# whoami

Hi, I'm Sudhara Dharmawardhana. I'm a results-driven information security specialist with over five years' experience spanning offensive and defensive security domains. I specialise in comprehensive penetration testing across applications, networks, cloud environments, DevOps, and mobile platforms. I also develop bespoke tools for sophisticated red team engagements. I am also proficient in conducting source code reviews for Go, Python, TypeScript, and Swift-based applications.

In addition to technical skills, my security expertise includes comprehensive knowledge of information security risk management. This broader perspective helps me identify organisational risks and build security architectures that can effectively resist attacks.

Outside the security domains, I enjoy recreational programming, running, fingerstyle guitar, travelling, hiking, and Chess.

# core_skills

  • Penetration Testing
  • Red Team Operations
  • Security Architecture
  • IT Risk Management
  • Software Development
  • DevSecOps

# work_history

Principal Security Analyst, Cyber Testing and Assurance | Australian Energy Market Operator (AEMO)
// 2024 January - Present
Senior Security Tester | Office of Digital Government, Department of Premier and Cabinet, Perth
// 2023 January - 2023 December
ICT Security Analyst | Health Support Services, Department of Health, WA
// 2019 November - 2023 December
Cyber Security Intern | Office of Digital Government, Department of Premier and Cabinet, Perth
// 2019 August - 2019 October
Co-Founder | Ideal Web Designing, Perth
// 2018 August - 2019 July

# education

Master of Cyber Security | Edith Cowan University
// Acquired in 2019.
Professional Graduate Diploma in IT | British Computer Society
// Acquired in 2016.

# certifications

Offensive Security Certified Professional (OSCP)
// Acquired in 2023.
Certified Information Security Manager (CISM)
// Acquired in 2023.
Certified Information Security Auditor (CISA)
// Acquired in 2023. Expired as of now.
Certified in Risk and Information Systems Control (CRISC)
// Acquired in 2023. Expired as of now.
GIAC Cloud Security Automation (GCSA)
// Acquired in 2023. Expired as of now.

# contact