Muhammad Ramis
▋
Software engineer with 10+ years building event-driven Java/Kafka backends, .NET microservices, AI/LLM products and accessible React front-ends - and an OSCP+ penetration tester who breaks systems to build sturdier ones. Engineering, AI/ML, security and UX, treated as one craft.
Pick a lens - the whole site re-tailors itself.
CTO → AppSec lead → researcher
Two disciplines, one operator
Projects & contributions
Offensive tooling, security engineering, platforms and product UX. Filter by discipline - cards open full details.
51 findings · public & private
Accepted coordinated-disclosure findings across several public and private programs, each with a reproducible PoC. Program breakdown and a redacted disclosure log below.
Where I've made an impact
From the field notes
Methodology, build logs and research - offensive, defensive, engineering and design.
Written in the open - posts live as Markdown in the repo and are published through a Git-based CMS.
Let's build something together
Available for consultancy, contract and freelance projects across security, engineering, AI and UX, and open to hire for senior / staff roles in the UK. Tell me about your project and I'll get back to you.
How I can help
Security testing & assessment
Web, API, cloud and Active Directory penetration testing (OSCP+), with reproducible PoCs and fix-focused reports.
AppSec & secure SDLC
Secure code review, threat modelling and SAST/DAST automation built into your CI/CD pipeline.
AI / LLM engineering
Agentic systems, RAG pipelines, evals and guardrails, plus red-teaming LLM agents for safety.
Backend & platform
Event-driven Java/Kafka and .NET services built to scale, stay up and ship securely.
Project-based, retainer or fractional. Remote, hybrid or on-site in the UK. A quick call is the best place to start.
Quick answers
Are you available for consultancy or contract work?
Yes. I take on consultancy, contract and freelance engagements - penetration testing, application security reviews, AI/LLM builds and full-stack delivery - project-based or retainer, remote-first from Nottingham, UK.
Are you open to full-time roles?
Yes. I am open to senior software engineering, application security and security engineering roles, UK-based or remote, and I can start immediately.
What do you specialise in?
- Event-driven Java/Kafka backends and .NET microservices
- LLM agent systems, RAG pipelines, evals and guardrails
- Accessible React and TypeScript front-ends
- Offensive security: OSCP+ certified, 51 accepted bug-bounty findings
How do I get in touch?
Email hello@ramis.me, send the inquiry form on this page, or message me on LinkedIn. I usually reply within one business day. For roles, contracts or project scoping, include a little about the timeline and scope and I will come back with availability and next steps.