Software Engineer Security Researcher Open Source Contributor AI Builder

Zain Nadeem

Software Engineer & Security Researcher

I design Python and Django backend systems, REST APIs, local AI tools, and security-focused software while contributing to open source and conducting responsible vulnerability research.

Building where software, AI, and security intersect.

Zain Nadeem is a Software Engineer and Security Researcher specializing in Python and Django backend systems, REST APIs, application security, developer tooling, and local AI software.

My work is grounded in systems that are useful, understandable, and designed around real operational constraints. I build maintainable backend services, robust API architectures, and privacy-conscious local AI tools that keep sensitive context closer to the people using them.

Security is integral to this engineering lifecycle—from secure code reviews and runtime defensive controls to responsible vulnerability research across open-source software including Django REST Framework and CyberChef, alongside upstream contributions to CPython, Celery, and Visual Studio Code.

Engineering systems with a clear point of view.

Focused project previews lead to concise technical case studies covering the problem, architecture, engineering decisions, and current state.

Additional systems

03

Local AI / Agentic Systems

AI Brain

A portable local AI knowledge and engineering workstation built for grounded research, repository intelligence, and approval-led agentic work.

  • FastAPI
  • Ollama
  • ChromaDB
  • PostgreSQL
Personal System / ActiveExplore project
04

Organizational Intelligence

EchoMind AI

A secure local organizational knowledge system for source-grounded answers, meeting intelligence, and human-reviewed action.

  • Django
  • Celery
  • ChromaDB
  • Ollama
Under DevelopmentExplore project
05

AI / Career Technology

AI Interview Platform

A local-AI interview preparation and assessment platform combining mock interviews, resume analysis, and structured practice.

  • Django
  • FastAPI
  • PostgreSQL
  • Ollama

Responsible research, disclosed with evidence.

I approach vulnerability research through reproducible analysis, coordinated disclosure, regression testing, and upstream remediation. The public record below links directly to official project advisories.

View all research
Django REST Framework

CVE-2026-73228

Potential bypass of Django DATA_UPLOAD_MAX_MEMORY_SIZE when parsing oversized JSON and urlencoded request bodies via DRF request.data

GHSA-2m8g-3cmr-wg3w

ModeratePublished · Credited reporter
Read technical analysis
Django REST Framework

CVE-2026-73229

AdminRenderer may disclose GET-protected data when rendering invalid write requests

GHSA-g47c-3xmw-q6m2

ModeratePublished · Credited reporter
Read technical analysis
CyberChef

CVE-2026-72912

CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URL

GHSA-w74r-jxjh-gwr6

ModeratePublished · Credited reporter
Read technical analysis

Engineering in public.

Selected bug fixes, regression work, and security-focused engineering across established open-source projects.

View all contributions

A focused engineering toolkit.

Technologies and disciplines I use across backend delivery, local intelligence, security engineering, and infrastructure.

01

Backend & Systems

Python · Django · Django REST Framework · FastAPI · REST APIs · PostgreSQL · Redis · Celery

02

AI Engineering

Local LLMs · Ollama · RAG · ChromaDB · Agentic Workflows · AI-assisted Applications

03

Security Engineering

Secure Code Review · Application Security · API Security · Vulnerability Research · Security Automation · Log Analysis · Static Analysis

04

Infrastructure

Docker · Linux · Git · GitHub Actions · Nginx

How I approach engineering.

  1. 01

    Software Engineering

    Designing dependable backend services and product foundations.

  2. 02

    Building Local AI Systems

    Keeping inference, knowledge, and sensitive context closer to users.

  3. 03

    Open Source Engineering

    Learning, reviewing, and improving software in public.

  4. 04

    Security Research

    Finding, reproducing, reporting, and helping remediate vulnerabilities.

Frequently asked engineering questions.

Direct, factual answers regarding professional background, technical specializations, security research, open-source work, and project collaboration.

Who is Zain Nadeem?

Zain Nadeem is a Software Engineer and Security Researcher specializing in Python and Django backend systems, REST APIs, application security, developer tooling, and local AI software. He actively contributes to major open-source projects and conducts responsible vulnerability research.

What does Zain Nadeem specialize in?

Zain specializes in backend engineering (designing robust Python/Django APIs, asynchronous task workflows, and data pipelines), application security (secure code analysis, parser validation, and vulnerability research), and local AI engineering (source-grounded retrieval-augmented generation and developer workstations).

What technologies and tools does Zain Nadeem work with?

The core technology stack includes:

  • Backend & Languages: Python, Django, Django REST Framework, FastAPI, JavaScript, TypeScript, Next.js
  • Databases & Queues: PostgreSQL, Redis, Celery, SQLite, ChromaDB
  • Security & Analysis: Static analysis (Semgrep, Bandit, AST parsers), HTTP protocol analysis, vulnerability reproduction, CVE disclosure
  • AI & Tooling: Ollama, local LLM orchestration, Docker, Linux, Git, GitHub Actions
Does Zain Nadeem develop backend systems with Python and Django?

Yes. Python and Django are central to Zain's backend engineering work. This includes designing scalable REST APIs with Django REST Framework, architecting distributed worker queues with Celery and Redis, enforcing database integrity, and contributing upstream bug fixes and security improvements directly to CPython and Django REST Framework.

What kind of security research has Zain Nadeem published?

Zain publishes evidence-based vulnerability research coordinated through responsible disclosure. Published advisories include:

All research records include reproducible test cases, root-cause analysis, and links to official GitHub Security Advisories.

What open-source projects has Zain Nadeem contributed to?

Zain has authored 16 verified merged pull requests and reliability fixes across major open-source ecosystems:

  • CPython: Windows scandir trailing space normalization, blocking profiler exit termination, asyncio sendfile exception handling, and normpath allocation safety.
  • Django REST Framework: Unique-together validation error handling, OpenAPI zero-numeric bounds schemas, and negative integer int64 boundary detection.
  • CyberChef: npm allowScripts build security policy, bcrypt invalid salt handling, malformed image decoding, and presenter state cleanup.
  • Celery: Pidbox consumer lifecycle cleanup during worker reset cycles.
  • Visual Studio Code: PowerShell environment variable quoting and Workspace Trust transition awaiting.
  • Nuclei & OWASP APTS: Raw HTTP parser panic prevention on single-LF payloads and CI automated sanity checks.

Detailed technical breakdowns and merge proofs are documented in the Open Source case studies.

How does Zain Nadeem approach system design and code quality?

Zain prioritizes correctness, bounded resource consumption, explicit failure modes, and automated regression testing. Rather than adding opaque complexity, systems are designed around clear domain boundaries, verifiable input parsing, defensive default settings, and privacy-preserving architectures.

How can someone contact Zain Nadeem about a project or collaboration?

You can initiate a discussion by filling out the project inquiry form below with details on your technical problem, current architecture, and goals. Alternatively, you can reach out directly via email at zainnadeemzainnadeem80@gmail.com, connect on LinkedIn, or send a message on WhatsApp.

Let’s discuss the problem.

If you’re working on a Python or Django backend, REST API, security-focused application, developer tool, or local AI system, feel free to share the technical context and what you’re trying to achieve. I’m open to selected engineering collaborations where there is a clear problem to solve.

Selected Engineering Capabilities

  • Backend & API EngineeringPython, Django, Django REST Framework, REST API development, and API integration.
  • Security-Focused EngineeringApplication security, secure code review, bug fixing, debugging, and technical research.
  • Developer & Local AI ToolingDeveloper workflows, repository intelligence, local AI systems, and AI-assisted applications.

Start with the engineering problem.

Share enough context to begin a useful conversation. You can refine scope and requirements later.

Your inquiry is processed through Formspree so I can respond to your message. Please do not include passwords, API keys, credentials, or other sensitive information.

Message sent successfully

Inquiry received

Thanks for reaching out. Your project inquiry has been received successfully. I’ll review the details and aim to respond within 24 hours.

Please keep an eye on the email address you provided.