Nehemiya Wickramasinghe
// Security Researcher & Software Engineer

Nehemiya Wickramasinghe

$
01

About

Independent security researcher specializing in manual source code auditing across low-level systems: blockchain VMs, cryptographic libraries, embedded engines, and infrastructure platforms. No automated scanners. Every finding comes from reading code line by line in containerized environments.


Currently working on AI training data systems for frontier model development and conducting security research across multiple bug bounty programs.

TryHackMe
Top 1%
Focus
Source Auditing
Disclosure
CVE Assigned
Interests
Arduino & IoT
02

Tech Stack

Languages

CC++RustGoPythonJavaTypeScriptJavaScriptSoliditySQL

Security

Burp SuiteWiresharkSource Code AuditingMemory CorruptionAuth BypassBlockchain ConsensusCrypto AnalysisSSL/TLS

Cloud & Infra

AWSAzureGCPDockerKubernetesTerraformVMware ESXipfSense

DevOps & Tools

GitLab CI/CDGitHub ActionsLinux AdminJiraConfluenceNotion
03

Projects & Research

CVE / Vulnerability Research

CVE Discovery: Monitoring Platform

Found an integer overflow in a widely-used monitoring platform's C source through manual auditing in Docker. Wrote a working PoC demonstrating the crash. CVE assigned.

CDockerManual Audit
Blockchain Security

Blockchain VM Allocator Audit

Analyzed a blockchain VM allocator for resource limit bypass. Identified state rollback inconsistencies in mempool block construction that could cause invalid block production.

RustPython
DeFi Security

DeFi Protocol SDK Audit

Audited transfer verification logic in a DeFi protocol SDK. Identified missing validation of leaf values, refund outputs, and timelocks during transfer receipt.

TypeScript
AI / ML Infrastructure

AI Training Data Pipeline

Built coding task specs, test suites, and QA for training frontier AI models through RL. Created automated tooling for identifying high-complexity commits and calibrating task difficulty.

C++RustPython
Open Source

iExtract: iTunes Backup Tool

Tool to extract and back up iMessages/SMS from iTunes backups into CSV. Modular architecture with full documentation, UI, and installer supporting large backups.

Python
Infrastructure

Home Lab & Cloud Ops

VMware ESXi servers, pfSense firewall, network monitoring, cloud deployment with AWS and Terraform. CI/CD pipelines via GitLab. Simulated ransomware recovery drills.

AWSTerraformESXi
Responsible Disclosure

Vulnerability Disclosure

Independently discovered and responsibly disclosed vulnerabilities in production systems.

Security Research
Methodology

Meta-Prompt Generator for Auditing

Systematic methodology for auditing open source repos with Q0/Q1/Q2 quality gates: clone, containerize, trace execution paths, identify logic bugs, write PoCs, provide fixes.

SecurityAutomation
04

Certifications

Google Cybersecurity Professional Certificate V2
ISC2 Cybersecurity Fundamentals
DevSecOps Certificate / TryHackMe
LFS158: Introduction to Kubernetes / Linux Foundation
Ethical Hacker / Cisco
AWS Educate: Getting Started with Security
05

Contact

GitHub
nehemiyawicks
LinkedIn
nehemiya-wickramasinghe
HackerOne
nwicks
Email
nehemiyawicks@gmail.com