Based in Dubai, UAE

Muhammad Kashif Raza

I build full-stack web applications that are scalable by architecture and secure by design.

Contact Me
Find me on:
Muhammad Kashif Raza

About Me

Who I Am & My Background

WHO I AM

Designing resilient full-stack systems.

I engineer full-stack systems that scale—and resist attack. With 2+ years building ERP/CRM platforms using MERN, TypeScript, and Next.js, I specialise in backend-heavy architecture, API design, and system integrations. But I don't stop at "it works." I ask: "Is it secure by design?"

My security focus isn't theoretical. I apply OWASP guidelines to real projects: hardening authentication flows, implementing parameterised queries to prevent injection, and designing RBAC systems that follow least-privilege principles. I'm currently deepening my hands-on security skills through structured labs, vulnerability research, and automation scripting (Python/Bash).

What I bring to teams: senior-capable full-stack engineering (scalable backends, clean API contracts, performance optimization), security-aware development (threat modeling in design, secure coding patterns), and hybrid value—I bridge the gap between dev and security, reducing rework and accelerating secure delivery.

0+

Years Engineering

0

Roles Delivered

0K+

Daily Transactions

0+

Concurrent Users

Education & Qualifications

National University of Computer and Emerging Sciences (FAST-NUCES)

Bachelor's, Computer Software Engineering

September 2021 — September 2025

Experience

Enterprise delivery with security built in

Skills

Languages & Proficiency Profiles

95%

JavaScript

Expert
90%

TypeScript

Expert
80%

Python

Advanced
75%

Dart (Flutter)

Advanced
88%

SQL

Advanced
70%

Bash / Shell

Intermediate

Tech Stack

My core development toolbox and stack

React
Next.js

Other Skills

Methodologies & Supporting Technologies

System Architecture Design
Client Requirement Analysis
Agile / Scrum Methodology
Scalable API Design
OWASP-Aware Development
PostgreSQL Query Optimisation
Security-Aware SDLC
System Architecture Design
Client Requirement Analysis
Agile / Scrum Methodology
Scalable API Design
OWASP-Aware Development
PostgreSQL Query Optimisation
Security-Aware SDLC
System Architecture Design
Client Requirement Analysis
Agile / Scrum Methodology
Scalable API Design
OWASP-Aware Development
PostgreSQL Query Optimisation
Security-Aware SDLC
System Architecture Design
Client Requirement Analysis
Agile / Scrum Methodology
Scalable API Design
OWASP-Aware Development
PostgreSQL Query Optimisation
Security-Aware SDLC
Microservices
Technical Team Leadership
In-House Server Deployment
Code Review & Mentorship
RBAC & Least Privilege
WebSocket Integration
Microservices
Technical Team Leadership
In-House Server Deployment
Code Review & Mentorship
RBAC & Least Privilege
WebSocket Integration
Microservices
Technical Team Leadership
In-House Server Deployment
Code Review & Mentorship
RBAC & Least Privilege
WebSocket Integration
Microservices
Technical Team Leadership
In-House Server Deployment
Code Review & Mentorship
RBAC & Least Privilege
WebSocket Integration

Projects

Selected Engineering Work & Platforms

SifGen — WPS SIF File Generator
Full Stack★ Featured

SifGen — WPS SIF File Generator

Free browser-based tool for UAE employers to generate WPS Salary Information Files (SIF) instantly. Supports bulk Excel/CSV import, IBAN validation, and outputs EDR & SCR records — all processed 100% client-side with zero data storage or registration.

Tech Stack
Next.jsTypeScriptReactMUI
Click to view details
ERP Notifications — Kafka & WebSockets
Distributed Systems

ERP Notifications — Kafka & WebSockets

High-throughput, event-driven orchestration layer distributing enterprise real-time updates via decoupled microservices. Apache Kafka ingests invoicing actions; WebSockets stream sub-second status notifications to reactive UIs.

Tech Stack
Node.jsKafkaSocket.IOReact
Click to view details
JWT Hardening Monorepo
Security / Auth

JWT Hardening Monorepo

Production-grade JWT authentication monorepo featuring Redis-backed refresh token rotation, breach detection via family wipe on token reuse, algorithm confusion prevention (HS256 pinning), XSS/CSRF mitigations, and a Next.js security lab workspace for live attack-and-defence scenarios.

Tech Stack
Node.jsExpressTypeScriptRedisNext.jsDocker
Click to view details
WebSocket Resilience — React Native
Mobile / Network

WebSocket Resilience — React Native

Fault-tolerant network engine managing resilient WebSocket links across unstable mobile interfaces with exponential backoff, heartbeats, and offline message queues.

Tech Stack
React NativeExpoWebSocketJavaScript
Click to view details
React Native Performance Demo
Mobile / Performance

React Native Performance Demo

Hands-on demo taking a React Native list from 12 FPS → 60 FPS across 5,000 invoice records. Showcases three targeted fixes — React.memo, useMemo, and FlatList virtualization props — with a live FPS counter and side-by-side toggle between unoptimized and optimized modes.

Tech Stack
React NativeExpoTypeScript
Click to view details
PostgreSQL Optimization
Database Engineering

PostgreSQL Optimization

Performance blueprint for PostgreSQL and Sequelize demonstrating indexing strategies, N+1 countermeasures, and transaction control for low-latency queries at scale.

Tech Stack
PostgreSQLSequelizeJavaScript
Click to view details
Email Cleanup Service
Full Stack

Email Cleanup Service

Production-ready full-stack platform for secure OAuth2 Gmail linking, sender analytics, and asynchronous batch inbox cleanup with a glassmorphic UI.

Tech Stack
TypeScriptNode.jsExpressMongoDBReactTailwind
Click to view details
CSR vs SSR vs ISR
Frontend Architecture

CSR vs SSR vs ISR

Architectural laboratory comparing Client-Side, Server-Side, and Incremental Static Rendering lifecycles with identical layouts to expose TTFB, payload, and SEO trade-offs.

Tech Stack
TypeScriptNext.jsReact
Click to view details
Cyberpunk Eid Card
Creative UI

Cyberpunk Eid Card

Responsive thematic generator with cyberpunk neon components, programmatic user-string injection, and atomic style management.

Tech Stack
TypeScriptReactVite
Click to view details
MERN Lectures
Technical Enablement

MERN Lectures

Instructional repository of production-ready MERN patterns: REST route separation, Mongoose schemas, and React state integration examples.

Tech Stack
JavaScriptNode.jsExpressMongoDBReact
Click to view details