Portfolio / 2026
01 — Full-stack engineer / security researcher
AdnanSyukur
I design and build full-stack products, stress-test them against realistic attack paths, and document the decisions that keep them reliable, secure, and maintainable.
Internships & entry-level roles
TO WORK
00 / By the numbers
Every number below traces back to documented portfolio work, public repositories, or a formal credential — nothing estimated.
01 / Summary
My background blends practical MERN stack development with applied web security, particularly the OWASP Top 10, insecure direct object reference (IDOR) vulnerabilities, and authentication bypass testing. It is grounded in formal networking fundamentals and strengthened by independent project work that required me to design, build, and validate a complete product end to end.
I see development and security as one engineering discipline: a product is only reliable when it is both functional and resistant to misuse.
When I build a feature, I do not stop at “it works.” I test the authentication flow, validate input handling, check access boundaries, and probe the system for abuse patterns before I consider the feature stable. That habit was sharpened while building C-Pay, where transaction logic had to be safe by design from the first line of code, not corrected after launch.
I am still early in my career, and I am transparent about that. What I bring is consistency, accountability, and a habit of shipping work that is documented, reviewed, and improved beyond the original brief.
02 / How I Work
Five principles guide how I build, test, and improve digital systems: clarity, accountability, security-minded thinking, and disciplined iteration.
- Build FirstA working prototype with rough edges is more valuable than a perfect plan that never ships. Most of my learning has come from completing projects and then improving what broke under real use.
- Test Like an OutsiderOnce a feature works, the next question is how someone could misuse it. That habit helps catch issues earlier, before they become expensive to fix.
- Document While BuildingI record decisions as I work so the reasoning behind the system remains visible during review, handoff, and future iteration.
- Choose Boring ReliabilityAuditable and predictable solutions are preferred over clever shortcuts. In systems with money, data, or user trust at stake, clarity is a core security feature.
- State the Gaps HonestlyWhen a tool or technique is still developing, I say so clearly. It is better to be explicit about current limitations than to overstate capability.
03 / Focus Areas
Where the actual hours have gone, with a specific project or credential behind each claim.
Primary
Full-Stack Development
Schema design, RESTful API design, authentication middleware, and React frontends, applied end to end on a solo-built payment system.
Primary
Web Application Security
OWASP Top 10 testing with particular depth in IDOR and authentication bypass, recognized with a VAPT award for a live university system assessment.
Ongoing
Team & Stakeholder Leadership
Chairman of Himasti, coordinating cross-functional teams and acting as the main point of contact between members, faculty, and external partners.
04 / Selected Work
The current GitHub work that best represents my direction: defensive security platforms and kernel-native systems research.
Flagship Security Platform
Aegis Fortress XDR
Open-source XDR architecture for critical infrastructure, combining endpoint, network, cloud, identity, detection, response, and deception layers.
Explore the repository ↗Kernel-Native Endpoint Defense
Lyncis-EDR
eBPF-LSM endpoint defense focused on pre-execution enforcement, process lineage, and automated forensic preservation.
Explore the repository ↗Open to internship and entry-level roles
Full-stack development, junior red team or cybersecurity work, or project coordination. Reach out about a role, a project, or just to talk security and product.