Summary
Overview
Work History
Education
Skills
PROJECTS
Accomplishments
REFEREES
Timeline
Generic

Sanjaya Ranasinghe

Perth,WA

Summary

Cybersecurity-focused DevSecOps Engineer with over 7 years of experience in cloud security, automation, and secure infrastructure design across AWS and hybrid environments. Proven expertise in Zero Trust architecture, vulnerability management, and secure CI/CD pipelines using Terraform, Ansible, Docker, and Kubernetes. Skilled in automating security workflows and ensuring compliance with ISO 27001 and the Essential Eight. Adept at delivering scalable, resilient systems through secure-by-design practices, and effective teamwork.

Overview

8
8
years of professional experience

Work History

DevOps Team Lead - Security

Moresand Technologies
Colombo, Sri Lanka
08.2024 - Current
  • Designed and implemented secure remote access in AWS using Client VPN and Zero Trust principles, enabling encrypted, least-privilege access for distributed teams.
  • Applied IAM policies, security groups, and audit logging to enforce compliance, improve visibility, and reduce attack surfaces across AWS workloads.
  • Led development of secure, automated UAT environments using ephemeral IaC pipelines (Bitbucket, Terraform, AWS), enhancing security and cost efficiency.
  • Integrated OpenVAS vulnerability scanning into CI/CD pipelines and Jira, automating remediation and reducing MTTR.
  • Mentored DevOps engineers in cloud security, vulnerability management, and secure-by-design practices, embedding ISO 27001 and Essential Eight compliance into operations.

Senior Cyber Security Analyst

ABN Group
Perth , Western Australia
03.2025 - 06.2025

UNIVERSITY PLACEMENT

  • Developed and implemented access control policies, strengthening security posture and ensuring compliance with business requirements.
  • Designed and deployed Bash automation tool, integrated with AlienVault (SIEM), to analyze suspicious URLs from alarms.
  • Queried VirusTotal API for risk classification, automated alerts, and reduced manual workload.
  • Integrated CrowdStrike into incident response workflows, enabling threat detection, investigation, and mitigation across endpoints.
  • Improved incident response efficiency through automation and policy alignment with IT and security teams.

Senior DevOps Engineer

Moresand Technologies
Colombo, Sri Lanka
08.2022 - 08.2024
  • Configured and managed OpenVAS vulnerability scanning across on-premise and AWS workloads, automating reporting and remediation through Jira.
  • Implemented quarterly security scanning processes that identified and mitigated high-risk vulnerabilities, ensuring compliance with security standards.
  • Developed Python automation scripts to parse OpenVAS reports and create Jira tickets, streamlining vulnerability management.
  • Configured AWS Client VPN endpoints and BIND DNS to provide secure hybrid network access, and seamless domain resolution.
  • Migrated Docker-based applications to AWS ECS, leveraging CloudFormation and ECR to improve scalability and deployment consistency.
  • Built and maintained Jenkins CI/CD pipelines integrated with Bitbucket, automating build, test, and deployment workflows.
  • Delivered zero-downtime deployments with infrastructure-as-code, automated rollbacks, and cloud-native best practices.

DevOps Engineer

Moresand Technologies
Colombo, Sri Lanka
08.2021 - 08.2022
  • Designed and implemented secure remote access in AWS using Client VPN and Zero Trust principles, enabling encrypted, least-privilege access for distributed teams.
  • Enforced compliance and reduced attack surfaces through IAM policies, security groups, and audit logging across AWS workloads.
  • Developed secure, automated UAT environments with ephemeral IaC pipelines (Bitbucket, Terraform, AWS), improving security and cost efficiency.
  • Integrated OpenVAS vulnerability scanning into CI/CD pipelines and Jira, automating remediation and reducing MTTR.
  • Mentored DevOps engineers on cloud security, vulnerability management, and secure-by-design practices, aligning operations with ISO 27001 and Essential Eight.

DevOps Engineer

M I SYNERGY PVT LTD
Colombo, Sri Lanka
08.2017 - 08.2019
  • Deployed and managed containerized applications using Docker, Docker Compose, and Docker Swarm, ensuring scalability, and reliable production releases.
  • Administered and maintained Linux-based systems (Debian, CentOS) across development, staging, and production environments.
  • Configured and managed Zabbix monitoring infrastructure with email alerting, serving as the primary administrator for Sri Lanka’s largest Zabbix-based mail server at the time.
  • Built and maintained CI/CD pipelines with Bitbucket, automating deployments to improve delivery speed and reliability.
  • Managed database servers (MS SQL, MySQL, MariaDB, MongoDB), implementing backup and recovery strategies to ensure performance, security, and business continuity.

Systems Engineer

M I SYNERGY PVT LTD
Colombo, Sri Lanka
08.2017 - 08.2019
  • Managed firewall/proxy servers (pfSense), mail servers (Zimbra), and Linux systems (CentOS, RedHat, SUSE), ensuring security, performance, and stability across environments.
  • Built and optimized CI/CD pipelines in collaboration with developers, automating deployments and system operations with Bash and Ansible.
  • Administered and maintained Jira and Confluence, streamlining workflows and improving team efficiency.
  • Deployed and maintained container clusters using Docker Swarm and Kubernetes, supporting scalable application environments.
  • Supported development and QA teams by designing Linux server environments, handling production operations (deployments, upgrades, patches), and mentoring team members.

Education

Master of Science - Cyber Security

Edith Cowan University
Joondalup, WA
06-2025

Bachelor of Science - Computer Networking

University of Plymouth
England
03-2018

Skills

🛡️ Cloud & Infrastructure Security

  • AWS Security & IAM, Zero Trust Architecture, Network Security, Secure Remote Access (VPN, Client VPN)
  • Vulnerability Management (OpenVAS), Compliance Alignment (ISO 27001, Essential Eight)
  • Security Monitoring & Incident Response (Grafana, Nagios, AWS CloudWatch)

⚙️ DevSecOps & Automation

  • Secure CI/CD Pipelines (Jenkins, Bitbucket, Git)
  • Infrastructure as Code (IaC) – Terraform, AWS CloudFormation, Ansible
  • Automation & Security Scripting (Bash, Python)

☁️ Cloud Platforms & Containerization

  • Amazon Web Services (AWS) – EC2, VPC, S3, RDS, ECS, ECR, Lambda
  • Containerization & Orchestration – Docker, Kubernetes

🧠 Systems & Administration

  • Linux/Unix Administration (CentOS, RedHat, Debian)
  • Backup & Recovery, Database Security (PostgreSQL, MySQL, MongoDB)

PROJECTS

Secure Remote Access & VPN (AWS)

  • Implemented Client VPN with Zero Trust, least-privilege access, and encrypted communication for distributed teams.
  • Managed Bind9 DNS servers and built fault-tolerant DNS/VPN for high availability and minimal attack surface.
  • Delivered self-service VPN client with authentication integration to improve security and reduce operational overhead.

Automated Dynamic UAT Environments

  • Built ephemeral AWS environments via Bitbucket + IaC pipelines for secure, on-demand deployments.
  • Enabled configurable EC2 instances, multi-container frameworks, and TTL-based auto-destroy to optimize cost and security.
  • Guided cross-functional teams to balance developer experience, automation, and secure operations.

Accomplishments

  • Dream Team of the year 2023 and 2024.

REFEREES

Available upon request

Timeline

Senior Cyber Security Analyst

ABN Group
03.2025 - 06.2025

DevOps Team Lead - Security

Moresand Technologies
08.2024 - Current

Senior DevOps Engineer

Moresand Technologies
08.2022 - 08.2024

DevOps Engineer

Moresand Technologies
08.2021 - 08.2022

DevOps Engineer

M I SYNERGY PVT LTD
08.2017 - 08.2019

Systems Engineer

M I SYNERGY PVT LTD
08.2017 - 08.2019

Master of Science - Cyber Security

Edith Cowan University

Bachelor of Science - Computer Networking

University of Plymouth
Sanjaya Ranasinghe