Curriculum vitae
Abdulah Proho
Security Engineer & Full-stack Developer
Summary
Security engineer and full-stack developer with professional software development experience since 2018. Currently SecOps Lead at Circeus, performing source-code security audits, penetration testing and application security assessments, with a background in building and modernizing commercial Shopify applications.
Experience
SecOps Lead · Circeus
Application security work across a portfolio of more than 50 applications, as part of the company's security and engineering teams.
- Perform source-code security audits
- Conduct penetration testing and application security assessments
- Support security improvements across a portfolio of more than 50 applications
- Identify and assess vulnerabilities
- Recommend improvements to application security controls
- Improve security practices within software development processes
- Develop and improve security-related tooling
- Draft security policies
- Help development processes adapt to security challenges introduced by AI-assisted software engineering
Senior Full-stack Developer · ShopCircle
Worked on established Shopify applications, building functionality, maintaining existing systems, modernizing legacy code, fixing bugs, and improving performance and security.
- Mentoring junior developers
- Participating as a guest speaker in an internal developer talk
Accentuate Custom Fields
Modernized a legacy application through frontend migration, React adoption, performance work, bug fixes, and feature development.
Releasit COD Form & Upsells
Built a replacement React-based Shopify storefront extension, rewriting an approximately 20,000-line legacy extension while introducing new functionality, configurability, and security improvements.
Full-stack .NET Developer · Ankeboot
Full-stack software development using .NET technologies.
Freelance Developer · Self-employed
Independent software development for clients found through Upwork and other freelance platforms.
Key competencies
- Application Security
- Web application penetration testing, Source-code security auditing, Vulnerability research, Application security reviews, Secure development practices, Vulnerability assessment, Security tooling
- AI and Developer Tooling
- AI-assisted application development, Developer productivity tooling, Local and self-hosted AI systems, AI content production workflows
- Backend Engineering
- Node.js, Go, .NET / C#, Python, API development, Databases
- Frontend Engineering
- React, TypeScript, JavaScript, HTML and CSS, Next.js, Tailwind CSS
- Systems and Language Development
- Programming language implementation, Compilers, LLVM, Systems programming
Certifications
Security research
Selected projects
BPL3
A statically typed compiled programming language targeting LLVM, exploring native compilation, modern language features, and developer tooling.
OpenManga
A self-hosted platform for creating AI-generated manga, manhwa, webtoons, and narrated video content through structured story planning, image generation, character references, narration, and production workflows.
CodeGuardian
A local security auditing tool combining static analysis, existing security scanners, AI-assisted source review, vulnerability triage, and structured reporting.
ExposeGuard
An infrastructure exposure validation platform: it checks whether each service is reachable from where it should be — and only from there.
Education
- Logos, Mostar
Bachelor's level, 180 ECTS (not yet awarded) · Awaiting final defense
Transferred in 2023. Awaiting defense of the third-year final project.
- Faculty of Information Technologies (FIT), Mostar
Not completed
Studied at FIT before transferring to Logos in 2023.