Viraj Premaratne, Developer in Mackay, Queensland, Australia
Viraj is available for hire
Hire Viraj

Viraj Premaratne

Application Security Developer

Mackay, Queensland, Australia

Toptal member since February 3, 2026

Bio

Viraj is an application security leader with 9+ years of experience, including work with Uber. He partners with CISOs and engineering to reduce product risk and protect revenue by maturing secure SDLC, risk-based vulnerability remediation, and security governance. Viraj improves audit readiness and customer trust by aligning security programs with leading compliance frameworks and embedding security into delivery without slowing teams.

Portfolio

Testlio
Amazon Web Services (AWS), GitHub, CircleCI, MariaDB, PHP, TypeScript, Docker...
Uber Carshare
Amazon Web Services (AWS), GitHub, Ruby, JavaScript, Redis, Docker...
Singapore Press Holdings
PHP, JavaScript, MySQL, Docker, Amazon Web Services (AWS), GitHub, Jenkins...

Experience

  • Application Security - 9 years
  • Penetration Testing - 8 years
  • Dynamic Application Security Testing (DAST) - 8 years
  • Security Architecture - 8 years
  • Source Code Review - 8 years
  • Product Security - 7 years
  • Static Application Security Testing (SAST) - 7 years
  • ISO 27001 - 3 years

Preferred Environment

Slack, Amazon Web Services (AWS), GitHub, CircleCI, SaaS, ISO 27001, Application Security, CI/CD Pipelines, Python, IT Security, AWS Secrets Manager

The most amazing...

...thing I've done is leading an ISO 27001 certification end-to-end while uplifting application security and building lasting client trust.

Work Experience

Security Manager

2024 - PRESENT
Testlio
  • Delivered an ISO 27001:2022 certification by standing up the ISMS, coordinating evidence, and driving remediation through audit closure.
  • Implemented secure SDLC governance (security requirements, reviews, and release gates) to reduce customer-facing exposure.
  • Led a company-wide product security uplift by establishing risk-based vulnerability triage, SLAs, and executive reporting for remediation.
  • Deployed security training and secure coding enablement for 200+ staff to reduce recurring vulnerability patterns.
  • Established vendor security governance with assessment workflows and risk tracking to reduce 3rd-party-driven product risk.
  • Published a customer trust center and standardized security questionnaire responses to accelerate sales cycles and strengthen client confidence.
Technologies: Amazon Web Services (AWS), GitHub, CircleCI, MariaDB, PHP, TypeScript, Docker, Secure Software Development Lifecycle (SSDLC), Product Security, Bug Bounty Program, Penetration Testing, Cloud Security, Security, CI/CD Pipelines, Python, IT Security, NIST, Node.js, Network Segmentation, AWS IAM, Web App Security, Cybersecurity, AI Trust, Risk and Security Management (AI TRiSM), Certified Ethical Hacker (CEH), Atlassian, Slack

Application Security Specialist

2023 - 2024
Uber Carshare
  • Conducted application security assessments and translated findings into prioritized remediation plans aligned to real-world threat paths.
  • Performed threat modeling, design reviews, and code reviews to prevent high-impact vulnerabilities before release.
  • Partnered with engineering to improve secure SDLC practices, increasing consistency of security controls across services.
  • Coordinated penetration testing and ensured verified remediation through retesting and follow-up tracking.
  • Delivered developer security enablement through training, standards, and reusable guidance to improve secure implementation quality.
Technologies: Amazon Web Services (AWS), GitHub, Ruby, JavaScript, Redis, Docker, Penetration Testing, Cloud Security, Security, CI/CD Pipelines, Python, IT Security, NIST, Datadog, Network Segmentation, AWS IAM, Web App Security, Cybersecurity, AI Trust, Risk and Security Management (AI TRiSM), Certified Ethical Hacker (CEH), Atlassian, Slack

Senior Application Security Engineer

2021 - 2023
Singapore Press Holdings
  • Led application security reviews across multiple products and delivered actionable remediation guidance to engineering teams.
  • Embedded application security into delivery by introducing repeatable processes for triage, ownership, and closure of findings.
  • Improved security baselines by defining secure coding standards and reviewing implementations against them.
  • Partnered with DevOps to strengthen deployment security controls and reduce release-time security regressions.
  • Mentored engineers on secure development and improved security outcomes through targeted workshops and coaching.
Technologies: PHP, JavaScript, MySQL, Docker, Amazon Web Services (AWS), GitHub, Jenkins, Penetration Testing, Cloud Security, Security, CI/CD Pipelines, Python, IT Security, NIST, Network Segmentation, Web App Security, Cybersecurity, Certified Ethical Hacker (CEH), Atlassian, Slack

Senior Information Security Engineer

2020 - 2021
Sysco LABS Sri Lanka
  • Led cloud and product security risk assessments and presented prioritized remediation plans to senior stakeholders.
  • Improved product security controls by strengthening security testing coverage and integrating findings into remediation workflows.
  • Supported compliance-driven security for payment-related environments by aligning controls, evidence, and remediation activities.
  • Developed governance artifacts (policies, standards, procedures) that improved security consistency across teams.
  • Performed incident response and post-incident improvements that reduced recurrence through control and process changes.
  • Ensured PCI-DSS compliance for products and supported compliance-driven security controls.
Technologies: Java, JavaScript, MySQL, Docker, Amazon Web Services (AWS), Bitbucket, Jenkins, PCI DSS, Penetration Testing, Cloud Security, Security, CI/CD Pipelines, Python, IT Security, NIST, PCI, Node.js, Grafana, Prometheus, Network Segmentation, AWS IAM, Web App Security, Cybersecurity, Certified Ethical Hacker (CEH), Atlassian, Slack

Information Security Engineer

2016 - 2020
TechCERT
  • Designed a WebTrust 2.0-compliant PKI (MS ADCS) environment, ensuring scalability, cost-effectiveness, and high availability.
  • Deployed monitoring to improve the availability and operational visibility of the PKI infrastructure.
  • Conducted CIS-benchmark server hardening and delivered incident response support for client environments.
  • Performed security assessments (system, web, wireless, cloud) and provided forensic and malware analysis support.
Technologies: Amazon Web Services (AWS), QualysGuard, Acunetix, Nessus, Security Architecture, Network Security Monitoring, Penetration Testing, Security, Python, IT Security, NIST, PCI, Network Segmentation, Web App Security, Cybersecurity

Experience

Application Security Program and Vulnerability Management

I led a company-wide application security uplift by establishing a structured vulnerability management program across engineering repositories. I implemented SAST, SCA, and Infrastructure-as-Code scanning using Snyk, enabling consistent detection of code and dependency risks and improving visibility into security debt.

I also introduced governance for triage and remediation by categorizing findings and prioritizing client-facing/public endpoints first to reduce exposure and blast radius. I set up a clear workflow to assign issues to the proper engineering channels, track remediation progress, and improve closure predictability. I also coordinated periodic internal penetration testing to validate controls and uncover gaps not detected by automated tooling, and revamped the bug bounty process with defined SLAs, improved reporter communication, and clearer internal ownership to ensure timely, professional handling of inbound reports. Additionally, I complemented the program with developer security enablement, including secure coding training and practical guidelines for secure coding.

ISO 27001:2022 Certification Program and Security Maturity Uplift

https://trust.testlio.com/
This project involved leading Testlio's ISO 27001:2022 certification program end-to-end, owning planning, execution, and audit readiness. I selected and implemented a compliance automation platform to reduce evidence-collection overhead and improve control traceability. I also designed and rolled out key controls across device management, asset inventory/registry, 3rd-party/vendor security management, operational security, and HR security (onboarding/offboarding).

I built and delivered security and privacy training for 200+ staff, increasing awareness and adoption of standardized processes, and partnered closely with the external audit team to ensure accurate scoping and evidence quality. I also drove remediation, so the final audit report reflected no unresolved high-severity issues. I also launched a trust center to strengthen customer confidence and support sales/prospect engagement, while institutionalizing policies, procedures, and governance to measurably elevate overall security maturity.

Bug Bounty & Vulnerability Disclosure (HackerOne/Intigriti Recognition)

Conducted vulnerability research and responsible disclosure across multiple programs, contributing to real-world security improvements in production systems. Achieved quarterly Top 10 leaderboard ranking on Intigriti and maintained verified vulnerability submissions on HackerOne under my profile. Reported and validated impactful issues through coordinated disclosure, including identifying a critical vulnerability in a public-sector endpoint that was acknowledged by the Netherlands government. Demonstrated strong triage discipline, clear technical write-ups, and professional communication with security teams to drive timely remediation and measurable risk reduction.

LankaSign – Sri Lanka Commercial Digital Certificate Issuance System

https://lankasign.lankapay.net/
I led the delivery of Sri Lanka's first commercial digital certificate-issuing platform, serving as both project manager and hands-on engineer. I owned the full lifecycle from RFP and stakeholder alignment through architecture, build, deployment, testing, and ongoing operations.

The project included implementing secure PKI certificate issuance and lifecycle processes on Microsoft Active Directory Certificate Services (AD CS), aligned to WebTrust principles for CA operations (governance, access control, auditing, and operational rigor). I also designed high availability with site-to-site replication and established a DR site, defining runbooks and conducting regular DR drills to validate recovery readiness. Additionally, I managed key lifecycle activities, including secure key ceremony coordination and controls to ensure integrity, continuity, and service availability.

Education

2013 - 2016

Bachelor's Degree in Computer Engineering

University of Peradeniya - Sri Lanka

Certifications

JANUARY 2021 - JANUARY 2023

Microsoft Certified: Azure Administrator Associate

Microsoft

DECEMBER 2020 - DECEMBER 2023

AWS Certified Security – Specialty

Amazon Web Services

SEPTEMBER 2020 - SEPTEMBER 2023

AWS Solutions Architect Associate

Amazon Web Services

MAY 2018 - MAY 2021

Certified Ethical Hacker (CEH)

EC-Council

Skills

Libraries/APIs

Node.js

Tools

Atlassian, AWS IAM, Slack, GitHub, CircleCI, Jenkins, Bitbucket, Acunetix, Nessus, Grafana

Paradigms

Penetration Testing, Security Software Development

Platforms

Vanta, Amazon Web Services (AWS), Docker, Azure, Windows Server, QualysGuard

Industry Expertise

Cybersecurity

Languages

PHP, TypeScript, Ruby, JavaScript, Java, Python

Storage

MariaDB, Redis, MySQL, Datadog

Other

Bug Bounty Program, PKI, Digital Certificates, Security Architecture, IT Project Management, ISO 27001, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Snyk, Vulnerability Triage, Cloud Security, Security, IT Security, Network Segmentation, Web App Security, Application Security, Vulnerability Management, Source Code Review, Secure Coding, Developer Security Training, CI/CD Pipelines, NIST, PCI, AWS Secrets Manager, Threat Modeling, Certified Ethical Hacker (CEH), Software Development, Computer Engineering, Electronics, Secure Software Development Lifecycle (SSDLC), Product Security, Burp Proxy, Active Directory Certificate Services (AD CS), X.509, Transport Layer Security (TLS), SSL, High Availability (HA), Business Continuity & Disaster Recovery (BCDR), Request for Proposal (RFP), Deployment, Operations, Vendor Management, Monitoring, Documentation, Information Security Management Systems (ISMS), Compliance Automation, Security Governance, Risk Management, Audit Management, Trust Center, Detectify, Threat Analysis and Risk Assessment (TARA), SaaS, PCI DSS, Network Security Monitoring, Prometheus, Security Research, AI Trust, Risk and Security Management (AI TRiSM)

Collaboration That Works

How to Work with Toptal

Toptal matches you directly with global industry experts from our network in hours—not weeks or months.

1

Share your needs

Discuss your requirements and refine your scope in a call with a Toptal domain expert.
2

Choose your talent

Get a short list of expertly matched talent within 24 hours to review, interview, and choose from.
3

Start your risk-free talent trial

Work with your chosen talent on a trial basis for up to two weeks. Pay only if you decide to hire them.

Top talent is in high demand.

Start hiring