Sachin Gautam
Cybersecurity Student & Associate SOC Analyst
Defending networks through real-time detection, threat hunting, and incident response. Final-year BScIT student with hands-on SIEM experience across live SOC environments, from alert triage and detection tuning to proactive threat hunting mapped to MITRE ATT&CK.

Currently
Associate SOC Analyst
01 / About
Security-first.
Final-year BScIT student and Associate SOC Analyst with real-world experience in security monitoring, incident response, and threat detection. Hands-on with SIEM platforms in live SOC environments, with a track record of improving detection quality and supporting security operations across multiple client environments. Passionate about cybersecurity, continuous learning, and making security operations more effective.
Detection & Monitoring
24/7 alert triage across multiple client environments using LogPoint, FortiSIEM, and LogRhythm.
Threat Hunting
Proactive hunts mapped to the MITRE ATT&CK framework to catch threats before impact.
Incident Response
Investigation, evidence collection, and coordinated containment with cross-functional teams.
Detection Engineering
Tuning rules, alerts, and dashboards to raise detection accuracy and reduce noise.
02 / Experience
Where I've worked.
Real SOC time monitoring, tuning, and responding across live client environments.
Associate SOC Analyst
Aug 2025 - Mar 2026Cryptogen Nepal Pvt. Ltd. · Kathmandu, Nepal
- Monitored and triaged security alerts across multiple client environments using SIEM platforms on a 24/7 basis.
- Built and tuned detection rules, alerts, and dashboards to improve the quality and accuracy of security event detection.
- Validated log ingestion and coverage from systems, applications, and endpoints to ensure complete visibility.
- Investigated security incidents, collected evidence, and coordinated containment and remediation with relevant teams.
- Conducted proactive threat hunting using the MITRE ATT&CK framework to identify threats before they caused impact.
- Documented investigation findings and contributed to improving SOC playbooks and workflows.
- Delivered knowledge transfer sessions to new analysts to standardise team processes and improve overall capacity.
- Prepared clear security reports for stakeholders, translating technical findings into practical recommendations.
SOC Analyst Intern
Jun 2025 - Jul 2025Cryptogen Nepal Pvt. Ltd. · Kathmandu, Nepal
- Supported real-time SIEM monitoring and alert analysis across multiple client environments.
- Investigated phishing campaigns, suspicious domains, and IP addresses using threat intelligence tools.
- Performed log correlation and incident triage to identify and help neutralise potential threats.
- Contributed to threat hunting and digital forensic investigations as part of the SOC team.
Cybersecurity Intern
Apr 2025 - May 2025Hack Secure · Remote, India
- Conducted vulnerability scanning across lab network environments using Nmap and Metasploit.
- Participated in simulated penetration testing exercises to identify gaps in security controls.
- Wrote technical reports summarising vulnerabilities, their potential impact, and remediation steps.
03 / Projects
Things I've built.
Security tooling built to solve real problems I ran into during investigations and research.
A local-first OSINT aggregator that builds a digital footprint from a username, email, phone number, or photo. It enumerates 75 platforms, checks breach and registration signals, resolves phone carrier data, and pulls image EXIF metadata into one correlation graph with local scan history.
A CLI tool that fetches a webpage and scans its content and structure for phishing indicators: brand impersonation, credential-harvesting forms that submit off-domain, hidden iframes, obfuscated JavaScript, and IP-hosted sites.
A web application that checks multiple IP addresses for malicious activity using the AbuseIPDB API, with WHOIS lookup for additional context. Built to speed up the IP investigation process during alert triage.
A collaborative Android security testing tool that uses ADB to identify mobile vulnerabilities and security misconfigurations in Android devices.
A CLI tool that encrypts and decrypts files using Fernet (AES-128-CBC with HMAC authentication), deriving the key from a passphrase via PBKDF2-HMAC-SHA256 with a random per-file salt.
A CLI demo of a secure username/password auth flow: PBKDF2-HMAC-SHA256 password hashing with per-user salt, account lockout after repeated failed attempts, and generic error messages that don't leak whether a username exists.
A fast, multi-threaded TCP port scanner for auditing hosts on your own network. Accepts a port range or explicit list and identifies likely services (SSH, HTTP, HTTPS, MySQL, RDP) with configurable timeout.
A CLI tool that analyzes a URL's structure for phishing and scam red flags (IP-hosted links, punycode lookalikes, shorteners, excessive subdomains, @ tricks) and produces a risk rating, with an optional live TLS and redirect check.
A CLI tool that looks up geolocation and network info (country, ISP, ASN, timezone, coordinates) for any IP address, or your own public IP if none is given.
A CLI tool that scores password strength from Very Weak to Very Strong based on length, character variety, common-password lists, and predictable patterns, with actionable improvement suggestions.
A CLI tool that generates cryptographically secure random passwords using Python's secrets module, with configurable character sets and an unbiased Fisher-Yates shuffle.
A CLI implementation of the classic Caesar shift cipher with a brute-force crack mode that tries all 26 shifts and ranks candidates by letter-frequency scoring.
04 / Skills
Tools of the trade.
Platforms, frameworks, and languages I use day to day in security operations.
SIEM Platforms
Security Operations
Frameworks
Tools
Networking
Programming
Cloud
Languages
05 / Certifications
Continuous learning.
A dozen certifications across cybersecurity fundamentals, cloud, and networking, with more in progress.
Fortinet Certified Fundamentals Cybersecurity
Fortinet · Jul 2025
Getting Started in Cybersecurity 3.0
Fortinet · Jul 2025
Introduction to the Threat Landscape 3.0
Fortinet · Jul 2025
Python Essentials 1
Cisco Networking Academy · Mar 2025
AWS Cloud Quest: Cloud Practitioner
Amazon Web Services · Feb 2025
Ethical Hacker
Cisco Networking Academy · Sep 2024
Cyber Threat Management
Cisco Networking Academy · Sep 2024
Introduction to Cybersecurity
Cisco Networking Academy · Nov 2024
AWS Academy: Cloud Web Application Builder
Amazon Web Services · Sep 2024
ISO/IEC 27001:2022 Information Security Associate
SkillFront · 2024
Introduction to Critical Infrastructure Protection
OPSWAT Academy · 2024
Introduction to Networking
HTB Academy · 2024
06 / Achievements & Education
Beyond the day job.
Achievements
- Identified and reported security vulnerabilities in a local web platform including unauthorised access and enumeration issues, with recommended fixes.
- Reported a fraudulent online scam to the Cyber Bureau, contributing to the apprehension of the individual responsible.
- Active contributor to a cybersecurity club focused on dark web monitoring, reporting data leaks, and identifying malicious online activity.
- Consistent participant in CTF competitions on TryHackMe and Blue Team Labs Online with top-tier rankings.
Education
BScIT (Bachelor of Science in Information Technology)
Jul 2022 - PresentPresidential Graduate School · Baneshwor, Kathmandu
+2 Science (Computer Science)
2020 - 2022Little Angels College · Hattiban, Lalitpur
Secondary Education Examination (SEE)
2010 - 2020Bardiya Academy and Polytechnic Research Centre · Bardiya
07 / Contact
Let's talk security.
Open to SOC analyst, threat hunting, and security engineering roles. Reach out any time.
Kalanki, Kathmandu, Nepal