Information Security Intern
I am an Information Security Intern with 1–2 years of experience at Softlogic Finance, where I successfully conducted periodic user access reviews that identified and remediated over 50 dormant accounts, significantly reducing unauthorized access risks. My work supporting security monitoring and risk management initiatives has enhanced my analytical thinking and incident investigation skills, reinforcing my commitment to cybersecurity. I am building toward a role as a Cybersecurity Engineer, where I can leverage my technical knowledge and problem-solving abilities to strengthen organizational security frameworks.
March 2026 – Present
Drive information security audit readiness by coordinating internal compliance assessments and preparing evidence for internal and external audits. Conduct periodic user access reviews across Active Directory, VPN, and application user matrices, identifying dormant accounts and excessive privileges to reduce unauthorized access risk. Reconcile remote access assets (VPN, corporate APN connections, dongles) against authorization records and active-employee lists to close compliance gaps. Conduct risk assessments and document identified risks, review exceptions and remediation actions, partnering with system owners to drive issues to closure. Review and maintain information security policies, standards and procedures to keep governance documentation current and audit-ready. Apply and monitor compliance against ISO 27001 controls and Central Bank of Sri Lanka (CBSL) directions, supporting the organization’s regulatory and information security governance requirements. Lead security awareness reporting by tracking training completion and compiling compliance metrics for management.
June 2025 – December 2025
Monitored systems, applications, tenant accounts, and AWS environments, producing daily and monthly reports that gave management real-time visibility into system health. Designed and ran phishing simulation campaigns in GoPhish, from drafting realistic lure emails to reporting outcomes that shaped targeted security awareness training. Authored internal security communications — awareness messages, training invitations, and phishing updates — to strengthen organization-wide security culture. Supported configuration, testing, and maintenance of internal applications, including user access management. Diagnosed and resolved incidents through root-cause analysis, ensuring timely resolution for internal users and clients. Partnered with cross-functional teams to maintain stable, secure system operations.
BSc (Hons) in Computer Networks & Cyber Security • 2022 – Present
3.34
G.C.E. A/L – Bio System Technology with ICT • 2017 – 2019
B, 2S
Interested in collaboration or just want to say hello? Feel free to reach out!