Helping companies find security gaps before attackers do — and building the AI & automation that keeps them safe.
I'm a China-based AI Security Researcher and Penetration Tester, currently pursuing an MSc at Xinjiang University (Ürümqi), where my research focuses on Industrial Anomaly Detection. That places my work close to the manufacturing and IIoT ecosystem combining offensive security with practical industrial AI research and production engineering.
I work across three areas: application & API security testing, DevSecOps automation, and industrial AI / LLM safety.
Responsible for a plant, an IIoT platform, or an early-stage product where security, uptime, and AI reliability affect the business? Let's talk → zus3cu@gmail.com
Web apps, APIs, authentication flows, and cloud/connected business systems assessed with an attacker-informed methodology. Reproducible, CVSS-scored reports with clear remediation guidance.
- OWASP Top 10 · API security · OAuth 2.0 flow analysis · TLS review
- Tooling: Burp Suite, OWASP ZAP, Nuclei, Nmap, SQLMap, Amass, ffuf
Security that runs inside production, not as a separate audit.
- Infrastructure & VPN automation, ERP hardening, CI/CD, Docker, nginx, cloud
- Python tooling: recon/OSINT, scanning, reporting, browser automation, scraping
- Industrial anomaly detection & explainability (PyTorch, anomalib)
- LLM/RAG systems, prompt-injection defense, AI security evaluation
| Project | What it is | Stack |
|---|---|---|
| VPN Production Platform vpn.zus3c.info | Live OpenVPN/WireGuard automation + customer portal (create / renew / revoke, diagnostics). ~12.8k lines. | Python, Flask, nginx, Alibaba Cloud |
| Enterprise ERP (delivered client project) | Sales/purchase workflows, RBAC, automated tests, production containers. | Next.js, NestJS, Prisma, PostgreSQL, Redis, BullMQ |
| MalwareGuard-AI | Static malware classifier (PE/ELF headers, entropy) with FastAPI + SHAP explainability. | Python, scikit-learn, FastAPI |
Security research highlights
- Critical SQL Injection responsibly disclosed on a production e-commerce platform (CVSS-scored report, 2024)
- Critical OAuth 2.0 nonce vulnerability responsibly disclosed to Windsurf (CVSS 7.1, 2025)
- ISO 27001 gap analysis and OWASP engagements with dated, reproducible reporting
- offsec-toolkit automated installer/config for 300+ offensive-security tools across 20+ categories
- MalwareGuard-AI AI-powered static malware detection (Random Forest/XGBoost + FastAPI + SHAP)
- BugDrillX bug-bounty learning platform: recon → web/mobile testing roadmap
- ssrf-cheatsheet-2025 modern SSRF attack-vector reference
- Smart-Cursor-System-2.0 accessibility tool: control the cursor with facial gestures (computer vision)
| Certification | Provider | Year |
|---|---|---|
| Certified Network Security Specialist (CNSS) | ICSI (UK) | 2020 |
| Lean Six Sigma — White Belt | BGMC (England) | 2022 |
| Kali Linux for Advanced Pen Testing | LinkedIn Learning | 2023 |
| Agile Testing | LinkedIn Learning | 2023 |
I write methodology and analysis, not blurbs.
- Bug Bounty Methodology (Volume 2)
- Bug Hunting with GPT: Tips, Tricks, and Prompts
- Why 95% of Micro-SaaS Startups Fail — and How Solo Founders Can Win
I take on fixed-scope, professional engagements for startups and businesses:
- Web App / API Security Audit attacker-informed testing + CVSS-scored report with remediation
- Python Automation & Tooling scraping, OSINT, security automation, internal tools
- AI / LLM Integration RAG systems, LLM safety review, anomaly detection
Get a quote → zus3cu@gmail.com · Portfolio & services: zus3c.info
| Portfolio | zus3c.info |
| GitHub | github.com/TheZubairUsman |
| linkedin.com/in/thezubairusman | |
| Medium | medium.com/@thezubairusman |
| zus3cu@gmail.com |
Based in Ürümqi, China (UTC+8) · Originally from Pakistan · Goal: bridge cybersecurity and AI for Industry 4.0

