Nazmul
Building resilient systems & breaking them ethically.
Most applications are built for functionality first and security later. I approach both sides: building scalable applications while understanding how attackers abuse weak assumptions, insecure logic, and exposed attack surfaces.
About Me
I am a PERN stack developer and web application pentester focused on building applications that are both functional and harder to break. My background in offensive security heavily influences how I approach development.
I prefer practical engineering over unnecessary complexity. The goal is stable systems that are maintainable, scalable, and resistant to common abuse patterns.
Services
Web Application Development
Modern PERN stack apps with scalable backend APIs, authentication, dashboards, and maintainable frontend interfaces.
Web App Security Testing
Manual testing for XSS, broken access control, insecure APIs, auth flaws, business logic weaknesses.
Security Review for Startups
Reviewing architecture pre-deployment to catch mistakes early instead of patching critical issues post-launch.
Technical Stack
Frontend
React, Next.js, Tailwind CSSBackend
Node.js, Express.js, REST APIsDatabase
PostgreSQL, RedisInfra
Linux, Docker, NginxSecurity
Pentesting, XSS Exploitation, API Security, Auth Testing, Recon AutomationFeatured Projects
Secure Collaboration Platform
PERN-based platform with JWT auth, RBAC, audit logging & PostgreSQL relational modeling.
Recon Automation Dashboard
Automates subdomain aggregation, JS endpoint extraction, screenshot automation & URL filtering.
API Security Assessment Lab
Deliberately vulnerable API environment to practice auth bypasses, access control, rate limiting & business logic exploits.
Research & Security Writing
Documenting security findings, testing methodologies, attack chains, and application security observations. Focus on practical offensive security — not recycled theory.
Workflow
Business goals, architecture & security goals
API flow, DB design, threat modeling
Iterative building & validation
Auth logic, API exposure, attack surfaces
Production fixes & post-launch assistance
Let's Connect — Send a message
Available for freelance development, web app security testing & startup security reviews. Use the form below to reach me directly via Email client or WhatsApp with your questions.