Back to Developers
Soumya Sundar Biswas

Soumya Sundar Biswas

Security Managed Services Engineer

Kolkata, West Bengal, India 2+ yrs exp 84 · Excellent

About

Security Managed Services Engineer with 2 years of hands-on experience configuring and maintaining SIEM systems, developing and customising security detection rules, monitoring and investigating alerts, and managing security incidents through all response phases to closure. Proficient in Splunk Enterprise, IBM QRadar, and Wazuh EDR — with practical experience in log collection, normalisation, and storage from multiple sources including Windows Security Logs, Linux Syslog, and Firewall logs. Experienced in developing incident response procedures, writing incident reports, reducing false positives, and maintaining thorough SIEM documentation. Familiar with SOAR concepts, UEBA, EDR/XDR, vulnerability scanning, malware analysis, and forensic log analysis techniques. Committed to zero missed SLA conditions and continuous optimisation of SOC toolsets for operational integrity.

Skills & Expertise (44)

IBM QRadar Advanced
8.1/10
1
Years Exp
SIEM administration Advanced
8.1/10
1
Years Exp
Incident detection Advanced
8.1/10
1
Years Exp
Incident Response Advanced
8.1/10
1
Years Exp
Splunk Enterprise Advanced
8.1/10
1
Years Exp
Rest API Intermediate
7.6/10
1
Years Exp
SQL Intermediate
7.6/10
1
Years Exp
Python Intermediate
7.6/10
1
Years Exp
PowerShell Intermediate
7.6/10
1
Years Exp
Kali Linux Intermediate
7.6/10
1
Years Exp
Wazuh EDR Intermediate
7.6/10
1
Years Exp
Windows Server 2022 CIS Controls ISO 27001 NIST JSON XML Batch Shell Scripting Git Active Directory Group Policy DNS DHCP VLANs GitHub VMware Workstation Malware Analysis ServiceNow Jira Service Management SOAR EDR XDR UEBA WIRESHARK Qualys IOC Firewall IDS IPS Proxy VPN Log collection MITRE ATT&CK

Work Experience

Security Operations Engineer & SIEM Architect

NIIT Foundation

May 2025 - Jun 2026

Configured and maintained Splunk Enterprise SIEM and IBM QRadar systems — ensuring proper setup for security event data collection, log normalisation, and storage from multiple sources including Windows Security Logs, Linux Syslog, and Firewall logs across domain-joined enterprise lab environments. Developed, customised, and managed security detection rules within Splunk and IBM QRadar to detect and respond to security threats — engineering use cases for brute-force vectors, privilege escalation, unauthorised account modifications, and lateral movement aligned to MITRE ATT&CK; TTPs. Monitored SIEM alerts continuously, investigated events by severity and nature, and took appropriate response actions — maintaining zero missed SLA conditions across all monitored environments and updating tickets with detailed incident documentation. Managed security incidents through all incident response phases to closure — analysing events from Splunk, QRadar, and Wazuh EDR; writing incident reports; documenting actions taken; and implementing measures to reduce false positives and improve signal fidelity. Developed and documented incident response procedures, playbooks, and SOC runbooks — leading and assisting in incident response efforts across simulated enterprise environments and coordinating with cross-functional teams during active investigations. Ingested and normalised 10GB+ of daily live security event data using Splunk Universal Forwarders; maintained thorough documentation of SIEM configuration, log source inventory, and incident response plans for audit and compliance purposes. Integrated Wazuh EDR/XDR for automated endpoint detection and utilised Wireshark for packet capture (PCAP) analysis and network-level forensic investigation — examining running processes, network connections, and reconstructing event histories. Developed PowerShell and Python automation scripts to streamline common security response tasks, reduce manual effort in log pipeline configuration, and enhance SOC operational efficiency — applying REST API and JSON/XML concepts for tool integration. Collaborated with SIEM solution concepts and vendor documentation to apply updates, patches, and configuration improvements — proactively identifying and reporting system security loopholes, vulnerabilities, and infringements to senior management. Continuously optimised SIEM systems for efficient performance — fine-tuning alert thresholds, reducing noise, and ensuring the platform remained responsive under high log volume ingestion from multi-endpoint environments. Maintained operational integrity of SOC toolsets and ensured SIEM configurations aligned with security policies and compliance requirements — supporting audit readiness across NIST CSF, ISO 27001, and CIS Controls frameworks.

Freelance Web Application Security Assessment

Thou Shine in Life

Jan 2024 - Jan 2025

Performed reconnaissance and vulnerability scanning using Nmap — identifying open ports, running services, and exposed attack surfaces on a nopCommerce-based e-commerce web application; documented all findings with required forensic detail. Investigated and identified root causes of critical security misconfigurations including absent security headers (CSP, HSTS, X-Frame-Options), missing CSRF tokens, insecure password reset flows, and lack of rate limiting — reconstructing event histories and attack vectors using forensic analysis techniques. Audited Ventaforce-developed financial endpoints for IDOR vulnerabilities; developed and delivered a structured 10-point remediation report covering CAPTCHA, input sanitisation, patch management, and access control hardening — maintaining complete incident documentation.

Education

Bachelor of Technology (B.Tech) — Computer Science & Engineering - Academy of Technology

- 2024 · Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 9/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 84/100

Profile Overview

Member sinceJul 2026