Rasitha aafrin
Penetration Tester
About
Penetration Tester with 3+ years of combined experience in Internal & External Network, Web Application, API and Server Infrastructure Penetration Testing, including PCI DSS VAPT Audits and Server Hardening Assessments on various corporate Networks.
Skills & Expertise
No skills listed yet
Work Experience
Cyber Security SME Author
HCL GUVI
Sep 2023 - Present
Reviewed and validated 15+ cybersecurity courses on the GUVI platform, ensuring technical accuracy and alignment with industry frameworks for a global learner base of 3M+. Promoted to SME Author in recognition of performance, assuming ownership of course design, lab development, and assessment creation. Authored technical training content for the Burp Suite course & the Distributed Systems course and Python and Forensics for Visualization. Designed interactive learning assets, lectures, hands-on labs, product demonstrations, and scenario-based assessments to strengthen practical understanding of core security concepts.
Cyber Security Consultant
GRM Technologies Pvt. Ltd
Aug 2023 - Feb 2024
Perform Vulnerability Assessment and Penetration Testing across Internal & External Networks, Web Applications, APIs, Servers and Infrastructure environments. Perform Quarterly and Half-Yearly VAPT Audits for Government Banking Environments, including recurring security assessments and vulnerability validation. Perform Manual and Automated Security Testing using Black-Box and Gray-Box testing methodologies. Perform Web Application and API Security Testing based on OWASP Top 10 and industry security testing practices. Perform PCI DSS-focused VAPT Audits and support security assessments based on applicable compliance requirements. Perform Server Security and Hardening Assessments to identify security misconfigurations and vulnerabilities. Analyze identified vulnerabilities and assess their Technical and Business Security Impact. Deliver VAPT and Security Assessment Reports with vulnerability evidence, risk ratings and remediation recommendations. Discuss Security Findings, Attack Scenarios and Remediation Recommendations with clients and technical stakeholders.
Cyber Security Trainer
Self-Employed
Aug 2021 - Aug 2023
Conducted cybersecurity training sessions for students covering Cybersecurity Fundamentals, Ethical Hacking, Web Application Security and Vulnerability Assessment. Delivered practical training on VAPT methodologies, OWASP Top 10, Web Application Security and Network Security concepts. Provided hands-on demonstrations using security tools including Burp Suite, Nmap, Wireshark, Kali Linux and OWASP ZAP. Created practical exercises and training materials to help students understand Penetration Testing, Vulnerability Identification and Security Testing techniques. Guided through hands-on labs, security testing exercises and cybersecurity projects.
Education
Master of Science (M.Sc.) in Cyber Security - Manonmaniam Sundaranar University
- ยท Afghanistan
Bachelor of Science (B.Sc.) in Information Technology - Sri Adi Chunchanagiri Women's College
- ยท Afghanistan
Certifications
No certifications added yet