Associate Professor Nalin Arachchilage

Associate Professor Nalin Arachchilage

Associate Professor in Cyber Security

Details

Open to

  • Masters Research or PhD student supervision
  • Media enquiries
  • Collaborative projects
  • Industry Projects
  • Join a web conference as a panellist or speaker
  • Membership of an advisory committee
  • Mentoring (long-term)

About

Dr Nalin Arachchilage is an Associate Professor in Cyber Security in the School of Computing Technologies at RMIT University, Australia and a member of the RMIT University Centre for Cyber Security Research and Innovation (CCSRI). As part of his leadership role, he is currently overseeing the revamp of the Master of Cyber Security program at RMIT University, working collaboratively with other schools to develop a cutting-edge, culturally inclusive curriculum. He held an Honorary Associate Professorship in Cyber Security at the University of Warwick, UK. Besides, Nalin also serves as a Technical Advisor (Board of Advisors) to DEFSAFE Cyber Security Inc., New Zealand, where his responsibilities include providing technical advice/consultancies to develop various cyber-security-related products (e.g., novel training interventions) and other activities related to the advisor role at DEFSAFE Cyber Security Inc.

Previously, he was a Senior Lecturer (2021 - 2024) in Cyber Security at the University of Auckland, New Zealand, where he served as an Assistant Head of School (Research), and a Director and Coordinator of the Master of Professional Studies (MProfStuds) in Digital Security Programme. He was also a Senior Research Fellow in Cyber Security (2019 - 2021) at La Trobe University, Australia. Before joining La Trobe, Nalin worked as a Lecturer in Cyber Security (from 2015 to 2019) and then as a Visiting Researcher (2019 - 2021) in the School of Engineering and Information Technology of the University of New South Wales at the Australian Defence Force Academy (ADFA), where he led the Usable Security Engineering research group. Nalin holds a PhD in Computer Science (Cyber Security) from Brunel University London, UK, where he developed a game design framework for teaching people how to protect themselves from phishing attacks. At Oxford University, he cut his teeth as a Postdoctoral Researcher in Systems Security Engineering (2013 - 2014) in the Department of Computer Science and then joined the University of British Columbia (UBC), Canada, as a Postdoctoral Research Fellow in Usable Security and Privacy (2014 - 2015). Nalin's primary research interests are at the intersection of computer security, Human-Computer Interaction (HCI), Software Engineering, Information Systems Security, Machine Learning (ML), Natural Language Processing (NLP), and Serious Games, in an area known as Usable Security and Privacy Engineering. He has been serving on numerous world's leading cyber security and privacy conferences including several flagship conferences. Program Committee Member (usable security and privacy track): 

  • ACM CCS - 2022, 2023, 2024
  • AsiaCCS - 2023, 2024
  • USEC 2025
  • SOUPS - 2018, 2021, 2022, 2023, 2024
  • CSCW [Associate Chair] - 2019, 2020, 2021, 2022, 2023, 2024
  • ACM FAccT - 2022
  • ACM CSCW Awards Committee member - 2023
  • SOUPS Karat Award Chair - 2021
  • USENIX SOUPS Mentor - 2020
  • SOUPS Publicity Co-Chair - 2018, 2019
  • EASE Poster Chair - 2019
  • CHI 2019 Late Breaking Work - 2019

 

In his research, he applies HCI methods and concepts to the Cyber Security and Privacy domain. He also works on Secure Software Engineering (i.e., developer-centred) and Machine Learning for Cyber/Usable Security, specifically threat modelling through the cybercriminals' and end users' behavioural analysis. Nalin's research is interdisciplinary and he has published numerous articles at the world's leading conferences and high-impact journals. Notably, Nalin's recent work has made "a significant global impact" by improving the OWASP Enterprise Security API and Javadoc for the ESAPI Encoder interface - this will appear in their ESAPI 2.2.1.0 release [https://owasp.org]. Nalin has presented his research at Facebook Headquarters, Menlo Park, California, USA and collaborated with HP in a research capacity at the HP Lab, Bristol, UK. His research has been featured in numerous media outlets, including TV One New Zealand (tvnz 1 News), Sky News Australia, ABC TV, ABC News Radio, WIN TV Australia, 2GB 873 AM Radio, SYN Radio 90.7 FM, Daily Show on Radio 2SER 107.3, Choice - Australia, Guardian labs (sponsored by Intel Corporation, Australia), and UNSW TV. He has been an invited speaker for conferences both nationally and internationally. 

Nalin also worked on a number of "Visiting/Sessional" lecturing positions in Computer Science in the UK (Brunel University London, University of Bedfordshire, Westminster University, and Central Bedfordshire College), Canada (University of British Columbia), and Australia (Deakin University, Victoria University, and Central Queensland University (CQUniversity).

Nalin obtained a BSc (MIS) Hons from University College Dublin, National University of Ireland, and has completed a master's degree, MSc Information Management and Security at the University of Bedfordshire, UK. He is a Sun Certified Java Programmer (SCJP) at Sun Microsystems (now Oracle), USA.

*** Please note: I actively seek to supervise good PhD/Masters/Hons research students at RMIT University, Australia. Please feel free to contact me at nalin.arachchilage@rmit.edu.au if you are interested.***

Media

Research fields

  • 4604 Cybersecurity and privacy
  • 460806 Human-computer interaction
  • 4612 Software engineering
  • 4611 Machine learning
  • 460208 Natural language processing
  • 460706 Serious games
  • 460904 Information security management

Academic positions

  • Associate Professor in Cyber Security
  • RMIT University, Australia
  • School of Computing Technologies
  • Melbourne, Australia
  • 2024 – Present
  • Director of MProfStuds in Digital Security
  • The University of Auckland
  • The School of Computer Science
  • Auckland, New Zealand
  • 2022 – 2024
  • Assistant Head of School (Research)
  • The University of Auckland
  • The School of Computer Science
  • Auckland, New Zealand
  • 2022 – 2023
  • Lecturer/Senior Lecturer in Cyber Security
  • The University of Auckland
  • The School of Computer Science
  • Auckland, New Zealand
  • 2021 – 2024
  • Senior Research Fellow in Cyber Security
  • La Trobe University
  • Optus La Trobe Cyber Security Research Hub, La Trobe University
  • Melbourne, Australia
  • 2019 – 2021
  • PhD Research Supervisor (External)
  • King’s College London (KCL)
  • Department of Informatics
  • London, United Kingdom
  • 2019 – Present
  • Lecturer (Assistant Professor) in Cyber Security
  • University of New South Wales, Australian Defence Force Academy (ADFA)
  • Canberra, Australia
  • 2015 – 2019
  • Postdoctoral Research Fellow in Usable Security
  • The University of British Columbia
  • Electrical and Computer Engineering
  • Vancouver, Canada
  • 2014 – 2015
  • Postdoctoral Research Assistant in Systems Security Engineering
  • Oxford University
  • Department of Computer Science
  • Oxford, United Kingdom
  • 2013 – 2014

Non-academic positions

  • Advisor (Board of Advisors)
  • DEFSAFE Cyber Security Inc
  • Auckland, New Zealand
  • 2023 – Present
  • Chair of the Academic Board (in Cyber Security)
  • Canberra Business and Technology College (CBIT) - Australia
  • Canberra, Australia
  • 2020 – 2021

Supervisor projects

  • An Empirical Study of Computational Thinking Education in Remote Primary Schools
  • 2 Sep 2024
  • Developer-Centric Responsible AI: A Novel Framework for Software Developers to Embed Responsible AI into Software Apps
  • 4 Mar 2024

Teaching interests

  • Lecturer — Course coordinator - INTE2625 - Introduction to Cyber Security [2024]
  • Lecturer - COSC2738 - Human-centric Cyber Security {2025}
  • Lecturer - COSC2737 - IT Infrastructure and Security {2024]
  • Project Supervisor - COSC2410 - Software Engineering Project (2024)

Research interests

  • Cyber Security
  • Usable Security and Privacy
  • Human-Computer Interaction
  • Secure Software Engineering
  • Machine Learning for Cyber Security
  • Natural Language Processing (NLP)
  • Serious Games/Gamification for Cyber Security
  • Responsible AI

Initiatives and links

aboriginal flag
torres strait flag

Acknowledgement of Country

RMIT University acknowledges the people of the Woi wurrung and Boon wurrung language groups of the eastern Kulin Nation on whose unceded lands we conduct the business of the University. RMIT University respectfully acknowledges their Ancestors and Elders, past and present. RMIT also acknowledges the Traditional Custodians and their Ancestors of the lands and waters across Australia where we conduct our business - Artwork 'Sentient' by Hollie Johnson, Gunaikurnai and Monero Ngarigo.