Focus on a Chartered Security Professional Ornela Perera CSyP
We continue our CSyP profile series with Ornela Perera CSyP, whose career spans complex, high-risk environments across infrastructure and government. She reflects on her journey into the profession, the realities of senior-level security work, and the value of Chartered status.
Q Tell us something about your early career and how you became a security professional
Honestly, I didn’t set out to be a security professional – the title found me. My early career was spent in environments where decision making, risk awareness, and operational delivery weren’t neat boxes on an org chart; they were the same thing. I learned quickly that getting things done in complex, high-risk settings meant treating security as part of the fabric of the work, not a separate conversation that happened in a different meeting room.
Moving into consultancy formalised the way I already thought. Working with critical infrastructure and government clients sharpens the mind, because the consequences of poor security design tend to be visible, expensive and, occasionally, on the front page. Across transport, defence, nuclear and large-scale infrastructure, the consistent thread in my work has been translating risk into something deliverable, something that survives contact with programme, cost and the people who actually have to operate it.
Q What relevant training and qualifications have contributed to your success?
A combination of formal qualifications and the kind of learning that only comes from doing the work. Achieving CSyP status was a significant milestone, not just as recognition, but as a forcing function to articulate impact, leadership, and professional judgement. Complementary qualifications such as CSMP Level 6 and RSES have strengthened both technical depth and professional credibility.
But I would be misleading anyone if I said the qualifications did the heavy lifting. The most valuable learning has come from delivery: working through ambiguity, mediating between stakeholders who all believe their requirement is the priority, and making decisions where there is no perfect answer – only a defensible one. That isn’t something you can study for.
Q Were you inspired or mentored by any individuals along the way?
Mentorship has played an important role throughout my career, though rarely in a formal sense. I have worked alongside people who challenged assumptions, pushed for higher standards, and demonstrated what effective leadership looks like under pressure. You absorb that sort of thing without realising. It has shaped how I now approach my own role – developing others, setting clear expectations, and keeping a focus on outcomes rather than process for its own sake. Process is essential, but it isn’t the point.
Q Do you have any career highlights to share?
I have been fortunate to work on some genuinely interesting programmes, but the highlights I value most aren’t individual projects – they’re the level of responsibility and influence I have been trusted with along the way. Leading security inputs on nationally significant infrastructure, shaping strategies at scale, and – perhaps most rewarding – building capability within teams so that the next generation of practitioners is better equipped than mine was. Those are the markers of progression that matter to me.
If I had to name the single skill I keep coming back to, it would be the ability to operate credibly with senior stakeholders while still being able to engage with the technical detail. That’s where the real value sits, and it’s also, not coincidentally, where most of the interesting problems live.
Q Why would you recommend others becoming registered?
I would strongly recommend becoming professionally registered. The external validation matters – clients and colleagues take it seriously – the more interesting effect is internal. Registration forces you to be clear about what you stand for as a practitioner, how you add value, and where your professional limits sit. That clarity is genuinely useful, and surprisingly hard to arrive at without something like CSyP pushing you towards it.
It also does something quieter but important: it raises the bar for the profession as a whole. The more practitioners who hold themselves to a recognised standard, the harder it becomes for poor practice to pass unchallenged.
Q What advice would you give to those beginning their CSyP journey?
Focus on substance over form. The application process can feel administratively heavy, but underneath it is a straightforward question: can you demonstrate, with evidence, that you operate at the level the profession expects? If the answer is yes, the paperwork is just the paperwork.
Beyond that, build real experience across different environments. Understand how security integrates with business objectives, because if you can’t articulate that, technical knowledge alone won’t carry you. Learn to communicate clearly at every level, from the engineer in the site office to the director who has fifteen minutes between meetings. Progression in this profession comes from judgement, credibility, and the ability to influence decisions, not from knowing the most acronyms in the room.
And don’t be in a rush. CSyP is a recognition of where you already are, not a shortcut to where you would like to be.
Find out more about becoming a
Chartered Security Professional on the Security Institute website:
www.security-institute.org/csyp
