Skip to content
View Sarmad426's full-sized avatar

Highlights

  • Pro

Block or report Sarmad426

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sarmad426/README.md

Hi, I'm Sarmad Rafique 👋

Software Engineer · Cybersecurity · Agentic AI Security

Building production software, breaking and securing AI agent systems, and specializing in the security of autonomous, tool-using AI.


About Me

I'm a Software Engineer with 4+ years of experience building production web applications, APIs, and SaaS platforms — and I now spend most of my time working at the intersection of security engineering and AI systems.

My background in full-stack and backend engineering gives me a practical understanding of how applications, APIs, and infrastructure are actually built — which is exactly what informs how I think about how they fail, get attacked, and get secured. That engineering-first foundation carries directly into my current focus: Agentic AI Security.

Most engineers are focused on making AI agents more capable. I'm interested in making them secure.

As AI systems become more autonomous and tool-using, the hard problems shift toward trust boundaries, permissions, tool access, and agent behavior — not just model capability. That's the space I'm building toward.


🔐 Security Focus

  • Application & API Security — secure API development, secure code review, vulnerability assessment
  • Cybersecurity Tooling — building scanners and automated security assessment platforms, not just running them
  • Cloud, Network & CI/CD Security — attack surface discovery, DNS/TLS security, OSINT
  • AI & Agentic AI Security — prompt injection, excessive agency, tool-access boundaries, agent-to-tool trust
  • Studying and applying OWASP LLM Top 10, OWASP Agentic Top 10, OWASP MCP Top 10, and MITRE ATLAS

🚀 Featured Projects

Cyntra — Cybersecurity Scanning Platform Web-based platform for automated security assessment of applications and infrastructure. Built the scanning backend and security analysis workflow in Python/FastAPI, with findings surfaced through a web reporting interface. Example scan report →

Velentra — AI Buying Intent Tracker AI-powered platform that analyzes public Reddit conversations to surface buying intent and brand mentions. Built the data collection and processing pipeline.


🛠️ Tech Stack

Backend Python FastAPI

Frontend TypeScript React Next.js

Data & Infra PostgreSQL Docker Linux Git

AI Generative AI AI Agents Agentic AI


📚 Learning Path

Software EngineeringNetworkingCybersecuritySecurity EngineeringAI SecurityAgentic AI Security

Google Cybersecurity Professional Certificate · Cisco Networking Certification · Foundations of Cybersecurity · Connect and Protect: Networks and Network Security · Play It Safe: Manage Security Risks


📫 Let's Connect

I'm always open to conversations about application security, AI/agentic security, or security engineering roles.

LinkedIn · X · Portfolio · sarmadrafique040@gmail.com

Pinned Loading

  1. Agentic-ai Agentic-ai Public

    Agentic AI. AI agents are a software programs which performs operations on behalf of the user.

  2. Generative-AI Generative-AI Public

    Generative AI (ChatGPT, Gemini) API's and Hugging face transformers. Projects with streamlit.

    Jupyter Notebook 7 3

  3. WebSacraper.ai WebSacraper.ai Public

    Forked from SaraQadar779/WebSacraper.ai

    Enter any website URL and extract all visible text content from its internal pages in one click. Clean. Simple. Efficient.

    HTML

  4. Multi-PDF-Chat Multi-PDF-Chat Public

    Forked from Danish7861/Multi-PDF-Chat

    Python

  5. Python Python Public

    Python mastery. OOP | Numpy | Pandas | Jupyter Notebook & more.

    Jupyter Notebook 1

  6. FastAPI FastAPI Public

    Python API development with Fast API and SQL Model ORM. Microservices Backend architecture.

    Python 2