~/omar — zsh — 80×24
omar@portfolio:~$neofetch
product engineer · dhaka, +06
omar@portfolio:~$ press any key or tap to continue
OmarFaruk-0x01 / portfolio
location DHA / +06 status open · q2
~/omar $ whoami --verbose

Omar Faruk

Product engineer with a security habit. I build full-stack software end-to-end — and I spend the rest of my time finding what breaks it. Currently auditing internal security with the same eye I used when writing the feature at Klasio.

role
product engineer · security enthusiast
stack
react · typescript · go · laravel · php
interests
cs fundamentals · web security · programming
experience
6 yrs · 10+ shipped
status
● open to collaborations · q2 2026
$ tail -f now.log
uptime 6y reading OSTEP ch.7 shipping klasio auditing internal sec learning cs fundamentals timezone +06 DHA shell zsh editor neovim status open to collabs side-quest sawn · take-a-break coffee uptime 6y reading OSTEP ch.7 shipping klasio auditing internal sec learning cs fundamentals timezone +06 DHA shell zsh editor neovim status open to collabs side-quest sawn · take-a-break coffee
/* 01 */

Words from the legends.

a few people I've built with
Omar really cares about his work and stays focused. He learns fast because he understands the basics well. He also has a good eye for UI/UX, and it shows in what he builds.
Anis Uddin Ahmad Anis Uddin Ahmad Founder & CTO · Figlab
I call him the Young Superstar Dev. The mindset he has towards solving problems is rare these days. A sharp polyglot I would say.
M. Mahbubur Rahman M. Mahbubur Rahman Co-Founder & CTO · iViveLabs
I’ve worked with Omar Faruk for a few years, and he’s really solid at engineering and security. He knows his basics well, thinks about security, and puts in the work. I’d recommend him for any team.
Ahmed Shamim Hassan Ahmed Shamim Hassan Senior Software Engineer · Kahf
/* 02 */

Selected work.

shipped & in-flight · 10+ total
  1. 01 klasio product engineer · LMS for schools and tutors · shipping features, auditing internal security in parallel typescript · next · postgres 2023—nowlive
  2. 02 tinkerflow a modern tinker for Laravel devs · live reactive REPL with eloquent autocomplete, LSP, and SSH remote debugging · waitlist open laravel · php · lsp 2026waitlist
  3. 03 sms-trap decoy SMS gateway with a tiny dashboard · catch scrapers and naive integrations without burning SMS budget go · sqlite · htmx 2024live
  4. 04 sawn personal recursive DNS resolver written from scratch in Go · learning-by-building, private repo go · udp · dnssec 2025private
  5. 05 take-a-break desktop break-reminder app · customizable intervals, personal messages · built for my own RSI habit tauri · rust · react 2024live
/* 03 */

What I work on.

three disciplines · one desk
/* 03.1 · engineering */

Building products, end to end.

Build both ends — the UI and the backend behind it. Mostly TypeScript and PHP, whatever the job actually needs.

I like typed APIs because guessing what a response looks like wastes everyone's time. Migrations should be reversible — prod isn't the place to find out they aren't. I'd rather ship code the next person can read than code that makes me look clever.

vi ./principles.md 6 rules
1weekly cadence · no hero releases
2typed APIs · explicit error boundaries
3migrations roll back · dry-run always
4read PRs like an attacker before merge
5observability before scale
6no premature abstraction — three is a pattern
~
~
principles.md [RO] · markdown utf-8 · 6L · ~/omar
/* 03.2 · security */

Reading the code the way an attacker would.

Real web security — IDORs, broken access control, the quiet business-logic assumptions that turn into incidents. Same eye I use writing the feature.

Currently auditing internal security at Klasio: access-control boundaries, tenant isolation, a lightweight threat model alongside the roadmap.

cat ./review.logok
IDOR sweep on tenant-scoped endpointsweekly
Broken access control regression testsci
OWASP Top 10 checklist per PR surfaceactive
Legacy role matrix — shrinkingq2
Input taint review · server boundariesstanding
Audit log · append-only · per-tenantledger
Threat model revisited each releasediscipline
/* 03.3 · fundamentals */

The bits under the abstraction.

Half my curiosity lives below the framework — operating systems, kernels, memory, concurrency. Not for show. It's what turns a gnarly production incident from magic into a trace you can actually read.

Right now I'm reading OSTEP — slow, one chapter at a time, between real work.

gdb ./system.stack now: OSTEP · ch ~
book Operating Systems: Three Easy Pieces reading
user shell · processes · libc app
syscall read · write · mmap · clone boundary
kernel scheduler · vfs · vm · net reading
driver block · char · net-iface next
hw cpu · mmu · dma · io silicon
now: OSTEP — one chapter at a time
/* 04 */

Writing.

notes on the craft
writing/ first post, soon.
/* 05 */

Get in touch.

usually replies within a day

Got something
worth building?