
Penetration Tester (VAPT) | Web, API, Network & Cloud Security
Send a job offer directly to this candidate
Results-driven penetration tester with nearly 5 years of hands-on experience delivering Vulnerability Assessment and Penetration Testing (VAPT) across web applications, APIs, network infrastructure, and cloud environments. Skilled at identifying, validating, and exploiting security vulnerabilities through both manual and automated testing, with deep command of the OWASP Top 10, OWASP API Security Top 10, and white-box source code review. Hands-on with industry-standard tooling including Burp Suite Professional, Nessus, Metasploit, Nmap, and Kali Linux.
Proven track record of producing detailed security assessment reports with risk ratings and prioritised remediation recommendations, partnering with development and infrastructure teams to remediate findings, and re-testing fixes to verify successful closure. Holds seven OffSec certifications — including the OffSec Web Expert (OSWE) — and is actively preparing for the OSCP exam.
Application Security Engineer / Penetration Tester at Virtusa (2026-02 – Present)
Wiley engaged as a client following Virtusa's acquisition of Wiley Sri Lanka
Application Security Engineer / Penetration Tester at Wiley (2024-12 – 2026-02)
Cybersecurity Engineer (Penetration Tester) at Scybers (2022-01 – 2024-12)
Cybersecurity Advisory & Managed Services
Bachelor of Science in Cyber Security – Edith Cowan University