Skip to content
View Isuruvh's full-sized avatar

Block or report Isuruvh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Isuruvh/README.md

👋 Hi, I'm Isuru Heendeniya

Senior IAM & Cloud Automation Engineer | Transmission & Critical Infrastructure Specialist

I design, automate, and secure identity platforms for enterprise, telco, and critical infrastructure environments.
My work sits at the intersection of IAM, PKI, PAM, Azure, and network reliability — with a validator mindset that prioritises operational truth, audit‑grade documentation, and clean, modular engineering.


🔐 Identity, Security & Cloud Focus

  • Azure AD / Entra ID architecture
  • Hybrid identity (AD + AAD Connect + Cloud Sync)
  • Conditional Access, PIM, RBAC, Zero Trust
  • PKI (ADCS, Keyfactor, Venafi), certificate lifecycle automation
  • PAM (CyberArk, BeyondTrust)
  • MS Graph automation (Python + PowerShell)
  • Terraform, Bicep, ARM for identity & security infrastructure

⚙️ Automation & Engineering

  • Python automation for IAM, PKI, and cloud operations
  • Terraform modules for identity, networking, and security baselines
  • Bicep templates for Azure landing zones
  • MS Graph + REST API integrations
  • CI/CD pipelines for identity configuration and compliance
  • Modular, testable, production‑grade engineering

🛰️ Transmission & Critical Infrastructure Background

Before specialising in IAM, I engineered and supported mission‑critical networks across:

  • SDH/PDH, DWDM, OTN
  • MPLS, microwave, fibre
  • Multi‑vendor environments (Ericsson, Huawei, Nokia, Cisco)
  • High‑pressure fault diagnosis and service restoration
  • Preventative & corrective maintenance
  • Operational reliability for telco and transport networks

This gives me a unique blend of identity + infrastructure thinking — ideal for organisations where uptime, safety, and security are non‑negotiable.


📂 Featured Work (in progress)

🔧 iam-automation

A modular, enterprise‑grade IAM automation repository featuring:

  • Azure AD / Entra ID automation
  • PKI lifecycle workflows
  • PAM onboarding automation
  • Terraform/Bicep identity modules
  • MS Graph Python SDK examples
  • Architecture diagrams & operational runbooks

🧩 terraform-iam-modules (coming soon)

Reusable Terraform modules for identity, security, and compliance.

🔐 pki-lab (coming soon)

A hands‑on PKI lab with ADCS, certificate automation, and security hardening.


🎯 Current Goals

  • Build a complete IAM + PKI + PAM automation portfolio
  • Complete SC‑300, AZ‑204, AZ‑800/801, SC‑100, Terraform Associate
  • Target roles in:
    • Sydney Trains (Technical Specialist – Transmission / Identity)
    • Optus (Service Design & Delivery)
    • BAI Communications (Critical Communications / IAM)

📫 Connect


“Identity is the new perimeter — automation is how we secure it.”

Popular repositories Loading

  1. Isuruvh Isuruvh Public

    Config files for my GitHub profile.

  2. msgraph-training-python msgraph-training-python Public

    Completed project for Build Python apps with Microsoft Graph

    Python

  3. auth0-flask-app auth0-flask-app Public

    CSS

  4. entra-graph-python-samples2 entra-graph-python-samples2 Public

    Python

  5. PowerShellMC PowerShellMC Public

    PowerShell examples

    PowerShell

  6. PSIntro PSIntro Public

    A welcome screen for PowerShell and a set of brief tutorials designed for absolute beginners. The module also includes a few commands to help absolute PowerShell beginners manage their environment.

    PowerShell