01 · WHO I AM
EASIN ARAFAT
I'm an Application Security Engineer at Startise. I work on xCloud, a managed cloud hosting platform, and my job is to keep it and the sites it hosts secure.
Day to day that means security, but I don't stay in one lane. I build features, run infrastructure, work with AI tooling, and automate whatever I end up doing twice.
scroll ↓
02 · BACKGROUND
Background
I'm self-taught. I started with front-end, moved to full-stack, and learned by building actual projects instead of following tutorials. I still learn new tools the same way.
I graduated from MIST (Military Institute of Science and Technology), where I was President of the MIST Cyber Security Club. We ran CTFs and training sessions for anyone on campus who wanted in.
03 · SECURITY
Security research
I came into security from the offensive side. CTFs, cryptography, recon tooling, and eventually real vulnerability research.
That research led to 9 CVEs reported through Patchstack's disclosure program, and a co-authored paper in Array (Elsevier, Q1). The short version: I look for the bugs an attacker would use, and I get to them first.
04 · WHAT I DO
Four disciplines
Four areas, one job. Here's where my time actually goes.
05 · HOW I WORK
How I work
Whether it's a feature, a pipeline, or a security fix, I work through the same four steps.
- 01
PLAN
I start on paper, not in the editor. What can this break, what does it touch, what's the shortest honest path to something that works.
- 02
BUILD
Then I build whatever the problem actually needs. Could be app code, could be infrastructure, could be a one-off tool. It ships to production, not to a demo.
- 03
SECURE
Before release I put on the attacker hat and try to break what I just built. Anything I find gets fixed before it ships.
- 04
AUTOMATE
If I do something twice, I script it. Manual checklists turn into jobs that run themselves and tell me when something's off.
“Most failures aren't attacks. They're systems doing something in production that they never did in testing. That gap is where I spend my time.”
“I don't wait until I'm qualified for a problem. I take it, and I learn whatever's missing on the way.”
“Code is half the picture. The other half is understanding why people build things, break things, and decide the way they do.”
Easin Arafat — Application Security Engineer at Startise
Easin Arafat (also known as Sheikh Easin Arafat, handle n0_arafat_n0) is an Application Security Engineer at Startise, working on the xCloud hosting platform. A graduate of the Military Institute of Science and Technology (MIST) in Bangladesh and former President of the MIST Cyber Security Club, he specializes in application security, penetration testing, DevSecOps, and secure coding. He has responsibly disclosed 9 CVEs through the Patchstack Vulnerability Disclosure Program and is a co-author of peer-reviewed research published in Array (Elsevier, Q1). Easin Arafat is not affiliated with other individuals of the same name, such as the Eötvös Loránd University PhD student or the University of Dhaka Islamic-finance researcher.