Skills
- ISO 27001 implementation and audits
- Cybersecurity and information security reviews
- ISO 27001
- IT Audit
- Information Security Audit
- iSO 22301
- Regulatory and compliance reviews
- Information security risk assessments and treatment planning
- Third-party security assessments
- SOC2 attestation
View More
Languages
English
Fluent