About Me
Professional Summary
Offensive Security professional with 1.5 years of client-facing experience delivering Web Application, API, Network, Active Directory, Wireless, and Mobile Application penetration testing across enterprise and financial-sector environments.
Delivered 13+ security assessment engagements for 10+ clients, surfacing 160+ vulnerabilities and producing risk-rated reports that directly informed remediation roadmaps. CRTA and eJPT certified, with hands-on red team and phishing simulation experience.
Experience
Trainee Information Security Consultant
Trustvault
Sep 2025 – July 2026
- Managed end-to-end security engagement delivery across 10+ enterprise clients, including scoping, stakeholder communication, technical assessment, and post-engagement support.
- Delivered 13+ assessment engagements spanning Internal/External VAPT, Web Application, API, Active Directory, Wireless, Mobile, Endpoint Security, Firewall/DNS Configuration Reviews, and Phishing Simulations.
- Surfaced 160+ vulnerabilities (80+ High, 60+ Medium severity) across 10+ enterprise environments, translating findings into risk-rated reports that informed client remediation roadmaps.
- Uncovered critical authentication, authorization, and injection flaws across web and API platforms using Burp Suite Professional against OWASP Top 10 threat classes.
- Simulated real-world attacker behavior in Active Directory environments — domain enumeration, credential abuse, and lateral movement to expose privilege escalation paths.
- Assessed Firewall, DNS, and Database configurations, identifying critical misconfigurations across enterprise infrastructure.
- Developed and executed phishing simulation campaigns using GoPhish and PhishingBox targeting finance, productivity, and collaboration platforms.
Intern – Cyber Security
Centre for Defence Research and Development (CDRD), Ministry of Defence, Sri Lanka
Jul 2024 – Jan 2025
- Designed and implemented a fully functional open-source SOC (SIEM, HIDS, NIDS, EDR, SOAR, and network monitoring) performing L1 and L2 analysis.
- Conducted advanced threat hunting and intelligence gathering using open-source tools in a controlled lab environment.
- Performed Bluetooth and Wireless penetration testing using dedicated adapters.
- Gained hands-on experience with hardware penetration testing tools, simulating real-world physical attack vectors.
- Administered servers and VMware ESXi virtualized environments, including Windows installation and configuration.
- Configured and managed network devices: routers, switches, and firewalls to harden infrastructure security.
Education
BSc (Hons) in Information Technology, Specializing in Cyber Security
Sri Lanka Institute of Information Technology (SLIIT), Malabe, Sri Lanka
2022 – 2026 (Graduated)
Technical Skills
Domains
Tools & Platforms
Certifications
- CR
CRTA — Certified Red Team Analyst
CyberWarFare Labs · Nov 2025
- EJ
eJPT — Junior Penetration Tester
INE Security · Dec 2025
- OC
Oracle Cloud Infrastructure 2024 Foundations Associate
Oracle · Feb 2025
- CC
CCNA — Cisco Certified Network Associate
Vibernets Academy · Jul 2024
- LS
Linux Server Administration and Security
Vibernets Academy · May 2024