Zeyu (Zayne) Zhang
Email:
[email protected] | W
ebsite:
analogue.computer
| Link
edIn:
www.link
edin.com/in/zhang-zeyu
Education
University of Cambridge Oct. 2023 – 2027 (Expected)
B.A. (Hons) and MEng in Computer Science Cambridge, England
•
Grade: 1st Class. Highest mark for Object-Oriented Programming. Top 5 in: Databases, Discrete Mathematics, Machine
Learning & Real-world Data, Software & Security Engineering.
•
Cybersecurity Society: Secretary (2024/25) – Represented the University in various international competitions.
∗ 1st place at pwnEd5 finals, hosted by the University of Edinburgh.
∗ 2nd place at the global finals of LakeCTF 2024, hosted by the Swiss Federal Institute of Technology Lausanne.
∗ 3rd place at European finals of CSAW CTF 2023, hosted by New York University.
•
Hughes Hall May Ball (2023/24) – Developed www.hughesmayball.co.uk and managed domain. React · TailwindCSS
•
CUMSA Database Officer (2024/25) – Revamped membership.cumsa.org and admin panel. Next.js · DynamoDB
Experience
Optiver Jul. 2025 – Sep. 2025
Incoming Software Engineer Intern Amsterdam, Netherlands
Open Government Products Jun. 2024 – Sep. 2024
Software Engineer Intern Singapore
•
Built & shipped a Next.js app used by HR and team leads to visualize and preview changes to access control policies on the
organization’s GitOps access control solution, reducing human error. This replaces previously ClickOps-heavy workflows.
•
Used Pulumi infrastructure as code to build a Better Stack integration that reduces time-to-triage for vulnerability reports
from several hours to < 1 minute.
•
Initiated and led a project to build open-source secure-by-default components used by developers in production systems and
our starter kit template, making application security easy and invisible. Remediated a Next.js 0-day in the process.
•
Configured CI/CD pipelines including automated NPM package publishing, changelog generation, documentation generation
from TSDoc comments (published to a documentation website), testing and deployment.
•
Initiated and configured advanced static code analysis pipelines across the organization. Wrote and published custom
CodeQL query packs and libraries for data flow analysis on common technologies used, including Next.js, React, and tRPC.
Insight Programmes 2024
•
Jane Street: One of 60 selected participants for the First-Year Trading & Technology Programme.
•
IMC Trading: One of 15 selected participants for Launchpad. 4th place in the individual low-latency challenge.
•
Macquarie Group: One of 30 selected participants for the Technology Insight Programme.
Cure53 May 2023 – Present
Freelance Security Engineer Berlin, Germany (Remote)
•
Performed 20+ code audits and VAPTs for global clients, including Fortune 20 companies.
•
Targets included web applications, browser extensions, Electron-based desktop applications, and mobile applications.
TikTok Apr. 2023 – Sep. 2023
Security Engineer Intern Singapore
•
Discovered 50+ security vulnerabilities affecting critical internal and external facing services, such as TikTok.
•
Developed Java extension on Burp Suite’s new Montoya API for testing protobuf over both WebSockets and HTTP(s), a
feature not supported by any open-source extension at the time of development.
•
Wrote and deployed to K8s a deliberately vulnerable app in React and Express used as part of an internal competition.
•
Researched at scale: Protobuf over WebSockets, XSS filter bypasses, and rich text editor vulnerabilities.
•
Weaponised a 0-day in an online word processor to harvest employee credentials in a red team operation.
Hackathons & Projects
EurekaPad | Next.js · TailwindCSS · Convex · Clerk · Radix UI · Vercel · Azure Cognitive Services
•
Supported by Microsoft for Startups. Recipient of the SUTD Baby Shark Fund grant.
•
Notion + Jupyter Notebooks for STEM students. Runnable code blocks, intuitive math editor, interactive graphs, etc.
¬ Catfish | Next.js · TailwindCSS · Radix UI · Flask · Vercel · Tavily · Antrophic API · Instagram OAuth · Tinder API
•
2nd Place @ Cam Hack 2024 (Cambridge University Hackathon).
•
AI-powered Tinder dating assistant – automatic profile updates, match compatibility, smart opening lines, and date ideas.
L
A
T
E
X Source: github.com/zeyu2001/cv | Web Version: cv.analogue.computer