<security_cloud_qa_profile>
</security_cloud_qa_profile>
Open to Security Operations, Security Analyst, Cloud Security, QA and API Testing Opportunities
<profile>
Security-focused IT professional with QA engineering experience across Agile software delivery, API validation, backend data verification, defect analysis and release support, now expanding expertise in Cloud Computing and Cyber Security.
I bring a strong analytical and investigation mindset developed through functional testing, API validation using Postman, SQL-based data verification, defect analysis and cross-functional collaboration with developers, product owners and stakeholders.
Through hands-on projects and labs in AWS, Microsoft Azure and Fortinet, I have worked with IAM, VPCs, public and private networking, access control, security groups, firewall concepts, secure hosting, monitoring and cloud administration scenarios. I am particularly interested in Security Operations, cloud security, vulnerability analysis, incident response support, and technology environments where I can combine my QA background with growing cyber security capability.
</profile>
Agile testing, API validation, backend verification and issue investigation across product teams
AWS, Azure and Fortinet project work covering IAM, networking, access control, monitoring and secure hosting
Active learning path across security operations, cloud security, networking and cyber security fundamentals
Professional Development
Thiru Solutions Limited
Freelance Projects
DHV Consulting, Auckland, New Zealand
ICT Internet Presence (ICTIP) - Colombo, Sri Lanka
Group-based multi-cloud security project focused on planning, implementing and documenting a secure AWS, Azure and Fortinet FortiGate integrated environment. Covers VPC, EC2, IAM, RDS, ELB, CloudWatch, Lambda, VPN and S3 alongside Azure RBAC and Azure AD, plus risk assessment, incident analysis, monitoring and professional project documentation.
Practical network security project demonstrating Fortinet FortiGate firewall configuration, security policy design and protected network segmentation across LAN, WAN and DMZ zones. Includes documented architecture decisions, proof-of-concept implementations, traffic control rules, and a video walkthrough showing security controls, policy enforcement and blocked-versus-allowed scenarios in action.
Hands-on AWS security implementation covering IAM users, groups, roles and permission boundaries, VPC security design, security groups and least-privilege access control. Focused on securing cloud workloads through network protection, encrypted storage, credential management and audit logging, while applying AWS security best practices across realistic deployment and incident-response scenarios.
Scenario-based AWS implementation focused on VPCs, public and private subnets, route tables, internet and NAT gateways, and secure network segmentation. Emphasises practical cloud networking, traffic flow control, defence-in-depth infrastructure design, and clear deployment documentation covering IP planning, connectivity paths, security groups and hardened administrator access.
AWS-focused architecture exercise combining foundational cloud concepts with practical deployment choices across compute, storage, high availability, monitoring and administration. Demonstrates secure design thinking, right-sized service selection, resilience planning and cost-aware decisions, backed by written justification of trade-offs, security considerations and recommended AWS service configurations.
Azure project work covering virtual machines, storage accounts, virtual networks, network security groups and secure resource management. Demonstrates practical Azure service administration, role-based access, resource tagging and cloud infrastructure fundamentals through guided implementation tasks, alongside documented configuration steps, verification screenshots and lessons learned from hardening a multi-resource Azure environment.
Azure administration project focused on user and identity management, resource provisioning, activity monitoring, governance policies and operational oversight. Highlights practical cloud administration activities aligned with secure, well-governed public cloud environments, including role assignments, access reviews, cost visibility, alerting and documented procedures for maintaining a healthy production-ready Azure tenant.
<contact>
I am open to Security Operations Analyst, Security Analyst, Cloud Security, QA and API Testing opportunities where I can combine my QA investigation background with growing cloud and cyber security capability.
</contact>
Let's discuss how I can contribute across security operations, cloud security, QA, API testing and modern technology delivery teams.
SEND MESSAGE