Susheel Thapa
Susheel Thapa
Skip to content
Susheel ThapaST
Lalitpur, Nepal•Cloud Security & DevOps

Securing & Automating Cloud Infrastructure

SecOps & DevOps Engineer | Cloud Security, Healthcare Systems & Automation

SecOps and DevOps engineer working across cloud security, DevOps, backend engineering, and healthcare technology environments. Experienced in AWS, Azure, Microsoft Sentinel, Docker, CI/CD, and Auth0 security practices.

Susheel Thapa - Portrait

EXPLORE BY FOCUS & CAPABILITY

🛡️Cloud Defense & SecOps
⚡DevSecOps & CI/CD Security
🔍Threat Hunting & SIEM Operations
☁️AWS & Azure Cloud
🚨Microsoft Sentinel & KQL Detection
🐳Docker & Container Systems
🔒Auth0 & IAM Hardening
🐍Python & Security Automation
📊ELK Stack & Log Telemetry
🏥FHIR / Aidbox & HIPAA Security
🐧Linux Systems & Network Defense
🎯Incident Response & Threat Analysis
01.

Who Am I

Bridging front-line security operations with modern cloud infrastructure and DevOps automation.

Profile Summary
Verified Credentials
⚡
CURRENT ROLE
SecOps / DevOps Engineer
Global Health Information Technology
🎓
ACADEMIC BASE
IOE Pulchowk Campus
B.E. Computer Engineering (< 1% Rate)
🛡️
CERTIFICATIONS
SC-200 • AZ-104 • ISC2 CC
Microsoft & ISC2 Validated
📍
LOCATION
Lalitpur, Nepal
Lalitpur, Nepal (UTC+5:45)

I am a SecOps and DevOps engineer based in Lalitpur, Nepal. I work at the intersection of defensive cybersecurity, cloud infrastructure, and software delivery pipelines—ensuring environments are resilient, observable, and hardened against real-world attack vectors.

My technical background is rooted in enterprise Security Operations Centers (SOCs), operating with certified SC-200 expertise. My daily operations focused on triaging security alerts, authoring KQL detection rules, and conducting threat hunts across Microsoft Sentinel, IBM QRadar, LogPoint, and the ELK Stack across endpoint, network, and multi-cloud environments.

Today, I apply that threat-informed perspective to DevOps & Cloud Architecture at Global Health Information Technology. I build and maintain reliable AWS infrastructure, Python/Flask services, containerized Docker systems, and automated CI/CD pipelines—while engineering Auth0 identity workflows (SSO/MFA), FHIR/Aidbox healthcare data exchanges, and HIPAA/SOC 2-aligned security controls.

02.

Featured Projects

Hands-on SIEM telemetry pipelines, log ingestion architectures, and secure systems automation.

03.

Career Milestones

Chronological progression across engineering positions, academic foundations, and industry certifications.

May 2026 — Present•JOINED

SecOps/DevOps Engineer

Global Health Information Technology•Lalitpur, Nepal
Jun 2025 — May 2026•COMPLETED

SOC Analyst

Vairav Technology•Kathmandu, Nepal
Apr 2026•CERTIFIED

Microsoft Certified: Azure Administrator Associate

Microsoft • AZ-104•Verify Credential↗
Feb 2026•CERTIFIED

Microsoft Certified: Security Operations Analyst Associate

Microsoft • SC-200•Verify Credential↗
Jul 2025•CERTIFIED

ISC2 Certified in Cybersecurity

ISC2 • CC•Verify Credential↗
May 2021 — Apr 2025•GRADUATED

Bachelor in Computer Engineering

Tribhuvan University, IOE Pulchowk Campus•Lalitpur, Nepal
Aug 2024•CERTIFIED

AWS Academy Graduate – AWS Academy Cloud Foundations

Amazon Web Services • AWS Academy
Jul 2018 — Nov 2020•GRADUATED

Higher Secondary School

Sainik Awasiya Mahavidyalaya•Khairahani, Chitwan
04.

Our Security Philosophy

How we protect our systems, data, and users at every step of building and running software.

01 // BUILDING SECURELY

Check for Mistakes Early

Security shouldn't be a last-minute scramble right before launch. By automatically checking code for bugs, outdated software, and leaked passwords while developers write it, we fix risks before they ever reach our customers.

02 // SYSTEM DESIGN

Trust No One by Default

A single locked front door isn't enough. We design every part of our system to verify who is asking for access—every time. Even if someone manages to sneak in, strict limits ensure they can't access sensitive information or move around freely.

03 // CLOUD SETUP

Replace, Don't Tweak

Instead of making manual changes to live servers where mistakes can hide, we build our entire setup using blueprint scripts. If something breaks or needs an update, we replace it with a fresh, pre-approved version that strictly follows company safety rules.

04 // MONITORING

Clear Alerts, Fast Action

Too many false alarms cause teams to miss real threats. We track activity across our systems and connect the dots so our team gets clear, reliable alerts—enabling us to spot suspicious behavior and respond immediately.