Security Engineering / Local AI
CodeGuardian AI
A privacy-first secure code review platform that combines context-aware static analysis with local AI interpretation and professional reporting.
Software Engineer Security Researcher Open Source Contributor AI Builder
Software Engineer & Security Researcher
I design Python and Django backend systems, REST APIs, local AI tools, and security-focused software while contributing to open source and conducting responsible vulnerability research.
01 — About
Zain Nadeem is a Software Engineer and Security Researcher specializing in Python and Django backend systems, REST APIs, application security, developer tooling, and local AI software.
My work is grounded in systems that are useful, understandable, and designed around real operational constraints. I build maintainable backend services, robust API architectures, and privacy-conscious local AI tools that keep sensitive context closer to the people using them.
Security is integral to this engineering lifecycle—from secure code reviews and runtime defensive controls to responsible vulnerability research across open-source software including Django REST Framework and CyberChef, alongside upstream contributions to CPython, Celery, and Visual Studio Code.
02 — Selected Work
Focused project previews lead to concise technical case studies covering the problem, architecture, engineering decisions, and current state.
Security Engineering / Local AI
A privacy-first secure code review platform that combines context-aware static analysis with local AI interpretation and professional reporting.
Security Operations / AI
An analyst-grade investigation platform that turns uploaded or streamed logs into correlated attack stories, cases, and reports.
Additional systems
Local AI / Agentic Systems
A portable local AI knowledge and engineering workstation built for grounded research, repository intelligence, and approval-led agentic work.
Organizational Intelligence
A secure local organizational knowledge system for source-grounded answers, meeting intelligence, and human-reviewed action.
AI / Career Technology
A local-AI interview preparation and assessment platform combining mock interviews, resume analysis, and structured practice.
03 — Research
I approach vulnerability research through reproducible analysis, coordinated disclosure, regression testing, and upstream remediation. The public record below links directly to official project advisories.
View all researchPotential bypass of Django DATA_UPLOAD_MAX_MEMORY_SIZE when parsing oversized JSON and urlencoded request bodies via DRF request.data
GHSA-2m8g-3cmr-wg3w
AdminRenderer may disclose GET-protected data when rendering invalid write requests
GHSA-g47c-3xmw-q6m2
CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URL
GHSA-w74r-jxjh-gwr6
04 — Open Source
Selected bug fixes, regression work, and security-focused engineering across established open-source projects.
05 — Expertise
Technologies and disciplines I use across backend delivery, local intelligence, security engineering, and infrastructure.
Python · Django · Django REST Framework · FastAPI · REST APIs · PostgreSQL · Redis · Celery
Local LLMs · Ollama · RAG · ChromaDB · Agentic Workflows · AI-assisted Applications
Secure Code Review · Application Security · API Security · Vulnerability Research · Security Automation · Log Analysis · Static Analysis
Docker · Linux · Git · GitHub Actions · Nginx
06 — Approach
Designing dependable backend services and product foundations.
Keeping inference, knowledge, and sensitive context closer to users.
Learning, reviewing, and improving software in public.
Finding, reproducing, reporting, and helping remediate vulnerabilities.
07 — Knowledge & FAQ
Direct, factual answers regarding professional background, technical specializations, security research, open-source work, and project collaboration.
Zain Nadeem is a Software Engineer and Security Researcher specializing in Python and Django backend systems, REST APIs, application security, developer tooling, and local AI software. He actively contributes to major open-source projects and conducts responsible vulnerability research.
Zain specializes in backend engineering (designing robust Python/Django APIs, asynchronous task workflows, and data pipelines), application security (secure code analysis, parser validation, and vulnerability research), and local AI engineering (source-grounded retrieval-augmented generation and developer workstations).
The core technology stack includes:
Yes. Python and Django are central to Zain's backend engineering work. This includes designing scalable REST APIs with Django REST Framework, architecting distributed worker queues with Celery and Redis, enforcing database integrity, and contributing upstream bug fixes and security improvements directly to CPython and Django REST Framework.
Zain publishes evidence-based vulnerability research coordinated through responsible disclosure. Published advisories include:
request.data parsing in Django REST Framework.All research records include reproducible test cases, root-cause analysis, and links to official GitHub Security Advisories.
Zain has authored 16 verified merged pull requests and reliability fixes across major open-source ecosystems:
Detailed technical breakdowns and merge proofs are documented in the Open Source case studies.
Zain prioritizes correctness, bounded resource consumption, explicit failure modes, and automated regression testing. Rather than adding opaque complexity, systems are designed around clear domain boundaries, verifiable input parsing, defensive default settings, and privacy-preserving architectures.
You can initiate a discussion by filling out the project inquiry form below with details on your technical problem, current architecture, and goals. Alternatively, you can reach out directly via email at zainnadeemzainnadeem80@gmail.com, connect on LinkedIn, or send a message on WhatsApp.
08 — Contact
If you’re working on a Python or Django backend, REST API, security-focused application, developer tool, or local AI system, feel free to share the technical context and what you’re trying to achieve. I’m open to selected engineering collaborations where there is a clear problem to solve.