Cyber Security Analyst · Threat Intelligence · SOC Analyst
Performance-driven SOC Analyst with 2.5+ years across Tier 1 & Tier 2 operations in Banking, Aviation & Telecom.
NCSC Certified MSc · Hatfield, UK · Graduate Route Visa
Performance-driven Security Operations Centre (SOC) Analyst with over 2.5+ years of international experience across Tier 1 and Tier 2 operations in the Banking, Aviation, and Telecommunications sectors.
Proven track record in orchestrating real-time DDoS mitigation for critical infrastructure and automating alert triage using Python to improve operational efficiency by 30%.
Currently completing an NCSC Certified MSc in Cyber Security at the University of Hertfordshire, with a research focus on AI-augmented incident response and advanced digital forensics. Seeking SOC Analyst and Threat Intelligence roles in the UK.
Creating compelling visual identities, social media graphics, marketing materials, and brand assets that communicate clearly and leave a lasting impression.
Producing professional video content including cinematic edits, motion graphics, colour grading, and audio mixing for YouTube, social media, and corporate use.
Designing and building clean, modern, responsive websites and landing pages with a focus on user experience, accessibility, and performance optimisation.
Scenario: Security analysts spend excessive time manually parsing threat intelligence from varied sources.
Goal: Centralize 100+ RSS feeds to provide real-time, triaged threat intelligence.
Actions: Engineered a React/TypeScript dashboard with a SQLite backend. Built automated threat severity classification using keyword-based analysis and automated critical-alert email reporting.
Outcome: Delivered a centralized intelligence platform with interactive visualizations, reducing manual monitoring efforts by 50%.
Scenario: Unmanaged personal devices in corporate environments introduce severe access risks.
Goal: Design an access control system to securely authenticate and isolate BYOD endpoints.
Actions: Developed a framework using AES-128 encryption and UUID-based authentication. Integrated ML and CNN-based facial recognition to detect anomalies.
Outcome: Created a zero-trust model prototype that prevents unauthorized network access from compromised personal devices.
Scenario: Threat hunting requires checking numerous external IP reputation lists, consuming valuable triage time.
Goal: Automate IP enrichment to quickly determine the severity of a suspicious IP.
Actions: Developed a Python script integrating APIs (VirusTotal, AbuseIPDB, AlienVault OTX) and dark-web OSINT.
Outcome: Automatically generated hashes, geolocation, and severity scoring into an analyst-ready threat summary.
Scenario: Manual triage of noisy, unparsed SIEM alerts leads to alert fatigue and high MTTR.
Goal: Automate log parsing to extract actionable indicators from raw logs.
Actions: Wrote Python scripts to parse log formats and highlight critical fields.
Outcome: Integrated the pipeline with the SIEM, reducing manual triage time by 30% and improving SOC efficiency.
Scenario: Standard email security filters often miss sophisticated, targeted phishing attacks and zero-day malicious URLs.
Goal: Develop an automated email analysis engine to proactively detect, score, and quarantine complex phishing attempts.
Actions: Built a Python application fetching real-time IMAP emails, validating SPF/DKIM/DMARC headers, and querying CTI feeds + Gemini AI API.
Outcome: Created a robust pipeline that automatically flags spoofing and quarantines malicious messages with high accuracy.
Scenario: Routine vulnerability assessments involve running fragmented tools manually, causing reporting delays.
Goal: Create a lightweight, unified scanning tool to streamline basic reconnaissance.
Actions: Built a Bash CLI tool on Kali Linux orchestrating Nmap, Nikto, and Metasploit auxiliary modules.
Outcome: Consolidated scan outputs into structured HTML reports, doubling assessment speed and repeatability.
Microsoft · Aug 2021
Cybrary · Sep 2021
IBM · Aug 2021
Red Hat · Aug 2021
Air Arabia (ISA) · 2023
Sri Lanka Scout Association · 2019
Preparing for SOC 200 certification with a focus on advanced SOC operations, security monitoring, incident handling, threat detection, and real-world SIEM workflows.
Actively following the TryHackMe SOC Learning Path with daily hands-on practical labs, focusing on SIEM alert analysis, log investigation, threat detection, and incident response in real-world SOC scenarios.
Implementing and testing Wazuh security policies using Kali Linux, including log analysis, rule tuning, agent configuration, and threat detection use cases.
Designing and building a custom SOC lab environment on Kali Linux, integrating SIEM, endpoint monitoring, threat simulation, and incident response workflows for hands-on SOC practice.
University of Hertfordshire, UK
2024 – 2025 · NCSC Certified Master's Degree
Sri Lanka Institute of Information Technology (SLIIT)
2020 – 2024 · Specialization in Cyber Security
I'm actively looking for SOC Analyst opportunities in the UK. Whether you're a recruiter, a hiring manager, or a fellow security professional — feel free to reach out!
Hatfield, UK · Graduate Route Visa (Full-time work eligible)