cd ~/dashboard

01 · WHO I AM

EASIN ARAFAT

I'm an Application Security Engineer at Startise. I work on xCloud, a managed cloud hosting platform, and my job is to keep it and the sites it hosts secure.

Day to day that means security, but I don't stay in one lane. I build features, run infrastructure, work with AI tooling, and automate whatever I end up doing twice.

scroll ↓

02 · BACKGROUND

Background

I'm self-taught. I started with front-end, moved to full-stack, and learned by building actual projects instead of following tutorials. I still learn new tools the same way.

I graduated from MIST (Military Institute of Science and Technology), where I was President of the MIST Cyber Security Club. We ran CTFs and training sessions for anyone on campus who wanted in.

03 · SECURITY

Security research

I came into security from the offensive side. CTFs, cryptography, recon tooling, and eventually real vulnerability research.

That research led to 9 CVEs reported through Patchstack's disclosure program, and a co-authored paper in Array (Elsevier, Q1). The short version: I look for the bugs an attacker would use, and I get to them first.

04 · WHAT I DO

Four disciplines

Four areas, one job. Here's where my time actually goes.

05 · HOW I WORK

How I work

Whether it's a feature, a pipeline, or a security fix, I work through the same four steps.

  1. 01

    PLAN

    I start on paper, not in the editor. What can this break, what does it touch, what's the shortest honest path to something that works.

  2. 02

    BUILD

    Then I build whatever the problem actually needs. Could be app code, could be infrastructure, could be a one-off tool. It ships to production, not to a demo.

  3. 03

    SECURE

    Before release I put on the attacker hat and try to break what I just built. Anything I find gets fixed before it ships.

  4. 04

    AUTOMATE

    If I do something twice, I script it. Manual checklists turn into jobs that run themselves and tell me when something's off.

Most failures aren't attacks. They're systems doing something in production that they never did in testing. That gap is where I spend my time.
SYSTEMS THINKING
I don't wait until I'm qualified for a problem. I take it, and I learn whatever's missing on the way.
GROWTH MINDSET
Code is half the picture. The other half is understanding why people build things, break things, and decide the way they do.
THE LONG GAME

06 · CONTACT

Get in touch

These days most of my spare energy goes into agents and AI tooling. It's the most interesting ground I've worked on in years.

If you're working on a problem worth solving, I'd like to hear about it.

Easin Arafat — Application Security Engineer at Startise

Easin Arafat (also known as Sheikh Easin Arafat, handle n0_arafat_n0) is an Application Security Engineer at Startise, working on the xCloud hosting platform. A graduate of the Military Institute of Science and Technology (MIST) in Bangladesh and former President of the MIST Cyber Security Club, he specializes in application security, penetration testing, DevSecOps, and secure coding. He has responsibly disclosed 9 CVEs through the Patchstack Vulnerability Disclosure Program and is a co-author of peer-reviewed research published in Array (Elsevier, Q1). Easin Arafat is not affiliated with other individuals of the same name, such as the Eötvös Loránd University PhD student or the University of Dhaka Islamic-finance researcher.