DevSecOps · AppSec

M Amin Nasiri nXenon · امین نصیری

DevSecOps & Application Security Engineer

DevSecOps and Application Security Engineer with 7 years in software, 5 in security, focused on automating security at scale. Led a company-wide DevSecOps program at fintech and crypto companies, backed by hands-on pentesting of web, REST/gRPC APIs, mobile, and networks. Builds LLM agents for security automation and assesses AI systems, including MCP servers and guardrails. Peer-reviewed researcher whose HTTP/3 race-condition attack PortSwigger built into Burp Suite's Turbo Intruder.

Amin Nasiri (امین نصیری), DevSecOps and application security engineer
01

Research & selected work

H3SpaceX

Library built on quic-go for performing the single datagram attack (SDA) against HTTP/3 endpoints.

Library QUIC

H2SpaceX

HTTP/2 single-packet attack library, with a timing feature for exploiting timing attacks and race conditions.

Library HTTP/2
02

Writing & talks

03

Open source & tools

04

Contact

Open to talking about application security research, protocol-level attacks and DevSecOps.