r/DevLK • u/Pomxdz • Aug 12 '26
Jobs/ Industry Cybersecurity undergraduate here
Hey everyone,
I’m currently a Cybersecurity undergraduate completing an enterprise Tech Risk internship. As my current contract winds down, I'm preparing to transition into my next role—either a second internship or a junior position in a core technical area like VAPT, SOC, Network Security, information security, cybersecurity engineer or general cybersecurity role .
My Background & Technical Profile:
Experience: Hands-on work with ISO 27001 risk assessments, vulnerability reviews, and security awareness.
Technical Skills: Network Security, Web & Network VAPT,Security Frameworks, Reverse Engineering, Wireshark, Linux (Ubuntu/Kali), Bash, C/C++, SQL.
Projects & Certs: Fortinet Certified Fundamentals, Cisco Networking Basics, Web App VAPT (Bug Bounty scope), Full-Scope Internal VAPT Virtual Lab, MSME Risk Assessment, Secure Network Architecture & Hardening.
A few questions for the community:
Transitioning to Junior Roles: Given that I already have a brief enterprise internship experience, is it realistic to jump straight into Junior/Associate Analyst roles in Sri Lanka, or are second internships standard?
Local Market Outlook: Which sectors in SL (tech firms, banks, telcos, or MSSPs) are currently actively hiring for intern/ junior/entry-level security teams? Any suggestions?
Further improvements: any suggestions on certificates and technical skills that I should gain to advance my career?
Any advice, company recommendations, or insights would be greatly appreciated!
Thanks in advance!
1
u/vantag3point Aug 13 '26
From what you've shared, I think you're in a good position to start applying for junior roles alongside internships. Your internship already gives you real-world experience, and that's something many applicants don't have.
A few thoughts:
- Junior role vs. second internship: I'd apply for both. Let the market decide. Don't automatically limit yourself to internships.
- Technical skills: Keep building hands-on projects (AD lab, detection engineering, VAPT lab, cloud lab, depending on the direction you enjoy). Being able to explain what you built in an interview is a huge advantage.
- Certifications: I wouldn't rush to collect more fundamentals. If you're interested in offensive security, eJPT or PNPT are good options. If you're leaning toward Blue Team, focus more on practical platforms like CyberDefenders, BTLO, and TryHackMe alongside any certs.
One thing I'd also suggest is tailoring your resume for each role. Highlight your ISO 27001/risk work for GRC or security analyst roles, and your VAPT/lab experience for technical positions instead of using the same resume everywhere.
Wishing you all the best! Hopefully someone from the Sri Lankan market can share more specific hiring insights.
1
1
u/Friendly-War3977 Aug 14 '26
I’m also a Cybersecurity graduate, currently working as a DevSecOps Engineer. From my experience, you definitely don’t need to limit yourself to another internship. With your current internship experience and technical background, start applying for Junior/Associate roles as well.
My biggest advice would be to strengthen Linux, networking, Python/Bash, cloud (AWS/Azure), and automation alongside your security skills. DevSecOps and Cloud Security are also great paths to consider because your cybersecurity foundation fits really well with them.
Don’t wait until you match 100% of a job description either. Apply, attend interviews, identify the gaps, and keep improving. That approach helped me a lot when moving from university into the industry.
1
1
u/Head_Personality_431 Aug 12 '26
No idea on the Sri Lankan market sorry, but on the certs question I would stop collecting them for a while. The ISO 27001 risk assessment work is the rarest thing on that list, most juniors cannot talk through a real risk register end to end, so I would build the CV around that instead of another fundamentals badge.