Skip to content
View amz202's full-sized avatar
💭
das beste oder nichts
💭
das beste oder nichts

Highlights

  • Pro

Organizations

@NSS-Team @Nebulark-net

Block or report amz202

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
amz202/README.md

Full-stack engineer with a backend focus, building event-driven systems, real-time APIs, and RBAC platforms in TypeScript and Kotlin, on PostgreSQL and Redis.

Engineering Portfolio

Role Client Domain

A cybersecurity threat intelligence platform that aggregates vulnerability data (CVEs) and exploit proofs-of-concept, tracking them against specific software inventories to provide real-time alerting and cybersecurity risk profiles.

  • Data Ingestion: Architected diverse ingestion pipelines (API polling, web scraping, and Git diffing) to continuously synchronize and normalize distributed threat intelligence feeds via transaction-safe PostgreSQL batch processing.
  • Threat Indexing: Engineered a proprietary composite risk metric for vulnerabilities that evaluates real-world exploitability by blending foundational CVSS scores, predictive EPSS probabilities, and time-decayed exploit evidence with immediate federal catalog overrides.
  • Event-Driven Alerting: Built asynchronous, idempotent notification pipelines (Email, Telegram, Discord, WhatsApp) utilizing BullMQ and Redis pub/sub.
  • Infrastructure: Configured Nginx reverse proxy for real-time Server-Sent Events (SSE) stream delivery and SSR micro-caching.

NUST E-Support System

Role Client Domain Status

An enterprise IT support ticketing platform engineered for the ICT Dte., National University of Sciences and Technology (NUST), managing the complete complaint lifecycle with strict role-based access control (RBAC) for university staff and technicians.

  • State Machine Logic: Designed role-based ticket lifecycle transitions, enforcing conditional status updates per stage.
  • Real-Time Events: Integrated Socket.IO for instant, room-based event broadcasting to keep distributed teams synchronized.
  • Security & Compliance: Append-only audit logging written in-transaction with every mutating operation, and refresh-token rotation on each use with an absolute expiry to cap refresh chains.

Tech Stack:

Core Backend

Languages & Frameworks
TypeScript Node.js Kotlin Spring Boot Ktor

Data Layer
PostgreSQL Drizzle ORM Redis MongoDB

Infrastructure
Docker Nginx BullMQ Socket.IO

Mobile Frontend

Android Jetpack Compose Room DB

GitHub Stats:


Pinned Loading

  1. ClubApp ClubApp Public

    ClubApp is a native Android application designed for university environments to simplify the management of clubs and events. Students can easily discover and join clubs, browse upcoming events, and…

    Kotlin 2

  2. Nebulark-net/exploitgrid_dependency_action Nebulark-net/exploitgrid_dependency_action Public

    ExploitGrid dependency scanner for GitHub Actions. Detects CISA KEVs and public PoC exploits in Node.js projects and blocks risky PRs.

    TypeScript