I am a Certified Information Systems Auditor and security researcher based in Dhaka. For over eight years I have assessed web applications, mobile apps, networks and payment infrastructure for banks, fintechs, national media and government programmes.
My work sits where offensive testing meets formal audit: I plan and execute research-driven assessments, run red-team and blue-team exercises, and document findings so engineering teams can actually act on them. Alongside application security I work with encryption technologies, machine learning and blockchain — Solidity, Hyperledger Fabric, and the tooling around them.
The research half matters just as much. I have co-authored roughly a dozen papers on the security posture of the Bangladeshi web — SQL injection across the .bd domain, XSS and CSRF in public services, the Heartbleed fallout — plus a Bengali-language book on ethical hacking published at the Ekushey Book Fair.