Masbah Uddin

Abu Md Masbah Uddin

Software Developer | Backend Developer | Security Enthusiast

About Me

I'm Abu Md. Masbah Uddin, a Software Developer and Security Engineer with hands-on experience in backend development, cybersecurity, and cloud computing. I recently completed my degree in Computer Science and Engineering at Chittagong University of Engineering and Technology (2020-2025).

My expertise spans secure code review, payment system integration, and building scalable backend architectures. I've identified critical vulnerabilities in production systems including privilege escalation, 2FA bypass, and broken access control issues. I'm passionate about building secure, efficient systems and implementing robust RBAC solutions.

I'm a lifelong learner with deep interests in cybersecurity, artificial intelligence, and system architecture. My goal is to continuously enhance my skills and create meaningful contributions to secure software development.

Experience

Junior Security Engineer

LAB3

Remote, United States

Jun 2025 -- Oct 2025

  • Performed secure code reviews across 3+ production codebases, identifying critical vulnerabilities including privilege escalation, 2FA bypass, broken access control, and a bug allowing full database dump.
  • Created integrations with third-party systems and built auto-retry pipeline using Google Cloud Tasks to handle large-scale integrations, processing thousands of records without hitting rate limits.
  • Built payment features: autopayments (EMI-style), refunds, and reconciliation system for terminal/POS transactions.
  • Implemented RBAC and feature-based access control systems from scratch.
  • Built complete CI/CD pipeline using GitHub Actions, Docker, and Firebase; created monorepo architecture with esbuild.

Software Developer (Self-Employed)

Vector Classes

Chittagong, Bangladesh

Dec 2022 -- Dec 2024

  • Designed and built cloud-based financial tracking system with RBAC, optimizing database architecture for secure, efficient performance.

Technical Skills

Languages

JavaScriptPythonC++GoRustSolidityC

Databases

FirebaseMongoDBPostgreSQLMySQL

Cloud & DevOps

GCPAWSAzureDockerGitHub ActionsFirebase FunctionsNginx

Frameworks & Tools

Express.jsNest.jsReact.jsDjangoFlutterGitLinuxesbuild

Security & Concepts

Secure Code ReviewPenetration TestingRBACOWASP Top 10Payment Systems3rd Party IntegrationMonorepo Architecture

Projects

Vector Classes Website

Architected and developed the complete backend system.

Managed and optimized database performance and reliability.

Deployed and maintained the application on a Linux server.

Maintained and improved the Continuous Integration (CI) pipeline.

Eye of the Cosmos

Quickly learned Unity in 12 days to develop 3D games and interactive JWST assembly tools.

Adapted rapidly to Flutter, implementing and debugging an API system for seamless data flow.

Combined NASA JWST imagery with music to create a dynamic multimedia experience.

Utilized NASA’s API for live mission tracking and status updates.

Developed educational tools to inspire interest in STEM fields among younger audiences.

Grey Matter Omega

Architected and developed the complete backend system.

Deployed and maintained the application on a Linux server.

SymptoScan Disease Suggesting App

Employs machine learning to predict 41 types of diseases based on user symptoms.

Provides a health education section with detailed information on symptoms, risk factors, and preventive measures.

Utilizes Flutter for frontend development, Firebase for backend, and Hugging Face Transformers for model deployment.

PDF Plagiarism Checker

Developed for the Artificial Intelligence Lab course by Masbah & Sabik.

Implemented a plagiarism detection system using cosine similarity to compare PDF contents.

ProducerConsumerSimulator

Simulated bank and grocery queue systems, managing customer arrivals and service.

Developed components including producers, consumers, and distributors for queue management.

Implemented statistical tracking for customer service performance.

Configured and ran simulations with customizable parameters such as queue length, service time, and more.

Certifications

APIsec Certified Practitioner (ACP)

Apr 2025

Comprehensive training and exam focused on securing APIs against modern attack vectors.

View Credential →

Google Cybersecurity Professional Certificate

Dec 2023

Covered key principles including the CIA triad, network security, and threat modeling.

View Credential →

Education

Bachelor of Science in Computer Science and Engineering

2020 -- 2025

Chittagong University of Engineering and Technology (CUET), Chittagong, Bangladesh

Hathazari Govt College

2017-2019

Science Department

Contact

Email: masbahuddin60@gmail.com

Phone: +8801311807889

LinkedInGitHub

Programming Languages I Have Learned:

JavaScript/TypeScript

Rust

Python

C++

Go

Java

Technologies, Frameworks & Libraries I have used:

NestJS

ExpressJS

NextJS

Django

Flask

JavaFX

Unity

Researches