Software Engineer Security Researcher Open Source Contributor

Zain Nadeem

Software Engineer & Security Researcher

I build backend systems, local AI products, security tooling, and developer-focused software while contributing to open source and conducting responsible vulnerability research.

Building where software, AI, and security intersect.

My work is grounded in systems that are useful, understandable, and designed around real operational constraints.

I build Python backends, Django applications, APIs, and local AI systems that keep sensitive context closer to the people using them. Security remains part of that engineering process—from secure code review and practical tooling to evidence-led vulnerability research, responsible disclosure, and maintainable open-source fixes.

Engineering systems with a clear point of view.

Focused project previews lead to concise technical case studies covering the problem, architecture, engineering decisions, and current state.

Additional systems

03

Local AI / Agentic Systems

AI Brain

A portable local AI knowledge and engineering workstation built for grounded research, repository intelligence, and approval-led agentic work.

  • FastAPI
  • Ollama
  • ChromaDB
  • PostgreSQL
Personal System / ActiveExplore project
04

Organizational Intelligence

EchoMind AI

A secure local organizational knowledge system for source-grounded answers, meeting intelligence, and human-reviewed action.

  • Django
  • Celery
  • ChromaDB
  • Ollama
Under DevelopmentExplore project
05

AI / Career Technology

AI Interview Platform

A local-AI interview preparation and assessment platform combining mock interviews, resume analysis, and structured practice.

  • Django
  • FastAPI
  • PostgreSQL
  • Ollama

Responsible research, disclosed with evidence.

I approach vulnerability research through reproducible analysis, coordinated disclosure, regression testing, and upstream remediation. The public record below links directly to official project advisories.

View all research
Django REST Framework

CVE-2026-73228

Potential bypass of Django DATA_UPLOAD_MAX_MEMORY_SIZE when parsing oversized JSON and urlencoded request bodies via DRF request.data

GHSA-2m8g-3cmr-wg3w

ModeratePublished · Credited reporter
Read technical analysis
Django REST Framework

CVE-2026-73229

AdminRenderer may disclose GET-protected data when rendering invalid write requests

GHSA-g47c-3xmw-q6m2

ModeratePublished · Credited reporter
Read technical analysis
CyberChef

CVE-2026-72912

CyberChef’s pretty-recipe parser vulnerable to client-side ReDoS / CPU exhaustion when parsing a malformed #recipe= URL

GHSA-w74r-jxjh-gwr6

ModeratePublished · Credited reporter
Read technical analysis

Engineering in public.

Selected bug fixes, regression work, and security-focused engineering across established open-source projects.

View all contributions

A focused engineering toolkit.

Technologies and disciplines I use across backend delivery, local intelligence, security engineering, and infrastructure.

01

Backend & Systems

Python · Django · Django REST Framework · FastAPI · REST APIs · PostgreSQL · Redis · Celery

02

AI Engineering

Local LLMs · Ollama · RAG · ChromaDB · Agentic Workflows · AI-assisted Applications

03

Security Engineering

Secure Code Review · Application Security · API Security · Vulnerability Research · Security Automation · Log Analysis · Static Analysis

04

Infrastructure

Docker · Linux · Git · GitHub Actions · Nginx

How I approach engineering.

  1. 01

    Software Engineering

    Designing dependable backend services and product foundations.

  2. 02

    Building Local AI Systems

    Keeping inference, knowledge, and sensitive context closer to users.

  3. 03

    Open Source Engineering

    Learning, reviewing, and improving software in public.

  4. 04

    Security Research

    Finding, reproducing, reporting, and helping remediate vulnerabilities.

Let’s build something meaningful.

I’m open to conversations around software engineering, backend systems, local AI, open-source collaboration, and security research.