Open to conversations

Sumit Kant Jha

Security Operations Engineer II  ·  Corporate security, endpoint & security data

I build the systems that tell a company whether its fleet is actually safe — and I argue about what the numbers mean before I build them. Two years in security operations taught me that most disagreements about risk are really disagreements about definitions.

Sumit Kant Jha
—
years in security
Corporate
security focus
—
certifications
Bengaluru
based

About

Where this started

I came into security the long way round, through the parts of the industry nobody puts on a poster. Computer science at Haldia, then a support internship watching cloud dashboards, then a short contract on a firewall support desk reading other people's packet captures at two in the morning. None of it was glamorous. All of it turned out to be the actual education — you cannot write a good detection for traffic you've never had to explain to an angry customer.

The move into a 24×7 SOC was where it clicked. Triage teaches you something a course can't: that the hard problem in security operations usually isn't knowing what an alert means, it's the twenty minutes of gathering context before you can even start thinking. Eighteen months of that taught me what normal looks like, which is the only way to recognise what isn't.

A year of remote contract work sat in the middle of that. It was less comfortable than a salaried seat and considerably more instructive: no team to escalate to, no house style to inherit, and every conclusion had to be written down clearly enough for someone non-technical to act on it.

In May 2026 I moved to corporate security, which meant crossing to the other side of the alert queue — building the controls and the measurement rather than responding to what got through. It turns out the work I enjoy most is the unglamorous part: getting several teams to agree what a number actually means, publishing how it is calculated, and then fixing it in public when somebody proves it wrong. On my own time I build with language models, and I'm deliberately careful about that — putting a model near an investigation is easy, making it trustworthy is the interesting problem.

Journey

The whole path, not just the last stop

Education, the early roles, the sideways moves, and how each one led to the next. Written to be read start to finish rather than skimmed.

Focus

What I work on

Described by the shape of the problem rather than the detail of any one environment.

Skills

Sorted honestly

No percentage bars. Three buckets: what I'd own in a room, what I use well, and what I'm actively building.

Credentials

Certifications and education

Certifications are a floor, not a ceiling — but they're an honest signal that the fundamentals were done properly rather than picked up by osmosis.

Work log

A running record

Short entries added as things ship. Partly a portfolio, mostly a memory — it's easy to lose track of what a year actually contained.

Contact

Let's talk

Happy to hear from people working on security programmes, endpoint or security data, anyone earlier in their security career who wants a hand, or teams building something interesting.

Resume available on request — just ask by email and I'll send it over.