Skip to content

Cyber Screenshot Boot

Secure desktop snapshot assembling

Frozen interface cards, cyan telemetry, and a fast boot pass that feels technical without overwhelming the portfolio.

CI/CD Cloud Ops Security

Terminal + HUD Loader

Command surface synchronizing

Name Scan Reveal

Identity signature locking in

The cleanest option: a focused scanline reveal around your name with a restrained premium glow.

SL

Subash Lama Subash Lama Subash Lama

12+ years of enterprise IT operations, now fully focused on cybersecurity — I build detection rules, triage alerts, and map controls to NIST CSF, CIS, and ISO 27001. Available immediately for SOC / GRC / IAM roles.

SOC · GRC · IAM · CTI · Wazuh · Suricata · Sysmon · Docker · IaC · Cisco

Available for roles Open to Cybersecurity / SOC / GRC / IAM roles --:-- NPT
12+Years IT
7Certs
3Labs Built
150+Endpoints
📚
Currently Studying Elastic Stack (ELK)

About Me

I am a Cybersecurity Analyst with 12+ years in IT and a business degree, with hands-on experience in security operations, detection engineering, and GRC.

My enterprise IT background spans system administration at Primuson Pvt. Ltd., network support engineering at Green IT Solutions Pvt. Ltd., and IT contract deployments at State Bank of India and Unilever on behalf of Green IT Solutions. This gives me a deep operational foundation for understanding how attackers move through real infrastructure.

I built a personal SOC lab using Wazuh, Suricata, and Sysmon for host visibility, network telemetry, log collection, and real-time detection practice — while earning Cisco certifications in Ethical Hacking and Endpoint Security, and IBM credentials in Cybersecurity Fundamentals and Python for Data Science.

What I bring: A business-minded perspective combined with deep hands-on IT operations experience, now applied to threat detection, governance, risk & compliance, and identity & access management.
Portfolio Security Posture:
✓ Strict CSP ✓ HSTS ✓ No-Referrer ✓ No-Clickjack ✓ No-MIME-Sniff ✓ SRI ✓ Permissions-Policy ✓ security.txt 🔗 Headers 🔗 Observatory 🔗 SSL Labs 📜 Policy
Languages: Nepali (native) · English (professional working proficiency) · French (elementary, actively studying)

Experience

Information Technology System Administrator

Jan 2020 – Feb 2026 · 6 yrs 2 mos

Primuson Pvt. Ltd. · Full-time · Lazimpat, Kathmandu · On-site

  • Managed 150+ endpoints and multi-site infrastructure across 3 office locations
  • Deployed IDS/network monitoring stack, reducing security visibility gaps across the environment
  • Standardised patch management cycle, cutting unplanned downtime by ~40%
  • Led ethical hacking exercises to identify and remediate internal vulnerabilities

Ethical Hacking · Network Monitoring · System Administration · IDS · Infrastructure Security

Information Technology Specialist

Mar 2018 – Apr 2019 · 1 yr 2 mos

State Bank of India · Contract · via Green IT Solutions Pvt. Ltd. · Kathmandu · Hybrid

  • Administered Active Directory for 200+ banking staff across Kathmandu branches
  • Configured and hardened proxy server routing all outbound banking traffic
  • Enforced endpoint security policies across 80+ workstations meeting banking compliance standards

Proxy Server · Active Directory · Identity Management · Endpoint Security

Support Engineer

Mar 2016 – Apr 2019 · 3 yrs 2 mos

Green IT Solutions Pvt. Ltd. · Full-time · Kathmandu

  • Delivered network and infrastructure support across 20+ client organisations
  • Managed SAN/storage virtualisation deployments for enterprise clients
  • Maintained Linux server environments achieving 99%+ uptime across client engagements

Storage Virtualization · Proxy Server · Network Support · Linux Administration

Information Technology Consultant

Jan 2017 – Dec 2017 · 1 yr

Unilever · Contract · via Green IT Solutions Pvt. Ltd. · Nepal · Hybrid

  • Consulted on IT governance and infrastructure for FMCG operations across Nepal
  • Designed and documented Cisco network topology for distribution facilities
  • Supported Active Directory migration aligned with Unilever global IT standards

Cisco Networking · Active Directory · IT Governance · Infrastructure Consulting

Information Technology Trainee

Mar 2014 – May 2016 · 2 yrs 3 mos

Platinum Hotel & SPA · Full-time · Soltemode · On-site

  • Provided end-to-end IT support for 100+ hospitality staff across hotel operations
  • Managed POS system integration and network connectivity for hotel services

IT Support · Networking · Systems Troubleshooting

Projects

🛡 Home Lab Stats · last 30 days
99.7%Lab Uptime
1,247Alerts Triaged
34True Positives
2.4mAvg MTTR
📈 Contribution Activity
Subash Lama GitHub contribution chart

🔗 github.com/Subash107

Filter:

Secure Virtual Lab Automation

Problem: Manual lab provisioning took 3–4 hours and produced inconsistent security baselines across environments.

Built: Docker Compose templates, bash bootstrap scripts, and GitHub Actions CI checks that validate security configurations before deployment.

Outcome: Reduced environment setup time by ~70%; eliminated configuration drift; enabled reproducible, auditable lab builds.

Stack: Docker · Compose · GitHub Actions · Linux · Bash

Cloud Migration & Governance Suite

Problem: Cloud IaC deployments lacked pre-deploy security controls, causing unreviewed config changes and compliance drift.

Built: Terraform modules with mandatory plan reviews, CI-gated release pipelines, and policy-as-code checks enforcing security baselines before any apply.

Outcome: Every deployment is now plan-reviewed, fully auditable, and rollback-ready; config drift eliminated across environments.

Stack: Terraform · GitHub Actions · Azure · Linux · Python

Personal SOC Lab

Problem: Needed a real detection environment for alert triage, rule writing, and incident response practice — not simulations.

Built: Wazuh SIEM with 15+ custom detection rules, Suricata IDS monitoring all network traffic, and Sysmon delivering endpoint telemetry across lab VMs. Rules mapped to MITRE ATT&CK (T1059, T1110, T1547).

Outcome: 1,200+ alerts triaged; 34 true positives identified and responded to; detection latency under 3 minutes for brute-force and lateral-movement patterns.

Stack: Wazuh · Suricata · Sysmon · Docker · pfSense · Linux

Skills

Endpoint Security & IAM90%
Network & Infrastructure88%
Security Operations (SOC / SIEM)75%
Scripting & Automation72%
GRC & Detection Engineering65%
Core Skilled Growing

Security Operations & GRC

SOC Operations GRC IAM Cyber Threat Intelligence Detection Engineering Incident Response SIEM Log Analysis

Security Tools & Monitoring

Wazuh Suricata Sysmon IDS / IPS Endpoint Security Threat Detection Network Monitoring Ethical Hacking

Networking & Infrastructure

Cisco Networking Active Directory DNS Proxy Server Storage Virtualization Linux Administration Windows Server Docker

Scripting & Automation

Python Bash PowerShell GitHub Actions Terraform / IaC Data Analysis
WZWazuh
SRSuricata
SMSysmon
DKDocker
GHGitHub
PYPython
TFTerraform
CNCisco
LXLinux
ADActive Directory

🔌 Homelab Topology

FW pfSense IDS Suricata SYS Sysmon SIEM Wazuh CTR Docker KALI Kali SOC Analyst
  • ✓ Wazuh SIEM — host-based detection & log correlation
  • ✓ Suricata IDS — network anomaly & signature detection
  • ✓ Sysmon — Windows process, network & file telemetry
  • 🥵 Tor exit node detection — Suricata rules + Tor Project exit list

🥵 How Tor Onion Routing Works

Tor wraps traffic in 3 encryption layers. Each node peels one — no single node knows both sender and destination.

■ Guard — strips outer layer ■ Middle — strips middle layer ■ Exit — strips inner layer, makes request

🎯 MITRE ATT&CK Detection Coverage

Hover each tactic for technique details · Home lab: Wazuh + Suricata + Sysmon

Recon Partial T1595 Active Scanning T1592 Gather Host Info Tool: Suricata
Resource Dev Partial T1583 Acquire Infrastructure T1588 Obtain Capabilities Tool: Threat Intel feeds
Initial Access Detected T1190 Exploit Public App T1078 Valid Accounts T1566 Phishing Tool: Suricata + Wazuh
Execution Detected T1059 Command Scripting T1204 User Execution T1047 WMI Tool: Sysmon + Wazuh
Persistence Detected T1547 Boot Autostart T1053 Scheduled Task T1543 Create Service Tool: Sysmon + Wazuh
Priv Esc Detected T1134 Token Manipulation T1055 Process Injection T1068 Exploit Privilege Tool: Wazuh + Sysmon
Def Evasion Partial T1070 Indicator Removal T1027 Obfuscated Files T1562 Impair Defenses Tool: Wazuh (partial)
Cred Access Detected T1003 OS Cred Dumping T1110 Brute Force T1552 Unsecured Creds Tool: Wazuh + Sysmon
Discovery Partial T1046 Network Scan T1082 System Info T1069 Permission Groups Tool: Suricata + Sysmon
Lateral Mov Partial T1021 Remote Services T1570 Lateral Tool Transfer Tool: Wazuh (in progress)
Collection Partial T1560 Archive Collected T1005 Local Data Tool: Sysmon file events
C2 In Progress T1071 App Layer Protocol T1573 Encrypted Channel Tor exit node detection active Tool: Suricata (expanding)
Exfiltration Partial T1048 Alt Protocol Exfil T1041 Exfil over C2 Tool: Suricata rules
Impact Detected T1485 Data Destruction T1490 Inhibit Recovery T1489 Service Stop Tool: Wazuh FIM + alerts

■ Detected ■ Partial ■ In Progress  ·  MITRE ATT&CK Framework ↗ ⬇ Navigator Layer

Depth & Breadth

Core depth is in security operations, detection engineering, network monitoring, and identity & access management, built on 12+ years of enterprise IT operations.

I bring a business-minded perspective that bridges technical risk with governance and compliance requirements.

Certification Roadmap

My certification journey — from IT foundations to specialist cybersecurity credentials, with the path ahead clearly mapped.

IT
Base
IT Foundations
12+ yrs
CC
Cisco Intro to Cyber
Mar 2026
IBM
CF
IBM Cybersecurity Fundamentals
Mar 2026
ES
Cisco Endpoint Security
Jun 2026
EH
Cisco Ethical Hacker
Apr 2026
CySA+
CompTIA CySA+
In progress
SEC+
CompTIA Security+
Planned
ISC2
ISC2 CC
Planned
Achieved In Progress Planned

Compliance Mapping

Homelab and practitioner experience mapped to real controls across NIST CSF, CIS Controls, and ISO 27001.

🛡
NIST CSF 2.0
Cybersecurity Framework
  • IDENTIFY & PROTECT — Wazuh asset inventory, pfSense firewall rules, Sysmon baselines
  • DETECT — Suricata IDS + Wazuh correlation rules triggering SIEM alerts
  • RESPOND & RECOVER — Alert triage playbooks, lab rebuild scripts, image versioning
Full coverage
📋
CIS Controls v8
Level 1 & 2
  • CIS 1 & 4 — Asset management via Wazuh agents; hardened Docker & Linux baseline
  • CIS 8 — Centralised audit logs from Wazuh + Sysmon across all lab endpoints
  • CIS 10 & 13 — Endpoint protection policies; network monitoring via Suricata + pfSense
L1 implemented · L2 in progress
🌐
ISO 27001:2022
Information Security
  • A.5 & A.8 — Security policies documented in SOC runbooks; lab asset register maintained
  • A.12 — Operations security with change control enforced via GitHub Actions CI/CD
  • A.16 — Incident management playbooks covering triage, escalation, and post-incident review
Awareness level — GRC cert planned
GRC Practitioner
Risk & Governance
  • Risk registers applied to homelab change decisions and lab access control policies
  • Control gap analysis mapped against CIS L1 with evidence collected via GitHub Actions
  • GRC understanding built through enterprise IT roles at SBI and Unilever deployments
Applied in homelab & work experience

Certifications

Cisco

Endpoint Security

Proves EDR, threat detection, and endpoint hardening skills

Issued Jun 2026 Verify ↗
Cisco

Ethical Hacker

Proves penetration testing methodology and vulnerability assessment

Issued Apr 2026 Verify ↗
Cisco

Introduction to Cybersecurity

Proves foundational security concepts and security awareness

Issued Mar 2026 Verify ↗
IBM

Cybersecurity Fundamentals

Proves core security operations, threat intelligence, and risk management

Issued Mar 2026 Verify ↗
IBM

Python for Data Science

Proves Python scripting for data analysis and security automation

Issued Mar 2026 Verify ↗
IBM SkillsBuild

Data Analysis with Python

Proves data-driven analysis and security reporting workflows

Issued Mar 2026 Verify ↗
Google Skillshop

Google Ads Video Certification

Proves digital analytics and data-driven campaign decision making

Issued May 2026 · Expires May 2027 ID 182626545 Verify ↗
AVAILABLE NOW

Ready to join your security team

12+ years IT · 7 certifications · Hands-on SOC lab (Wazuh · Suricata · Sysmon) · Remote worldwide

Education

Bachelor of Business Studies (BBS)

Jan 2015 – Jun 2022

Nepal Mega College · Kathmandu, Nepal · Grade: 2nd

  • Business management, financial analysis, and organisational governance — directly applicable to GRC, risk assessment, and communicating security risk to non-technical stakeholders
  • Computer Science electives at High School level (Nepal Kasthamandap College, 2012–2014)
  • SLC — Tri Padma Vidhya Shram Higher Secondary School (2000–2012)

Professional Certifications

2026

Cisco · IBM SkillsBuild · CompTIA (in progress) · Online

  • 7 certifications across cybersecurity, ethical hacking, endpoint security, and data science — see Certifications section for full details and Credly badges

Languages

Nepali Native
English Professional Working Proficiency
French Elementary · Actively Studying

What I’m Looking For

🎯

Target Roles

SOC Analyst L1/L2 · Detection Engineer · GRC Analyst · IAM Specialist · Security Operations Engineer

🌎

Work Setup

Remote worldwide · Hybrid or on-site in Kathmandu · Open to relocation for the right opportunity

🕑

Availability

Available immediately · UTC+5:45 (Nepal) · Flexible hours for global teams

🤝

Ideal Team

Security-first culture · Hands-on engineering · Continuous learning · Real threat detection work

Let’s talk — contact me directly or download my CVv1.0.0

Contact

Let’s Talk Security

Open to Cybersecurity Analyst, SOC Analyst, GRC Analyst, IAM Specialist, Security Operations, and related cybersecurity roles — on-site, hybrid, or remote in Kathmandu · open to remote worldwide.

Stay in Touch

Share your goals around cybersecurity, SOC operations, GRC, IAM, or security-aware IT and I will reply with practical next steps.

For a quick call, send 2-3 time options in UTC+5:45 with a short role or project note.

Open to Opportunities SOC · GRC · IAM · Security Ops
Contact →