Skip to content
View Isuruvh's full-sized avatar
  • 07:08 (UTC +11:00)

Block or report Isuruvh

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Isuruvh/README.md

👋 Hi, I'm Isuru Heendeniya

Senior IAM & Cloud Automation Engineer | Transmission & Critical Infrastructure Specialist

I design, automate, and secure identity platforms for enterprise, telco, and critical infrastructure environments.
My work sits at the intersection of IAM, PKI, PAM, Azure, and network reliability — with a validator mindset that prioritises operational truth, audit‑grade documentation, and clean, modular engineering.


🔐 Identity, Security & Cloud Focus

  • Azure AD / Entra ID architecture
  • Hybrid identity (AD + AAD Connect + Cloud Sync)
  • Conditional Access, PIM, RBAC, Zero Trust
  • PKI (ADCS, Keyfactor, Venafi), certificate lifecycle automation
  • PAM (CyberArk, BeyondTrust)
  • MS Graph automation (Python + PowerShell)
  • Terraform, Bicep, ARM for identity & security infrastructure

⚙️ Automation & Engineering

  • Python automation for IAM, PKI, and cloud operations
  • Terraform modules for identity, networking, and security baselines
  • Bicep templates for Azure landing zones
  • MS Graph + REST API integrations
  • CI/CD pipelines for identity configuration and compliance
  • Modular, testable, production‑grade engineering

🛰️ Transmission & Critical Infrastructure Background

Before specialising in IAM, I engineered and supported mission‑critical networks across:

  • SDH/PDH, DWDM, OTN
  • MPLS, microwave, fibre
  • Multi‑vendor environments (Ericsson, Huawei, Nokia, Cisco)
  • High‑pressure fault diagnosis and service restoration
  • Preventative & corrective maintenance
  • Operational reliability for telco and transport networks

This gives me a unique blend of identity + infrastructure thinking — ideal for organisations where uptime, safety, and security are non‑negotiable.


📂 Featured Work (in progress)

🔧 iam-automation

A modular, enterprise‑grade IAM automation repository featuring:

  • Azure AD / Entra ID automation
  • PKI lifecycle workflows
  • PAM onboarding automation
  • Terraform/Bicep identity modules
  • MS Graph Python SDK examples
  • Architecture diagrams & operational runbooks

🧩 terraform-iam-modules (coming soon)

Reusable Terraform modules for identity, security, and compliance.

🔐 pki-lab (coming soon)

A hands‑on PKI lab with ADCS, certificate automation, and security hardening.


🎯 Current Goals

  • Build a complete IAM + PKI + PAM automation portfolio
  • Complete SC‑300, AZ‑204, AZ‑800/801, SC‑100, Terraform Associate
  • Target roles in:
    • Sydney Trains (Technical Specialist – Transmission / Identity)
    • Optus (Service Design & Delivery)
    • BAI Communications (Critical Communications / IAM)

📫 Connect


“Identity is the new perimeter — automation is how we secure it.”

Popular repositories Loading

  1. Isuruvh Isuruvh Public

    Config files for my GitHub profile.

  2. iam-automation iam-automation Public

    IAM Automation Platform using Python

    Python

  3. samples samples Public

    My copy of Samples

    Bicep

  4. graph-with-dotnetcore graph-with-dotnetcore Public

    Microsoft Learn code for the Microsoft Graph/.NET Core scenarios learning path.

    C#

  5. msgraph-training-dotnet msgraph-training-dotnet Public

    Microsoft Graph Training Module - Build .NET apps with Microsoft Graph

    C#

  6. msgraph-training-powershell msgraph-training-powershell Public

    Completed project for Build PowerShell apps with Microsoft Graph

    PowerShell