I’m a Software Engineering graduate with practical experience building backend and full-stack applications using Java, Python, Flask, JavaScript, React, REST APIs, SQL and NoSQL databases.
I hold a BSc (Hons) Software Engineering (2:1) from the University of Plymouth and am completing an MSc in Cybersecurity at the University of the West of Scotland.
My main focus is backend and secure software engineering — designing maintainable APIs, application logic, database integrations and cloud-connected systems while applying secure coding and software engineering best practices.
- Java
- Python
- Flask
- RESTful APIs
- Object-Oriented Programming
- Authentication, JWT, OAuth 2.0 & RBAC
- SQL & NoSQL databases
- API integration and backend architecture
- React
- JavaScript
- TypeScript
- HTML & CSS
- REST API integration
- Responsive web interfaces
- Microsoft Azure
- AWS
- Docker
- Git & GitHub
- CI/CD
- GitHub Codespaces
- Linux
- Application monitoring & logging
- pytest
- JUnit
- Unit & integration testing
- Debugging & troubleshooting
- Code reviews
- Refactoring
- Clean code
- Agile / Scrum
- OWASP Top 10
- Secure coding
- Authentication & access control
- Vulnerability management
- Cyber Threat Intelligence
- Incident response fundamentals
- Cloud security
- Penetration testing concepts
I designed and developed an AI-assisted dependency risk analysis platform that combines software dependency information with public vulnerability intelligence.
Tech: Python · Flask · React · Vite · Qwen3.5-9B · LoRA · PyTorch · Transformers · PEFT
The system:
- Analyses
package.jsonand lock files to extract software dependencies and versions. - Uses historical CVE and public CTI data to identify vulnerability evidence.
- Processes approximately 10 years of public CVE records (2016–2026) using Python data-processing pipelines.
- Uses a Qwen3.5-9B + LoRA workflow for structured vulnerability analysis.
- Generates risk levels, confidence scores, vulnerability evidence and remediation recommendations.
- Provides results through a React frontend connected to a Flask REST API backend.
The project focuses on evidence-based candidate zero-day risk analysis rather than claiming to predict confirmed future zero-day vulnerabilities.
Worked on client-facing applications involving:
- Java & Python backend development
- Flask APIs
- REST API development and integration
- SQL & NoSQL databases
- Authentication and RBAC
- Git/GitHub workflows
- Cloud services
- Debugging and application maintenance
Worked within the Centre for Defence Research & Development, Ministry of Defence, Sri Lanka on an early flood-warning platform involving:
- Real-time sensor-data processing
- Azure IoT Hub
- Azure Functions
- Monitoring and logging
- Data validation
- Reliability-focused software engineering
Languages
Java Python JavaScript TypeScript SQL
Backend
Flask Node.js Express.js REST APIs
Frontend
React Vite HTML CSS
Databases
MongoDB PostgreSQL MySQL
Cloud & DevOps
Azure AWS Docker Git GitHub CI/CD Linux
AI & Cybersecurity
PyTorch Qwen LoRA RAG OWASP CTI Vulnerability Management
- Strengthening Java backend development
- Building production-style applications with Python & Flask
- Improving data structures and algorithms
- Designing scalable REST APIs
- Building secure backend systems
- AWS & cloud engineering
- Docker and CI/CD
- Secure software development
- AI-assisted cybersecurity applications
📧 Email: supun2001hasanka@gmail.com 🌐 Portfolio: supunhasanka.tech 📝 Blog: supunhasanka.tech/blog 💼 LinkedIn: linkedin.com/in/supun-hasanka-908741186
Software engineer by discipline. Security-aware by design. Always building, learning and improving.
