Who I am
I'm Shreenkhala Bhattarai, Head of Security Operations atCryptoGen Nepal. I lead a managed Security Operations Center: the strategy, the technology roadmap, the escalations and the people. Our clients depend on it around the clock. Before leading it, I worked in it: four years as a SOC analyst on a 24/7 rotation, then as SOC Team Lead. I know what a night shift alert queue feels like, and I run the SOC accordingly.
My journey into cybersecurity
My academic background is in physics, with a foundation in mathematics and computer science, and honestly, that training in building models from incomplete evidence is the most transferable skill I brought into security. I joined CryptoGen Nepal as a cybersecurity analyst in 2019, moved into the 24/7 SOC, and grew with it: analyst, team lead, and now head of the operation. I'm currently pursuing a Master of Science in Cybersecurity at Westcliff University.
Current focus
Three things occupy most of my time: making security operations measurably effective (not just busy), building detection capability, from log source strategy through SIEM content to hunting, and sharing practical knowledge through InfoSec Stories and mentoring. I serve as an ITU incident response mentor and teach cybersecurity as an academic professor at KFA, bringing real SOC scenarios into the classroom.
Areas of expertise
- Security operations and SOC leadership
- SIEM implementation, parser development and detection engineering (LogRhythm, Logpoint, FortiSIEM, Splunk, Wazuh)
- Incident response and DFIR
- Threat hunting and threat intelligence
- Security automation with TheHive, Cortex and SOAR playbooks
- Security monitoring strategy for Windows and Linux telemetry
How I approach security
I believe most security failures are visibility failures. Long before an environment needs a clever detection, it needs the right logs, parsed correctly, in front of an analyst who has the context to read them. So I bias toward fundamentals: telemetry first, process second, tools third. I'd rather have ten detections the team trusts and tests than a hundred nobody maintains.
The same applies to people. A SOC is a team sport played at 3 a.m.; playbooks, training exercises and honest post-incident reviews matter more than any single product decision. And knowledge that stays in one analyst's head, or one organization's knowledge base, is knowledge the field loses, which is why I share notes and mentor.