
Viraj Premaratne
Verified Expert in Engineering
Application Security Developer
Mackay, Queensland, Australia
Toptal member since February 3, 2026
Viraj is an application security leader with 9+ years of experience, including work with Uber. He partners with CISOs and engineering to reduce product risk and protect revenue by maturing secure SDLC, risk-based vulnerability remediation, and security governance. Viraj improves audit readiness and customer trust by aligning security programs with leading compliance frameworks and embedding security into delivery without slowing teams.
Portfolio
Experience
- Application Security - 9 years
- Penetration Testing - 8 years
- Dynamic Application Security Testing (DAST) - 8 years
- Security Architecture - 8 years
- Source Code Review - 8 years
- Product Security - 7 years
- Static Application Security Testing (SAST) - 7 years
- ISO 27001 - 3 years
Preferred Environment
Slack, Amazon Web Services (AWS), GitHub, CircleCI, SaaS, ISO 27001, Application Security, CI/CD Pipelines, Python, IT Security, AWS Secrets Manager
The most amazing...
...thing I've done is leading an ISO 27001 certification end-to-end while uplifting application security and building lasting client trust.
Work Experience
Security Manager
Testlio
- Delivered an ISO 27001:2022 certification by standing up the ISMS, coordinating evidence, and driving remediation through audit closure.
- Implemented secure SDLC governance (security requirements, reviews, and release gates) to reduce customer-facing exposure.
- Led a company-wide product security uplift by establishing risk-based vulnerability triage, SLAs, and executive reporting for remediation.
- Deployed security training and secure coding enablement for 200+ staff to reduce recurring vulnerability patterns.
- Established vendor security governance with assessment workflows and risk tracking to reduce 3rd-party-driven product risk.
- Published a customer trust center and standardized security questionnaire responses to accelerate sales cycles and strengthen client confidence.
Application Security Specialist
Uber Carshare
- Conducted application security assessments and translated findings into prioritized remediation plans aligned to real-world threat paths.
- Performed threat modeling, design reviews, and code reviews to prevent high-impact vulnerabilities before release.
- Partnered with engineering to improve secure SDLC practices, increasing consistency of security controls across services.
- Coordinated penetration testing and ensured verified remediation through retesting and follow-up tracking.
- Delivered developer security enablement through training, standards, and reusable guidance to improve secure implementation quality.
Senior Application Security Engineer
Singapore Press Holdings
- Led application security reviews across multiple products and delivered actionable remediation guidance to engineering teams.
- Embedded application security into delivery by introducing repeatable processes for triage, ownership, and closure of findings.
- Improved security baselines by defining secure coding standards and reviewing implementations against them.
- Partnered with DevOps to strengthen deployment security controls and reduce release-time security regressions.
- Mentored engineers on secure development and improved security outcomes through targeted workshops and coaching.
Senior Information Security Engineer
Sysco LABS Sri Lanka
- Led cloud and product security risk assessments and presented prioritized remediation plans to senior stakeholders.
- Improved product security controls by strengthening security testing coverage and integrating findings into remediation workflows.
- Supported compliance-driven security for payment-related environments by aligning controls, evidence, and remediation activities.
- Developed governance artifacts (policies, standards, procedures) that improved security consistency across teams.
- Performed incident response and post-incident improvements that reduced recurrence through control and process changes.
- Ensured PCI-DSS compliance for products and supported compliance-driven security controls.
Information Security Engineer
TechCERT
- Designed a WebTrust 2.0-compliant PKI (MS ADCS) environment, ensuring scalability, cost-effectiveness, and high availability.
- Deployed monitoring to improve the availability and operational visibility of the PKI infrastructure.
- Conducted CIS-benchmark server hardening and delivered incident response support for client environments.
- Performed security assessments (system, web, wireless, cloud) and provided forensic and malware analysis support.
Experience
Application Security Program and Vulnerability Management
I also introduced governance for triage and remediation by categorizing findings and prioritizing client-facing/public endpoints first to reduce exposure and blast radius. I set up a clear workflow to assign issues to the proper engineering channels, track remediation progress, and improve closure predictability. I also coordinated periodic internal penetration testing to validate controls and uncover gaps not detected by automated tooling, and revamped the bug bounty process with defined SLAs, improved reporter communication, and clearer internal ownership to ensure timely, professional handling of inbound reports. Additionally, I complemented the program with developer security enablement, including secure coding training and practical guidelines for secure coding.
ISO 27001:2022 Certification Program and Security Maturity Uplift
https://trust.testlio.com/I built and delivered security and privacy training for 200+ staff, increasing awareness and adoption of standardized processes, and partnered closely with the external audit team to ensure accurate scoping and evidence quality. I also drove remediation, so the final audit report reflected no unresolved high-severity issues. I also launched a trust center to strengthen customer confidence and support sales/prospect engagement, while institutionalizing policies, procedures, and governance to measurably elevate overall security maturity.
Bug Bounty & Vulnerability Disclosure (HackerOne/Intigriti Recognition)
LankaSign – Sri Lanka Commercial Digital Certificate Issuance System
https://lankasign.lankapay.net/The project included implementing secure PKI certificate issuance and lifecycle processes on Microsoft Active Directory Certificate Services (AD CS), aligned to WebTrust principles for CA operations (governance, access control, auditing, and operational rigor). I also designed high availability with site-to-site replication and established a DR site, defining runbooks and conducting regular DR drills to validate recovery readiness. Additionally, I managed key lifecycle activities, including secure key ceremony coordination and controls to ensure integrity, continuity, and service availability.
Education
Bachelor's Degree in Computer Engineering
University of Peradeniya - Sri Lanka
Certifications
Microsoft Certified: Azure Administrator Associate
Microsoft
AWS Certified Security – Specialty
Amazon Web Services
AWS Solutions Architect Associate
Amazon Web Services
Certified Ethical Hacker (CEH)
EC-Council
Skills
Libraries/APIs
Node.js
Tools
Atlassian, AWS IAM, Slack, GitHub, CircleCI, Jenkins, Bitbucket, Acunetix, Nessus, Grafana
Paradigms
Penetration Testing, Security Software Development
Platforms
Vanta, Amazon Web Services (AWS), Docker, Azure, Windows Server, QualysGuard
Industry Expertise
Cybersecurity
Languages
PHP, TypeScript, Ruby, JavaScript, Java, Python
Storage
MariaDB, Redis, MySQL, Datadog
Other
Bug Bounty Program, PKI, Digital Certificates, Security Architecture, IT Project Management, ISO 27001, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Snyk, Vulnerability Triage, Cloud Security, Security, IT Security, Network Segmentation, Web App Security, Application Security, Vulnerability Management, Source Code Review, Secure Coding, Developer Security Training, CI/CD Pipelines, NIST, PCI, AWS Secrets Manager, Threat Modeling, Certified Ethical Hacker (CEH), Software Development, Computer Engineering, Electronics, Secure Software Development Lifecycle (SSDLC), Product Security, Burp Proxy, Active Directory Certificate Services (AD CS), X.509, Transport Layer Security (TLS), SSL, High Availability (HA), Business Continuity & Disaster Recovery (BCDR), Request for Proposal (RFP), Deployment, Operations, Vendor Management, Monitoring, Documentation, Information Security Management Systems (ISMS), Compliance Automation, Security Governance, Risk Management, Audit Management, Trust Center, Detectify, Threat Analysis and Risk Assessment (TARA), SaaS, PCI DSS, Network Security Monitoring, Prometheus, Security Research, AI Trust, Risk and Security Management (AI TRiSM)
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring