Abbas Naderi Afooshteh

Entrepreneur, Security Researcher, Software Engineer
Charlottesville, US.

About

Highly accomplished Entrepreneur, Security Researcher, and Software Engineer with a proven track record of leading and scaling technology companies, developing cutting-edge cybersecurity solutions, and transforming complex systems. Expert in full-stack software engineering, advanced vulnerability research, and building high-performing remote teams. Recognized globally for significant contributions to cybersecurity, including numerous CVEs, bounties, and industry-leading training platforms. Drives impactful technical innovation and business growth.

Work

ZDResearch LLC
|

Co-Founder, CEO

Summary

Founded and led a cybersecurity firm specializing in advanced vulnerability research, security tool development, and best-in-class training, operating a fully remote, global team.

Highlights

Led and managed a 100% remote, digital nomad team of 12 world-renowned hackers and engineers.

Conducted advanced cybersecurity vulnerability and mitigation research, resulting in hundreds of awarded discoveries (CVEs, bounties), and presented findings at top global cybersecurity venues.

Directed the active development of commercial and open-source cybersecurity tools and projects, including OWASP ZSC, OWASP Nettacker, and ZDResearch Hybrid Taint Inference Firewall.

Developed and delivered best-in-class cybersecurity training across multiple practical areas, such as Win32 Reverse Engineering and Exploit Development, via Exdemy.com.

Provided expert custom vulnerability research and consultation services to diverse clients.

ContentFly
|

Consultant (through ZDResearch LLC)

Summary

Provided strategic consulting to evolve an MVP into a robust enterprise platform, significantly improving software engineering processes and enabling rapid organizational growth.

Highlights

Transitioned an MVP product, developed by two core developers, into an enterprise platform utilized by thousands of users globally.

Implemented industry-standard software engineering processes and practices, including code reviews, automated testing infrastructure, and multi-stage continuous deployments, reducing risk and improving productivity.

Contributed to scaling ContentFly's engineering team from 9 to over 100 people in less than one year, building a 100% remote culture.

RupaHealth
|

Senior Software Engineer

Summary

Enhanced software engineering and cybersecurity processes, ensuring HIPAA compliance for healthcare integrations.

Highlights

Solidified and adapted industry-standard software engineering and cybersecurity processes.

Developed and implemented a HIPAA-compliant integration subsystem for secure interaction with other healthcare institutions.

MotionArray
|

Senior Software Engineer

Summary

Led the expansion of the engineering team and spearheaded a critical codebase refactoring project, significantly improving system stability, user growth, and revenue.

Highlights

Led the expansion of MotionArray's 100% remote engineering team from 2 to 13 members, including DevOps and QA engineers.

Refactored a multi-million-line codebase, developed over 6 years by independent contractors, into a robust and stable system with 99.9% automated test coverage and high uptime.

Contributed to the company's quintupled growth in less than one year, resulting in over 1 million users and more than $1 million USD in monthly revenue.

Played a key role in the company's acquisition by Artlist Ltd. in November 2020 for $65 million.

Google
|

Software Engineer

Summary

Contributed to core ChromeOS development, focusing on secure native Linux binary support and inter-process communication.

Highlights

Integrated native Linux binary support into the ChromeOS kernel, including multiple security layers, enabling Android Studio development on Chromebooks.

Developed TCP/IP compatible VSOCK communication channels within the Linux Kernel to facilitate secure communication between Chromebook isolated VMs and TCP/IP compatible applications.

Implemented user-space NFS over VSOCK to provide file-sharing support for isolated native applications.

Volunteer

Various Professional & Academic Conferences/Journals
|

Program Committee Reviewer

Summary

Contributed to the academic and professional community by reviewing submissions for prominent journals and conferences in computer science and cybersecurity.

Highlights

Reviewed for Computers & Security Journal (Elsevier) from 2020-2023.

Reviewed for IEEE conferences including AICTC'23, ICSH'23, MobiApps'23, CyMaEn'23, 3ICT'22, MENACOMM'22, SRC'22, DATA'22, 3ICT'21, SRC'21, DATA'21, MENACOMM'21, FEMRC-UOB'20, SCS'20, 3ICT'20, DATA'20, ECONF'20, SRC'20, SCS'19, IJCDS'19, 3ICT'18, SCCCS'18, SRC'18.

University of Virginia
|

Co-Instructor, Graduate Defense Against the Dark Arts

Summary

Co-instructed an advanced graduate-level course on cybersecurity, covering topics from reverse engineering to web application security.

Highlights

Co-instructed an advanced graduate-level course covering a myriad of cybersecurity topics, from reverse engineering to exploit development and web application security.

Multiple Universities
|

Teaching Assistant, Multiple Curricular Courses

Summary

Provided teaching assistance for numerous courses across various universities, supporting student learning in computer science and engineering.

Highlights

Served as a teaching assistant for 15 courses at National University of Iran.

Served as a teaching assistant for 1 course at Sharif University of Technology.

Served as a teaching assistant for 4 courses at University of Virginia.

National University of Iran
|

Instructor, Multiple Curricular & Extracurricular Courses

Summary

Instructed multiple curricular and extracurricular courses, including operating systems, databases, game development, and information security.

Highlights

Instructed 3 curricular labs, including Operating Systems Labs and Database Labs.

Taught 10 full-semester extracurricular courses, including 3D Game Development, Information Security and Cryptography, and Classic Cryptography.

Education

University of Virginia

Ph.D.

Computer Science

Grade: N/A

Courses

Dissertation: Defeating Injection Attacks on Web Applications using Emulization and Hybrid Taint Inference.

Carnegie Mellon University

M.Sc.

Information Security Technology and Management

Grade: N/A

Sharif University of Technology

M.Eng.

Computer Software Engineering

Grade: N/A

National University of Iran

B.Eng.

Computer Software Engineering

Grade: N/A

Awards

1st Place, National Collegiate Cyber Defense Competition

Awarded By

National Collegiate Cyber Defense Competition

Achieved 1st place in a national competition demonstrating superior cyber defense capabilities.

1st Place, Mid-Atlantic Collegiate Cyber Defense Competition

Awarded By

Mid-Atlantic Collegiate Cyber Defense Competition

Secured 1st place in a regional collegiate cyber defense competition.

2nd Place, DARPA Cyber Grand Challenge

Awarded By

DARPA

Awarded $1,000,000 cash prize for achieving 2nd place in a prestigious cybersecurity challenge.

Best Innovator, OWASP WASPY Awards

Awarded By

OWASP

Recognized as a leading innovator by OWASP for contributions to web application security.

1st Place, National Hacking Competition

Awarded By

National Hacking Competition

Secured 1st place in a national hacking competition.

1st Place, Stripe CTF

Awarded By

Stripe

Achieved 1st place in the Stripe Capture The Flag competition.

3rd Place, National Hacking Competition

Awarded By

National Hacking Competition

Secured 3rd place in a national hacking competition.

17th Place, ACM International Collegiate Programming Contest

Awarded By

ACM

Achieved 17th place in the international collegiate programming contest.

Publications

Cubismo: Decloaking server-side malware via cubist program analysis

Published by

ACSAC

Summary

Co-authored a publication on decloaking server-side malware using cubist program analysis.

Malmax: Multi-aspect execution for automated dynamic web server malware analysis

Published by

ACM CCS

Summary

Co-authored a publication on multi-aspect execution for automated dynamic web server malware analysis.

LRBAC: Flexible function-level hierarchical role based access control for Linux

Published by

ISCISC

Summary

Co-authored a publication on flexible function-level hierarchical role-based access control for Linux.

Joza: Hybrid taint inference for defeating web application sql injection attacks

Published by

DSN Conference

Summary

Co-authored a publication on hybrid taint inference for defeating web application SQL injection attacks.

Languages

English

Fluent

Persian (Farsi)

Native

Skills

Cybersecurity

Vulnerability Research, Exploit Development, Reverse Engineering, Web Application Security, Taint Inference, Malware Analysis, Penetration Testing, Security Architecture, OWASP, HIPAA Compliance, Cryptography, Digital Forensics.

Software Engineering

System Design, Scalable Systems, Distributed Systems, Backend Development, Linux Kernel Development, TCP/IP, VSOCK, NFS, Code Review, Automated Testing, CI/CD, DevOps, QA, Product Development.

Programming Languages

C/C++, Python, Go, Assembly.

Leadership & Management

Team Leadership, Remote Team Management, Strategic Consulting, Organizational Scaling, Process Improvement, Business Development, Startup Operations, Mentorship.

Platforms & Tools

ChromeOS, Android Studio, OWASP ZSC, OWASP Nettacker, Exdemy.com.