Soumya ES is a Senior Security Engineer with 13+ years of experience in Cyber Security, specializing in security strategy, vulnerability assessments, and secure development practices. Vetted by Witarist and ready to join your team within 48 hours.
Founded a Cyber Security Startup providing consulting and solutions.
Implemented NIST RMF for a business unit, creating comprehensive risk documentation.
Managed the SmartThings Bug Bounty Program to enhance platform security.
Trained development teams on Secure Development practices across multiple engagements.
Conducted security assessments including manual and automated penetration testing.
Drove and oversaw security processes throughout the SDLC for 10+ different projects and teams.
Delivered specialized cyber security trainings and consulting services for multiple clients.
Conducted comprehensive security assessments including manual and automated penetration testing for various clients.
Overview: Provides independent information security consulting services for clients. Responsibilities: Conducts Vulnerability Assessments, Third Party Risk Assessments, and Threat Modeling. Performs Architecture Reviews and PenTesting (Manual, SAST and DAST). Develops Security Documentation for various client engagements.
Key outcomes:
Delivered specialized cyber security trainings and consulting services.
Performed comprehensive security assessments including manual and automated penetration testing.
Overview: Performed comprehensive security testing for the SmartThings IoT Platform. Responsibilities: Conducted Manual Pen Testing, SAST, DAST of web, mobile applications, microservices, and devices. Managed the SmartThings Bug Bounty Program to enhance platform security. Established security guidelines and documentation for all testing procedures and best practices.
Key outcomes:
Managed the SmartThings Bug Bounty Program.
Established security guidelines and documentation for all testing procedures.
Overview: Guided security strategy as a Business Information Security Officer based on central security team inputs. Responsibilities: Created Business Impact Analysis, Risk Assessment, and Mitigation Plan documentation for all projects. Tracked and reported the security status of projects to higher management.
Key outcomes:
Implemented NIST RMF for the Business Unit and created comprehensive risk documentation.
Oversaw security processes across 10+ projects and teams throughout the SDLC.
Key outcomes:
Conducted internal and external network infrastructure security reviews.
Performed third-party vendor risk assessments, ensuring compliance with client requirements.
Key outcomes:
Gained hands-on experience with industry-standard dynamic analysis tools for web application security.
SOUMYA ES
Cybersecurity Engineer