$ whoami --verbose
operator : Tharaka Dissanayaka
role : Security Engineer · Services Security Team
environment: MSSP · ~50 managed enterprise tenants
base : Colombo, Sri Lanka
experience : 8+ years · security, infrastructure, network
focus : [ SOC Ops, Threat Hunting, Vuln Mgmt, Firewall Eng ]
reading : Executive MSc, Information Security
status : ACTIVE ✓GitHub Stats
### 8+ |
### ~50 |
### 17 |
### MSc |
| YEARS IN SECURITY | MANAGED TENANTS | CERTIFICATIONS | IN PROGRESS |
Security engineer with 8+ years across cybersecurity, enterprise infrastructure and network security. I run threat detection and endpoint defence for roughly 50 managed enterprise tenants at an Australian MSSP — detection triage, incident response, vulnerability management, and the occasional 2 a.m. containment call.
My background runs both ways. I came up through infrastructure — Windows Server, Active Directory, VMware, ERP, backup and DR — before moving into security. That shows up in how I triage: knowing why a line-of-business application spawns a strange-looking process is often the difference between a five-minute false positive and a three-hour incident.
Working belief — a detection you can't explain in a ticket note isn't a detection, it's a guess.
THREAT DETECTION EDR/XDR triage · process lineage LOLBin analysis · exclusion scoping KQL threat hunting |
INCIDENT RESPONSE AiTM & token theft · BEC account compromise · containment post-incident review |
VULNERABILITY MGMT exposure analysis · CVE advisories remediation prioritisation closure criteria |
IDENTITY & ACCESS Entra ID · Conditional Access MFA & passwordless Zero Trust architecture |
SOC OPERATIONS SIEM detection engineering alert triage at MSSP scale playbooks & runbooks |
EMAIL SECURITY header authentication analysis quarantine adjudication tenant-wide purge & hunt |
NETWORK SECURITY FortiGate & SonicWall policy IPsec / SSL VPN · VLANs segmentation |
GOVERNANCE ISO 27001 · NIST CSF · COBIT change management client advisories |
|
Executive MSc in Information Security · Asia e University, Malaysia · Nov 2025 – Dec 2026 |
|
THE GAP Vulnerability prioritisation still runs on CVSS base scores, which describe a flaw in the abstract and say nothing about whether the affected system is internet-facing, patched, or business-critical. SSVC addresses that, but its environmental decision points are assigned by hand and don't scale. |
THE QUESTION Whether environmental factors — system exposure, mission impact — can be derived from managed service provider telemetry instead: asset inventories, internet exposure, patch state, business criticality. Completing the SSVC decision tree without manual analyst input. |
WHY IT'S OPEN Existing automation such as CISA Vulnrichment resolves the vulnerability-specific factors and stops there — the organisation-specific ones cannot be derived from public data. That half of the tree has no automated answer yet. |
▸ Method and evaluation
Historical backtesting against public datasets — NVD, EPSS, CISA KEV, Vulnrichment — comparing automated SSVC prioritisation against conventional CVSS severity-based remediation.
| Measure | What it captures |
|---|---|
| Exploitation coverage | Share of actually-exploited CVEs caught by each prioritisation scheme |
| Efficiency | Precision of the remediation queue — how much effort goes to vulnerabilities that mattered |
| Remediation effort | Total volume of work each approach demands |
The environmental model is built either from aggregated, anonymised statistics drawn from a real multi-tenant managed services environment (subject to approval) or from a fully synthetic dataset where approval is unavailable.
What it settles: whether automated, context-aware prioritisation produces better remediation outcomes than severity-ranked patching — or whether the added machinery buys nothing a CVSS cutoff doesn't already deliver.
▸ Incident Response & Threat Hunting
AiTM phishing investigation and token-theft response · EDR triage across process injection, AMSI tampering, VSS deletion and LSASS access · adversary emulation · CVE triage and threat intelligence correlation
▸ Vulnerability Management
Remediation tracking, closure criteria, and client-facing exposure reporting.
▸ Governance & Compliance
Change management · security runbook authoring · policy and control documentation.
SC-100 Cybersecurity Architect Expert |
SC-200 Security Operations Analyst |
SC-300 Identity & Access Administrator |
AZ-900 Azure Fundamentals |
MS APPLIED SKILLS Defend Against Cyberthreats Defender XDR |
ISC2 CC Certified in Cybersecurity |
CISCO CCNA Enterprise & Security |
CISCO CYBEROPS CyberOps Associate |
CISCO DEVNET DevNet Associate |
FORTINET NSE 3 Network Security Associate |
SECOPS CNSP Certified Network Security Practitioner |
MITRE ATT&CK Defender Fundamentals |
SENTINELONE Singularity Admin Essentials |
GOOGLE CYBERSECURITY Professional Certificate |
GOOGLE WORKSPACE Professional Administrator |
GOOGLE GENAI Generative AI Leader |
KODEKLOUD DevOps Engineer Level 1 |
Credentials verifiable via the portfolio site | ||
◈ In progress — TCM PNPT (Practical Network Penetration Tester) · Google Associate Cloud Engineer ○ Planned — ISC2 CISSP (Q3 2026) · HTB Certified Active Directory Bootcamp Expert
| Qualification | Institution | Period |
|---|---|---|
| Executive MSc in Information Security | Asia e University (AeU), Malaysia | Nov 2025 – Dec 2026 |
| Diploma in Network Engineering | National Institute of Business Management (NIBM) | 2019 – 2021 |
| Certificate in Linux Network Administration | Turnkey IT Campus | — |
|
KQL queries and detection playbooks from MSSP SOC operations. |
Structured study plan and notes for the Microsoft SC-200 and SC-300 exams. |
|
Gamified security awareness platform — phishing and password challenges, leaderboards, JWT auth, PostgreSQL. · live |
Hands-on tool for practising prompt patterns in security and productivity workflows. |
|
Portfolio site — Three.js background, live GitHub and Medium feeds, dark/light themes. |
claude-skills · private Version-controlled Agent Skills for SOC triage, CVE advisories and exposure analysis. |
I write up the things that took me too long to work out the first time — detection triage reasoning, vulnerability management practice, and the operational side of security that rarely makes it into vendor documentation.

