Overview
Technical skills
Timeline
Roles

Overview

Full-stack Node.js and React developer at a junior-to-middle level focusing on building REST APIs and security-focused tooling. The strongest proven skill is implementing authentication and user flows using bcrypt, Joi validation and JWT in server/api/Authentication.js. There is limited evidence of production-grade hardening, schema migrations, testing, performance engineering or observability tooling in the public code.
Phone

Technical skills

Languages
5
Python
Node JS
SQL
Bash
PHP
Node JS
6
Axios
Bcrypt
Joi
Mongoose
Express
Dotenv
DevOps
9
Grafana
Kibana
Splunk
Zabbix
AWS
Azure
Rest API
GitHub
Linux
Cybersecurity
10
Microsoft Defender
AbuseIPDB
Active Directory
CIS Benchmarks
Metasploit
Volatility
Burp Suite
SentinelOne
SIEM
Zscaler
Cryptography
3
OpenSSH
GPG
PyCryptodome
Other
14
MySQL
ElasticSearch
Prometheus
Cortex XSOAR
Recorded Future
Tanium
FortiGate
Nessus
Cryptography
Kali Linux
Debian
Cortex
MobSF
Anomaly Detection

Timeline

Senior Security Analyst • Senior
SyscoLABS • Full-Time
Jun 2026 to Present 3 Months In office
Handled SOC monitoring, alert triage, security investigations, and incident response following an incident response process. Correlated events across multiple data sources to identify threats and reduce false positives. Provided guidance to Tier 1 analysts, performed advanced investigations, and focused on detection gap remediation and process improvements with internal teams and clients.
L3 - Security Analyst • Middle
Ernst & Young • Full-Time
Jan 2025 to May 2026 1 Year 4 Months In office
Delivered 24/7 SOC consulting to clients, focusing on security monitoring and incident response. Developed and optimized Splunk Enterprise Security use cases, correlation searches, dashboards, and detection rules to improve threat visibility and lower false positives. Designed and maintained Splunk SOAR automation playbooks and supported ongoing SOC engineering improvements.
Splunk
SOC Analyst • Middle
Information Systems Associate (ISA) • Full-Time
Aug 2023 to Dec 2024 1 Year 4 Months In office
Monitored and responded to security incidents using Stellar Cyber and Microsoft Defender MDR to reduce incident volume. Conducted threat hunting using advanced KQL logic and DFIR-related scripting. Investigated endpoint, network, and cloud alerts, supporting enterprise monitoring with Microsoft Defender, Grafana, Zabbix, Site24x7, and Kibana.
Microsoft Defender
Grafana
Zabbix
Kibana
Cyber Security Specialist (Internship, VAPT) • Junior
PwC • Internship
Jul 2022 to Aug 2023 1 Year 1 Month In office
Performed penetration testing for web and mobile applications in client environments. Conducted vulnerability assessments and security audits for internal and external assets and maintained engagement documentation such as reports and proposals. Executed internal vulnerability assessments and firewall reviews to support compliance with security standards.
Sri Lanka Institute of Information Technology (SLIIT)
Bachelor's Degree • Information Technology
2020–2020 Colombo, Sri Lanka
Middle Backend Developer Confidence: Medium API Engineer
Full-stack Node.js and React developer at a junior-to-middle level focusing on building REST APIs and security-focused tooling. The strongest proven skill is implementing authentication and user flows using bcrypt, Joi validation and JWT in server/api/Authentication.js. There is limited evidence of production-grade hardening, schema migrations, testing, performance engineering or observability tooling in the public code.
API Design
2/10
How well APIs are designed
Basic REST API patterns and consistent JSON responses are present but there is no versioning, idempotency, pagination or advanced error contract; API design is largely CRUD and coupling to a single backend URL.
Evidence
DockerSec-V1.0/server/api/Authentication.js: consistent JSON responses with {status,message,data}
DockerSec-V1.0/client/src/pages/Login.js: axios.post to https://54.238.175.157:5000/login with {data} payload
Data Layer & Database
2/10
Working with databases
Uses Mongoose models for basic persistence and handles duplicate-key errors, but no migration history, transactions, isolation-level concerns or complex query tuning are evident.
Evidence
DockerSec-V1.0/server/api/Authentication.js: Admin.findOne and new Admin(...).save() calls
DockerSec-V1.0/server/api/Authentication.js: checks for err.code === 11000 to handle duplicate key
Scalability & Performance
1/10
Handling load and speed
No caching, queueing, connection-pooling or measured performance optimizations; simple synchronous request flows from UI to single backend endpoint.
Evidence
DockerSec-V1.0/client/src/pages/Scans.js: direct axios.get calls to backend endpoints without caching or backoff
DockerSec-V1.0/client/src/pages/Scan.js: axios.get fetch in gethostscan with no retry/backoff
System Architecture
2/10
Overall system structure
Project shows basic separation between server api, schema and client, but the architecture is a simple monolith without documented service boundaries, contracts or resilience boundaries.
Evidence
DockerSec-V1.0/server/api/Authentication.js: server side API module
DockerSec-V1.0/client/src/: clear React frontend separate from server folder
Security & Auth
3/10
Protecting data and access
Demonstrates security awareness through input validation (Joi), password hashing (bcrypt) and JWT usage, but has insecure practices such as a hardcoded JWT secret, insecure cookie flags and client storage of tokens.
Evidence
DockerSec-V1.0/server/api/Authentication.js: uses bcrypt.hashSync and bcrypt.compareSync for passwords
DockerSec-V1.0/server/api/Authentication.js: jwt.sign with hardcoded secret 'AKIAURO2OFILH25ELFJR' and cookie set with httpOnly: false
DockerSec-V1.0/client/src/pages/Login.js: stores token in localStorage via localStorage.setItem('jwt-token', ...)
Reliability & Observability
2/10
Stability and monitoring
Basic try/catch error handling and UI loading states exist, but there is little evidence of structured logging, timeouts, retries with backoff, graceful shutdown handling or metrics/alerts.
Evidence
DockerSec-V1.0/server/api/Authentication.js: try/catch blocks and console.log error traces
DockerSec-V1.0/client/src/pages/Register.js: try/catch around axios.post and loading state handling
Expertise
Node.js• Middle
Industries
Cybersecurity• Middle
Technologies
PHP
Node JS• Middle
Rest API
Express
Bcrypt
Joi
Mongoose
Axios
Dotenv
Recommendations
  • Develop small to mid-size REST APIs and admin backends that require basic auth, user management and CRUD endpoints with iterative hardening.
  • Build security tooling and automation around container/hardening checks where the CIS benchmark script (tool/main.py) can be extended and hardened.
  • Work on improving authentication lifecycle and security posture: remove hardcoded secrets, enable httpOnly/secure cookies, add token refresh/revocation and server-side session controls.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories:
Junior Security Engineer Confidence: Medium Generalist
Security-focused generalist developer (junior) working on network anomaly detection and a password manager with practical but immature cryptography code. The strongest proven skill is applied cryptography integration as evidenced by NextGenPass/AESencrypt.py and PasswordGen.py implementing AES-based encryption and key handling. The work lacks secure engineering maturity, containing hardcoded credentials, fragile crypto padding/encoding, minimal error handling, and almost no tests or threat-modeling artifacts.
Vulnerability Analysis
Finding security weaknesses
Not evidenced in public code
Cryptography & Secure Protocols
2/10
Using encryption correctly
Direct use of symmetric crypto primitives and a custom AES wrapper are present, showing practical familiarity but also insecure/buggy implementation patterns (custom padding/unpadding, nonstandard encoding, fragile string handling). The work demonstrates applied experience but lacks correct padding handling, clear key lifecycle, tests, and security review.
Offensive Security / Pentesting
Testing by attacking
Not evidenced in public code
Defensive Hardening
1/10
Making systems harder to break
Some defensive/detection goals exist (network capture, anomaly detection), but secure-by-default practices are absent and there are negative signals such as hardcoded credentials and lack of least-privilege reasoning or configuration hardening.
Detection & Incident Response
3/10
Spotting and handling attacks
There is a working detection pipeline: data cleaning, vectorization, model training and evaluation with confusion matrix and metrics, plus a runtime prediction module that uses a persisted model. This demonstrates basic detection engineering and evaluation awareness but lacks rigorous FP/FN analysis, labeled datasets descriptions, or detection tuning documentation.
Compliance & Threat Modeling
Planning against threats
Not evidenced in public code
Expertise
Cryptography & Data Protection• Junior
Industries
Cybersecurity• Middle
Technologies
Cryptography
Python• since 2022 • Junior
Bash
Burp Suite
Metasploit
Nessus
FortiGate
Zscaler
PyCryptodome
SentinelOne
Microsoft Defender• since 2023
MobSF
Cortex XSOAR
Tanium
Recorded Future
SIEM
Recommendations
  • Harden and refactor the encryption module: replace custom padding/encoding manipulation with a vetted library pattern, add unit tests for encrypt/decrypt, and document key lifecycle and threat assumptions.
  • Remove hardcoded secrets and implement secure configuration: move DB credentials to environment/secret manager and use connection retries, timeouts and least-privilege DB accounts.
  • Improve detection engineering rigor: add labeled dataset documentation, evaluation scripts that measure FP/FN tradeoffs, and automated model validation/CI to prevent regression.
  • Add defensive coding and operational controls: input validation for packet parsing, robust subprocess error handling for tshark calls, and principled logging without leaking secrets.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories:
Intern DevOps Engineer Confidence: Low Generalist
An entry-level cybersecurity-minded generalist with stated interest in ethical hacking and content creation. The only concrete artifact accessible is a README claiming ethical hacking experience and listing languages, so there is no proven engineering work in human-authored code to validate skills. There is no evidence of CI/CD, IaC, container orchestration, observability, tests, or incident artifacts to evaluate operational ability.
CI/CD Pipelines
Automated build and deploy
Not evidenced in public code
Infrastructure as Code
Managing servers with code
Not evidenced in public code
Containerization & Orchestration
Working with containers
Not evidenced in public code
Observability & Monitoring
Watching system health
Not evidenced in public code
Reliability & Incident Response
Keeping systems up
Not evidenced in public code
Cloud & Cost Optimization
Smart use of the cloud
Not evidenced in public code
Recommendations
  • Create and publish a small, fully human-authored project that demonstrates practical skills, for example a containerized security lab with a multi-stage Dockerfile, a basic health check, and a documented CI run that builds the image.
  • Implement a simple Infrastructure-as-Code example (a targeted Terraform module) with remote state and locking, plus a pipeline that deploys it to a disposable cloud account to show IaC and deployment hygiene.
  • Add observability and incident artifacts such as a sample Prometheus alert, a dashboard as code, and a short runbook or postmortem that ties alerts to remediation steps so operational skills can be evaluated.
Repositories
The developer's experience in this domain has been verified based on AI analysis of the following repositories: