About Me

Professional Summary

Offensive Security professional with 1.5 years of client-facing experience delivering Web Application, API, Network, Active Directory, Wireless, and Mobile Application penetration testing across enterprise and financial-sector environments.

Delivered 13+ security assessment engagements for 10+ clients, surfacing 160+ vulnerabilities and producing risk-rated reports that directly informed remediation roadmaps. CRTA and eJPT certified, with hands-on red team and phishing simulation experience.

Experience

Trainee Information Security Consultant

Trustvault

Sep 2025 – July 2026

  • Managed end-to-end security engagement delivery across 10+ enterprise clients, including scoping, stakeholder communication, technical assessment, and post-engagement support.
  • Delivered 13+ assessment engagements spanning Internal/External VAPT, Web Application, API, Active Directory, Wireless, Mobile, Endpoint Security, Firewall/DNS Configuration Reviews, and Phishing Simulations.
  • Surfaced 160+ vulnerabilities (80+ High, 60+ Medium severity) across 10+ enterprise environments, translating findings into risk-rated reports that informed client remediation roadmaps.
  • Uncovered critical authentication, authorization, and injection flaws across web and API platforms using Burp Suite Professional against OWASP Top 10 threat classes.
  • Simulated real-world attacker behavior in Active Directory environments — domain enumeration, credential abuse, and lateral movement to expose privilege escalation paths.
  • Assessed Firewall, DNS, and Database configurations, identifying critical misconfigurations across enterprise infrastructure.
  • Developed and executed phishing simulation campaigns using GoPhish and PhishingBox targeting finance, productivity, and collaboration platforms.

Intern – Cyber Security

Centre for Defence Research and Development (CDRD), Ministry of Defence, Sri Lanka

Jul 2024 – Jan 2025

  • Designed and implemented a fully functional open-source SOC (SIEM, HIDS, NIDS, EDR, SOAR, and network monitoring) performing L1 and L2 analysis.
  • Conducted advanced threat hunting and intelligence gathering using open-source tools in a controlled lab environment.
  • Performed Bluetooth and Wireless penetration testing using dedicated adapters.
  • Gained hands-on experience with hardware penetration testing tools, simulating real-world physical attack vectors.
  • Administered servers and VMware ESXi virtualized environments, including Windows installation and configuration.
  • Configured and managed network devices: routers, switches, and firewalls to harden infrastructure security.

Education

BSc (Hons) in Information Technology, Specializing in Cyber Security

Sri Lanka Institute of Information Technology (SLIIT), Malabe, Sri Lanka

2022 – 2026 (Graduated)

Technical Skills

Domains

Web App PentestingAPI PentestingNetwork PentestingActive DirectoryWireless & MobileRed Team OpsFirewall / DNS / DB ReviewsPhishing Simulations

Tools & Platforms

Burp Suite ProMetasploitNessusGoPhishPhishingBoxNmapffufBloodHoundImpacketNetExecELK StackWazuhSuricataZeekLinux

Certifications

  • CR

    CRTA — Certified Red Team Analyst

    CyberWarFare Labs · Nov 2025

  • EJ

    eJPT — Junior Penetration Tester

    INE Security · Dec 2025

  • OC

    Oracle Cloud Infrastructure 2024 Foundations Associate

    Oracle · Feb 2025

  • CC

    CCNA — Cisco Certified Network Associate

    Vibernets Academy · Jul 2024

  • LS

    Linux Server Administration and Security

    Vibernets Academy · May 2024