
Lightweight SIEM Deployment (ELK Stack & Beats)
Practical implementation of a Security Information and Event Management (SIEM) system using Elasticsearch, Logstash, Kibana, Filebeat, and Winlogbeat.
SecOps & DevOps Engineer | Cloud Security, Healthcare Systems & Automation
SecOps and DevOps engineer working across cloud security, DevOps, backend engineering, and healthcare technology environments. Experienced in AWS, Azure, Microsoft Sentinel, Docker, CI/CD, and Auth0 security practices.
EXPLORE BY FOCUS & CAPABILITY
Bridging front-line security operations with modern cloud infrastructure and DevOps automation.
I am a SecOps and DevOps engineer based in Lalitpur, Nepal. I work at the intersection of defensive cybersecurity, cloud infrastructure, and software delivery pipelines—ensuring environments are resilient, observable, and hardened against real-world attack vectors.
My technical background is rooted in enterprise Security Operations Centers (SOCs), operating with certified SC-200 expertise. My daily operations focused on triaging security alerts, authoring KQL detection rules, and conducting threat hunts across Microsoft Sentinel, IBM QRadar, LogPoint, and the ELK Stack across endpoint, network, and multi-cloud environments.
Today, I apply that threat-informed perspective to DevOps & Cloud Architecture at Global Health Information Technology. I build and maintain reliable AWS infrastructure, Python/Flask services, containerized Docker systems, and automated CI/CD pipelines—while engineering Auth0 identity workflows (SSO/MFA), FHIR/Aidbox healthcare data exchanges, and HIPAA/SOC 2-aligned security controls.
Hands-on SIEM telemetry pipelines, log ingestion architectures, and secure systems automation.

Practical implementation of a Security Information and Event Management (SIEM) system using Elasticsearch, Logstash, Kibana, Filebeat, and Winlogbeat.

Reproducible, trusted software delivery pipeline simulating secure package updates and cryptographic verification for isolated air-gapped networks.
Chronological progression across engineering positions, academic foundations, and industry certifications.
How we protect our systems, data, and users at every step of building and running software.
Security shouldn't be a last-minute scramble right before launch. By automatically checking code for bugs, outdated software, and leaked passwords while developers write it, we fix risks before they ever reach our customers.
A single locked front door isn't enough. We design every part of our system to verify who is asking for access—every time. Even if someone manages to sneak in, strict limits ensure they can't access sensitive information or move around freely.
Instead of making manual changes to live servers where mistakes can hide, we build our entire setup using blueprint scripts. If something breaks or needs an update, we replace it with a fresh, pre-approved version that strictly follows company safety rules.
Too many false alarms cause teams to miss real threats. We track activity across our systems and connect the dots so our team gets clear, reliable alerts—enabling us to spot suspicious behavior and respond immediately.