AI Security / Offensive Security

Kuala Lumpur / MY

MahirAsif

01 — 07 / PORTFOLIO 2026

I break systems, engineer agentic workflows, and build safer intelligent systems. Offensive security meets AI security and precise engineering.

Mahir Asif, AI security and offensive security engineerAI Security / OffSec / Build

01 / Profile

Adversarial by craft.
Systems by obsession.

Black and white portrait of Mahir Asif

I like systems most when I can understand their assumptions, stress them, and engineer better ones.

I’m Mahir, a cybersecurity and AI security engineer focused on offensive security, web and API testing, security automation, cloud security, and vulnerability research. I have hands-on client assessment experience and I care about how real assessments are scoped, executed, verified, and documented.

My engineering work extends into agentic AI and ML security: Xekute explores bounded AI-assisted security assessment workflows, while VULNERA applies code-focused machine learning to function-level vulnerability risk estimation. I care about deterministic verification, evidence-first systems, and turning research ideas into usable software.

eJPT / SAASecurity + cloud
3× AWSCloud certified
AI × OffSecCurrent focus

02 / Selected work

Built where AI meets attack surface.

01 / Windows Alpha / AI Security

Xekute

A local-first AI-assisted workspace for authorized security assessment that connects scope, intercepted traffic, evidence, findings, security tooling, advanced VAPT search, and governed agent workflows. It combines authority and scope controls, verification-oriented workflows, delegated agents, and a SQLite/FTS5 assessment intelligence engine. Xekute is an active Windows alpha.

Windows AlphaAI AgentsVAPT SearchSQLite / FTS5
02 / ML Security / Research

VULNERA

A function-level vulnerability triage system for C/C++ code. The research pipeline uses GraphCodeBERT window embeddings, a supervised tree ensemble, calibrated aggregation, signature corroboration, and explainable attribution—then exposes the analysis through FastAPI and React.

GraphCodeBERTTree EnsembleFastAPIML Security
03 / Agentic AI / Realtime

Mentora

A voice-first visual AI tutor where GPT-5.6 plans focused teaching turns, ten deterministic board tools construct and verify the visual state, and a realtime voice layer performs the validated explanation. Built around strict script validation, prepared turns, state verification, and reliable multimodal orchestration.

GPT-5.6Realtime VoiceTypeScriptVerification
04 / SaaS / Production

LeadBondhu AI

A production multilingual AI lead-capture platform for Bangladeshi SMBs, supporting Bangla, Banglish, and English while integrating Meta messaging channels, Gemini, Supabase, Resend, and Cloudflare-based serverless infrastructure.

ReactCloudflareSupabaseGemini
05 / AI Automation / Local LLM

Joblicator

A local-first job application workspace that stores structured career data and job postings, then runs reviewable LLM stages to generate tailored résumés and cover letters. A React interface, Python backend, visual templates, and local HTML/PDF export keep the workflow auditable and portable.

ReactPythonLLM PipelineHTML + PDF
06 / Local AI / Voice UX

Jarvis

A local Windows voice assistant using wake-word detection, faster-whisper speech recognition, layered intent routing, deterministic tool execution, and a local LLM fallback for ambiguous commands so common actions stay fast and predictable.

Pythonfaster-whisperOllamaTool Routing
07 / Studio / Production

devprobs

A studio for websites, custom software, and web development with a full VAPT included in every package. Honest pricing, short delivery loops, and security treated as part of the build rather than a separate engagement.

WebSoftwareVAPTStudio

03 / Capabilities

Attack surface to agent architecture.

01

Offensive Security

Web / API testing · reconnaissance · validation · cloud review · VAPT reporting

02

AI & Agent Security

Tool boundaries · authority models · scope controls · agent permissions · human-in-the-loop design

03

Security Automation

Agent harnesses · deterministic execution · verification · recovery · evidence pipelines

04

ML Security Research

GraphCodeBERT · PyTorch · dataset pipelines · model adaptation · calibrated risk estimation

05

Cloud & Systems

AWS · Azure review · Linux · networking · Bash · serverless architecture

06

Product Engineering

Python · TypeScript · React · Electron · FastAPI · APIs · software delivery

04 / Experience

Research that ships.

2025 — Present
Kuala Lumpur, Malaysia

01

Independent Security & AI Engineering

Research / Open-source / Product work

  • Architected Xekute, a local-first AI-assisted security assessment platform with bounded agent execution, tool gating, verification, and evidence intelligence.
  • Built VULNERA, a code-focused ML research pipeline for function-level vulnerability risk estimation in C/C++.
  • Shipped devprobs, a studio offering websites and software with a full VAPT included in every package.
  • Shipped production and experimental AI systems spanning SaaS, realtime voice, local LLM workflows, and deterministic tool orchestration.
  • Focus current research on the intersection of offensive security, agentic AI, security automation, and reliable autonomous systems.

Oct 2025 — Jan 2026
Kuala Lumpur, Malaysia

02

Junior Penetration Tester

FSeC @ APU / APIIT

  • Performed web application and API penetration testing for Australian enterprise and Malaysian government clients.
  • Reviewed security configurations across AWS and Azure environments.
  • Documented vulnerabilities using structured, CVSS-based severity ratings and reproducible evidence.
  • Translated technical findings into practical remediation guidance to reduce client attack surface.

05 / Credentials

Foundation for the work.

06 / Start a conversation

Have a system worth testing? Or an agent worth trusting?