About

Shreenkhala Bhattarai

Head of Security Operations, cybersecurity practitioner and security researcher, Kathmandu, Nepal.

Who I am

I'm Shreenkhala Bhattarai, Head of Security Operations atCryptoGen Nepal. I lead a managed Security Operations Center: the strategy, the technology roadmap, the escalations and the people. Our clients depend on it around the clock. Before leading it, I worked in it: four years as a SOC analyst on a 24/7 rotation, then as SOC Team Lead. I know what a night shift alert queue feels like, and I run the SOC accordingly.

My journey into cybersecurity

My academic background is in physics, with a foundation in mathematics and computer science, and honestly, that training in building models from incomplete evidence is the most transferable skill I brought into security. I joined CryptoGen Nepal as a cybersecurity analyst in 2019, moved into the 24/7 SOC, and grew with it: analyst, team lead, and now head of the operation. I'm currently pursuing a Master of Science in Cybersecurity at Westcliff University.

Current focus

Three things occupy most of my time: making security operations measurably effective (not just busy), building detection capability, from log source strategy through SIEM content to hunting, and sharing practical knowledge through InfoSec Stories and mentoring. I serve as an ITU incident response mentor and teach cybersecurity as an academic professor at KFA, bringing real SOC scenarios into the classroom.

Areas of expertise

  • Security operations and SOC leadership
  • SIEM implementation, parser development and detection engineering (LogRhythm, Logpoint, FortiSIEM, Splunk, Wazuh)
  • Incident response and DFIR
  • Threat hunting and threat intelligence
  • Security automation with TheHive, Cortex and SOAR playbooks
  • Security monitoring strategy for Windows and Linux telemetry

How I approach security

I believe most security failures are visibility failures. Long before an environment needs a clever detection, it needs the right logs, parsed correctly, in front of an analyst who has the context to read them. So I bias toward fundamentals: telemetry first, process second, tools third. I'd rather have ten detections the team trusts and tests than a hundred nobody maintains.

The same applies to people. A SOC is a team sport played at 3 a.m.; playbooks, training exercises and honest post-incident reviews matter more than any single product decision. And knowledge that stays in one analyst's head, or one organization's knowledge base, is knowledge the field loses, which is why I share notes and mentor.