Soumya M B
@soumyamb
I uncover web and network vulnerabilities and deliver actionable remediation guidance.
What I'm looking for
I've conducted web application and network VAPT engagements at ActivBytes, identifying vulnerabilities across client-facing applications using Burp Suite, Nmap, Nessus, Wireshark, and Kali Linux.
I assess risk with CVSS scoring and produce structured reports with prioritized remediation guidance aligned to the OWASP Top 10 and OWASP API Security Top 10. My findings have included SQL Injection, XSS, IDOR, and authentication flaws.
Before moving into cybersecurity, I developed production web applications at Softnotions and worked with REST APIs, Swagger, relational databases, Node.js, and JavaScript at ENTLOGICS. That development background helps me understand how security weaknesses are introduced at the code level.
I've also practiced reconnaissance, directory discovery, password cracking, reverse shells, and secure JWT-based authentication in controlled lab environments. I'm looking to bring this developer-security mindset to a forward-thinking security team.
Experience
Work history, roles, and key accomplishments
Cybersecurity Analyst
ActivBytes
Sep 2023 - Feb 2024 (5 months)
Conducted web application and network VAPT engagements using Burp Suite, Nmap, and Nessus, identifying and exploiting vulnerabilities aligned with OWASP Top 10 and OWASP API Security Top 10. Performed vulnerability assessment and risk analysis, assigning CVSS scores and delivering structured technical reports with risk classification and prioritized remediation recommendations.
Cybersecurity Intern
ActivBytes
Feb 2023 - Apr 2023 (2 months)
Assisted in web application and network penetration testing engagements under senior analyst supervision. Performed vulnerability scanning and reconnaissance using Burp Suite and Nmap; documented findings for inclusion in client reports.
Software Engineer
Softnotions
Jul 2022 - Jan 2023 (6 months)
Contributed to development and maintenance of production-level web applications using Node.js and JavaScript. Debugged and resolved application issues to improve performance, reliability, and security posture.
Associate Software Engineer
ENTLOGICS
Feb 2022 - Apr 2022 (2 months)
Deployed and managed web applications and relational databases; developed and documented REST APIs using Swagger. Performed API testing and validation, identifying functional and security-related issues prior to production release.
Software Engineer
Worked as a software engineer at LinkedIn, contributing to the platform's development and maintenance.
Education
Degrees, certifications, and relevant coursework
APISec University
OWASP API Security Top 10, API Security
Completed OWASP API Security Top 10 training in 2023.
ICT Academy of Kerala
Certified Specialist, Full-Stack Development
Certified Specialist in Full-Stack Development from ICT Academy of Kerala in 2022.
St. Albert's College, Ernakulam
Post Graduation, Post Graduation
Post Graduation from St. Albert's College, Ernakulam.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Portfolio
github.com/soumyamb98Social media
Job categories
Skills
Interested in hiring Soumya ?
You can contact Soumya and 90k+ other talented remote workers on Himalayas.
Message SoumyaGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
