Security-focused PERN Stack Developer & Web App Pentester

Nazmul
Building resilient systems & breaking them ethically.

I build modern web applications and analyze them from an attacker's perspective. My focus is backend architecture, API security, authentication systems, and offensive web security testing.

Most applications are built for functionality first and security later. I approach both sides: building scalable applications while understanding how attackers abuse weak assumptions, insecure logic, and exposed attack surfaces.

About Me

I am a PERN stack developer and web application pentester focused on building applications that are both functional and harder to break. My background in offensive security heavily influences how I approach development.

Authentication logic & access control
API exposure & client-side risks
Attack surface reduction
Recon automation & secure backend design

I prefer practical engineering over unnecessary complexity. The goal is stable systems that are maintainable, scalable, and resistant to common abuse patterns.

Services

Web Application Development

Modern PERN stack apps with scalable backend APIs, authentication, dashboards, and maintainable frontend interfaces.

Web App Security Testing

Manual testing for XSS, broken access control, insecure APIs, auth flaws, business logic weaknesses.

Security Review for Startups

Reviewing architecture pre-deployment to catch mistakes early instead of patching critical issues post-launch.

Technical Stack

Frontend

React, Next.js, Tailwind CSS

Backend

Node.js, Express.js, REST APIs

Database

PostgreSQL, Redis

Infra

Linux, Docker, Nginx

Security

Pentesting, XSS Exploitation, API Security, Auth Testing, Recon Automation

Featured Projects

Secure Collaboration Platform

PERN-based platform with JWT auth, RBAC, audit logging & PostgreSQL relational modeling.

JWT · RBAC · API hardening
strict auth & IDOR prevention

Recon Automation Dashboard

Automates subdomain aggregation, JS endpoint extraction, screenshot automation & URL filtering.

Node.js · Puppeteer · Redis
workflow efficiency during assessments

API Security Assessment Lab

Deliberately vulnerable API environment to practice auth bypasses, access control, rate limiting & business logic exploits.

Express · PostgreSQL · Jest tests
multi-role authorization testing

Research & Security Writing

Documenting security findings, testing methodologies, attack chains, and application security observations. Focus on practical offensive security — not recycled theory.

Modern XSS exploitation in React apps Finding hidden API endpoints via JS analysis Common auth mistakes in SaaS Chaining weak access control → account takeover Recon workflows for modern web apps

Workflow

1. Requirement Discussion
Business goals, architecture & security goals
2. Planning & Architecture
API flow, DB design, threat modeling
3. Development & Testing
Iterative building & validation
4. Security Review
Auth logic, API exposure, attack surfaces
5. Deployment & Support
Production fixes & post-launch assistance

Let's Connect — Send a message

Available for freelance development, web app security testing & startup security reviews. Use the form below to reach me directly via Email client or WhatsApp with your questions.