Susheel Thapa

Bridging Security Operations and DevSecOps to Deliver Secure Infrastructure

I am a Computer Engineering graduate with professional experience in security operations and a strong foundation in systems, networking, and infrastructure.

My early career focused on working in a production Security Operations Center, analyzing logs, participating in incident response workflows, and gaining exposure to real-world security monitoring across enterprise and cloud environments.

I am now expanding toward DevSecOps and secure systems engineering, with interest in building resilient infrastructure, automating secure deployments, and integrating security into the software delivery lifecycle.

CSOC Analyst

Vairav Technology · June 2025 – Present

  • Monitored and responded to security events across enterprise systems, endpoints, and cloud environments
  • Performed log analysis and correlation across centralized monitoring platforms to identify anomalies
  • Participated in incident response workflows including triage, escalation, and post-incident analysis
  • Gained hands-on exposure to SIEM platforms, endpoint security, and cloud logs (AWS/GCP)

Bachelor in Computer Engineering

IOE Pulchowk Campus · Apr 2021 – Apr 2025

Relevant Coursework: Artificial Intelligence, Distributed Systems, Probability & Statistics, Linux Administration, Computer Networks, Operating Systems, Internet & Intranet

Higher Secondary

Sainik Awasiya Mahavidyalaya, Chitwan · Jul 2018 – Nov 2020

Security Operations & Monitoring

SIEM Platforms (QRadar, ELK Stack, Sentinel, LogPoint), Log Analysis, Incident Triage

Systems & Infrastructure

Linux Systems, Networking Fundamentals, SSH & Access Control, System Hardening, Virtualization & Lab Environments, Configuration Management

DevOps & Automation

CI/CD Pipelines, GitOps Workflows, Ansible, Containerization (Docker)

Programming & Scripting

C / C++, Javascript/Typescript, Python, SQL, Bash Scripting

Research & Applied Security Interests

Computer Virus Mutation, DevSecOps Practices, Secure Software Systems, AI-assisted Intrusion Detection, Security Automation & Resilience Engineering

Secure Offline Software Update Distribution System

  • Designed a multi-VM air-gapped network to securely distribute software updates in isolated environments
  • Implemented a gateway–bastion–repository–client architecture with SSH jump-only access and key-based authentication
  • Configured Aptly and GPG to index, sign, and publish packages via Lighttpd, ensuring integrity and authenticity
Linux Networking VMware Aptly Lighttpd GPG SSH

GitOps Deployment Pipeline

  • Built reproducible CI/CD pipelines using Docker and Ansible for simulated infrastructure
  • Automated builds and deployments with GitHub Actions, ensuring secure and validated rollouts
  • Maintained environment separation and controlled traffic routing via Nginx for blue-green deployments
Docker Ansible GitHub Actions Nginx VMware

Mini SIEM and Security Monitoring Lab

  • Built a multi-VM security monitoring lab using ELK Stack across Windows and Linux systems
  • Forwarded logs via Filebeat and Winlogbeat to centralize analysis and detect anomalous activity
  • Simulated network reconnaissance using Nmap and monitored Snort IDS outputs through Kibana dashboards
ELK Stack Filebeat Winlogbeat Snort IDS

Enterprise Network Design & Simulation

  • Designed a scalable campus network with 35 routers, multiple VLANs, and inter-area OSPF routing
  • Implemented redundant services including DHCP, DNS, and web servers for high availability
  • Simulated routing and segmentation to demonstrate reliability, fault tolerance, and secure network principles
Cisco Packet Tracer OSPF VLANs IPv4/IPv6 Routing DNS/DHCP

ISC2 Certified in Cybersecurity (CC)

International Information System Security Certification Consortium · 2024

AWS Cloud Fundamentals Training

Amazon Web Services · 2024