CV view
RT Radu Todea
00/Intro
Say hi

Application Security Engineer Cyber-Physical Systems

Hello — thanks for stopping by.

I build machines. Then I break them — before anyone else can.

Based in Romania Open to interesting conversations

Who I am

Most engineers pick a side. Hardware or software. Builder or breaker. I never saw the line. I design the system, then attack it until it holds. Because the systems that matter now live where code touches the physical world.

Radu-Cristian Todea

Mechatronics engineer turned application security engineer. Three degrees — each with highest distinction.

Chapter I2020 — 2024

The Machine

It started with machines that had to find their own way.

Mechatronics taught me to build things that sense, decide and move on their own. My rover began as a sketch and became a machine: the chassis, the electronics, and the software that lets it map a room it has never seen and plan its own way through it. A year of electronics in Norway widened the lens.

Degree
B.Sc. Mechatronics — highest distinction
Built
An omnidirectional rover · custom electronics · digital twins
Stack
ROS 2 · LiDAR mapping · sensor fusion
Abroad
Erasmus+ · University of South-Eastern Norway
On stage
Presented my research on autonomous navigation

Chapter II2022 — 2025

The System

Then came safety-critical — where “almost right” is a failure mode.

In automotive R&D, for a global supplier, I built the automation that engineering teams relied on to keep electronic components right — for brake and suspension systems, where a mistake doesn’t crash a web page. It reaches the road.

Verification is a mindset, not a step.

  • R&D automation
  • Data integrity
  • Safety-critical electronics
  • Python

Chapter III2024 — 2026

The Convergence

Two master’s degrees, in parallel. One question: what happens when machines are attacked?

M.Sc. · Cybersecurity

Securing industrial IoT at the edge

Where the network meets the machine. The idea works; the details are .

Highest distinction

M.Sc. · Advanced Mechatronics

Intelligent monitoring for industrial processes

Teaching machines to notice when something is wrong — before a person has to.

Highest distinction

Both theses met in one machine: a portable lab I designed, wired and built by hand. Around them, an independent engineering practice — custom IoT devices built on Raspberry Pi, ESP32 and Arduino, embedded hardware and full-stack web platforms.

Chapter IV2026 — Now

The Breaker

Now I break software for a living — so it’s already fixed when someone else tries.

As an application security engineer, I audit code and test applications the way an adversary would, model threats before they become incidents — and then make sure the same bug can never quietly come back.

  • White-box code audits and grey-box penetration tests of web applications and APIs
  • Testing across the whole lifecycle — SAST, DAST, IAST, OAST, SCA, secrets and containers
  • Custom detection rules that turn every finding into a regression check in the pipeline
  • Threat models and risk ratings mapped to the frameworks auditors actually read
  • Remediation that’s verified, not assumed — findings end closed, with evidence

05How I think

Four moves.
Every system. Every time.

Keep scrolling →

01

Map

See the whole system.

From the circuit to the cloud API — code, configuration, containers and the people who run them. You can’t defend what you haven’t traced end to end.

02

Model

Think like them — first.

Every architecture has a story an attacker wants to tell. I write it down before they do.

03

Break

Test until it tells the truth.

Assumptions are hypotheses. I test them methodically and safely — and every verdict comes with its evidence.

04

Harden

Fix what matters. Prove it holds.

Findings ranked by real risk, fixed with the team, then tested again. Closed means closed — with proof.

Then I automate it.

A test that runs once is a snapshot. A test in the pipeline keeps watch. Security isn’t a state — it’s a loop.

Field notes

  1. N° 01

    Every system becomes a physical system eventually.

  2. N° 02

    Trust is a configuration, not a feeling.

  3. N° 03

    If it hasn’t been tested, it’s a rumour.

  4. N° 04

    An attacker needs one wrong assumption. I go looking for all of them.

  5. N° 05

    A bug fixed once is luck. A bug turned into a rule is progress.

  6. N° 06

    Good security tooling knows when to stay quiet.

  7. N° 07

    Report less. Fix more.

  8. N° 08

    The best security is the kind nobody has to think about.

07Your turn

Spot the fake.

Most attacks don’t start with code — they start with a link. One of these is where you’d really sign in; the others are traps of the kind that land in real inboxes every day. Pick the real one.

Round 1 of 3

Where would you sign in to LinkedIn?

The habit that beats most of these: read the address from the right, up to the first single “/”. That part is who you’re really talking to.

08What I bring

Security that goes all the way down.

  1. 01

    Application & API Security

    White-box code audits and grey-box pentests — access control, business logic and the bugs scanners miss. Every finding with its cause, its impact and a fix your developers can actually ship.

    • Pentesting
    • Code review
    • OWASP
    • Auth / MFA
  2. 02

    Threat Modeling & Risk

    Attacker-first architecture reviews and attack chains, risk rated honestly and mapped to recognised frameworks — with a risk register someone actually owns.

    • MITRE ATT&CK
    • NIST
    • ISO/IEC 27001
    • CVSS
  3. 03

    IoT, Embedded & OT Security

    Security for systems that touch the physical world — devices, firmware and industrial networks, where a bug can move a motor.

    • Embedded
    • IoT
    • OT / ICS
    • Hardware
  4. 04

    Secure Engineering, End to End

    From schematic to deployment: embedded firmware, robotics, automation and web platforms — secure from the first line.

    • C / C++
    • ROS 2
    • Python
    • Web
  5. 05

    Infrastructure, Cloud & Network

    Firewalls and segmentation, container images, infrastructure-as-code and cloud configuration — hardened against recognised benchmarks, least privilege by default.

    • Firewalls
    • Containers
    • IaC
    • CIS
  6. 06

    Security Automation & DevSecOps

    Every finding becomes a check that runs forever: custom rules and scanners wired into CI, results where developers already look — in code review — and silence when there’s nothing to say.

    • SAST · DAST
    • IAST · OAST
    • SCA · Secrets
    • CI/CD

09Toolbox

Tools change. Instincts don’t.

The tools rotate — there’s a new one on my bench most weeks. What stays is knowing which kind of tool a problem needs, and when none of them will do.

01Break

Offensive testing & analysis

  • Web & API interception
  • Manual code review
  • Recon & traffic analysis
  • Template-driven scanning
  • Proof-of-concept exploits
  • OSINT

02Defend

Detection, hardening & response

  • Firewalls & segmentation
  • IDS / IPS
  • Identity — OAuth, OIDC, MFA
  • Benchmark hardening
  • Anomaly detection
  • Digital forensics

03Automate

Security in the pipeline

  • Custom SAST rules
  • DAST & deploy-time checks
  • Dependency audits
  • Secret scanning
  • Container & IaC scanning
  • CI gates & code-review bots

04Make

Hardware, machines & software

  • Microcontrollers
  • ROS 2 · SLAM
  • C / C++ · Python
  • TypeScript · web stacks
  • PCB design
  • CAD & mechanical design

10Selected work

Proof, not promises.

Some of it is public. Some of it is need-to-know — ask me about the rest.

  1. A guardian that lives on the factory floor instead of the cloud, and decides — on its own — what to trust. It fits in a case you can carry into a plant. How it does that is .

    • Embedded
    • IIoT security
    • Detection
    Ask me →
  2. Machine learning that watches industrial networks for what doesn’t belong — and can explain why it raised the alarm.

    • Deep learning
    • Explainable AI
    • Python
    Code ↗︎
  3. A segmented cloud environment built as infrastructure-as-code, then put under a full attack chain to see which walls actually hold.

    • AWS
    • Terraform
    • Pentesting
    Read the write-up → Code ↗︎
  4. Every device has habits. This learns them, and flags the moment one starts acting like something else.

    • Machine learning
    • IoT
    • Python
    Code ↗︎
  5. Designed and built from scratch — chassis, electronics and software. Mecanum wheels to move in any direction, a LiDAR to see, and the autonomy to map a space it has never been in and find its own way through it.

    • Robotics
    • ROS 2
    • LiDAR · SLAM
  6. An industrial IoT system that watches a process, adapts to it, and diagnoses trouble early.

    • IIoT
    • Signal processing
    • Embedded
    Ask me →

11Credentials

Earned, not claimed.

Education

  • M.Sc. Cybersecurity2024–26Distinction
  • M.Sc. Advanced Mechatronics Systems2024–26Distinction
  • B.Sc. Mechatronics2020–24Distinction
  • Erasmus+ · ElectronicsNorway · 2021–22✓

Languages

  • RomanianNative
  • EnglishC2 · certified
  • GermanUniversity certified
  • FrenchB2 · independent
  • SpanishB1 · independent

Certifications & badges

01Network & security operations

  • Fortinet Certified Associate — CybersecurityFortinet · 2025
  • Fortinet Certified Fundamentals — CybersecurityFortinet · 2025
  • NSE 3 · NSE 2 · NSE 1 — Certified in CybersecurityFortinet · 2025
  • FortiGate 7.6 OperatorFortinet · 2025
  • Network Technician Career PathCisco · 2025
  • Technical Introduction to Cybersecurity · Introduction to the Threat Landscape · Getting Started in CybersecurityFortinet · 2025

02Secure development & identity

  • LFD121 — Developing Secure SoftwareThe Linux Foundation · 2026
  • Securing Applications Super badgeOkta · Auth0 · 2026
  • Secure Applications with Auth0 Attack ProtectionOkta · Auth0 · 2026
  • Secure Auth0 Apps with MFAOkta · Auth0 · 2026
  • Authenticate with Auth0 Database & Passwordless ConnectionsOkta · Auth0 · 2026

03Automation & languages

  • TAP RPA DeveloperTailent
  • TAP RPA AssociateTailent
  • English Certificate · C2 ProficientEF SET · 2025
  • German Language CompetenceUniversity certified

In the room

  • CyberSea Festival2025 · workshops & CTFs
  • Scientific Communications Session2024 · speaker
  • Cybersecurity industry meetupsOngoing

12Off the clock

Curiosity doesn’t clock out.

13Questions

Asked often.

  1. Both, honestly. I started with robots and circuit boards and ended up breaking web apps for a living. The problems I like most live right where the two meet.

  2. I look at software the way an attacker would — reading the code, poking at the running app — to find what could go wrong before someone else does. Then I help fix it, and automate the check so it can’t quietly come back.

  3. Systems that touch the real world — cars, factories, robots — and the everyday platforms people trust with their data. Anywhere getting security right actually matters.

  4. Some work belongs to the people I did it for, and some ideas are still mine. The interesting parts are better told over a coffee.

  5. Nobody keeps up with all of it — but I try. A new tool or technique most weeks, CTFs at the weekend, and a certification when it’s worth it. The credentials above are a snapshot, not a finish line.

  6. Look around — it’s a static site with nothing behind it, and it even audits itself: take a look under the hood ↗︎. On a keyboard, hold X to x-ray it. Find something real, tell me, and your name goes in the hall of fame. Just keep it to this site.

  7. Right below — hold the button to decrypt my email — or find me on LinkedIn. I read everything, even if a reply sometimes takes a day.

14Encrypted channel

Have something worth protecting?

So do I. My contact details aren’t in this page’s source — they’re encrypted, and only decrypt for a human. Check for yourself ↗︎

Keyboard: press and hold Space or Enter for about a second.

Email  

Locked · AES-256-GCM · key rotates every build

How this works
  1. Not in the source. A scraper can read this page all day and find nothing to harvest.
  2. Encrypted at build time with a fresh AES-256-GCM key. Every deploy, a new key; the plaintext never lives in the repository.
  3. Split and scattered. The key and ciphertext are sharded, shuffled and padded with decoys — reassembled only after a deliberate, trusted human gesture.
  4. Ephemeral. Decrypted in your browser, never sent anywhere, and wiped again after 60 seconds.

Honest footnote: anything a browser can show, a determined person can read. This is friction for harvesters, not secrecy — the same principle I apply to real systems. Raise the cost. Shrink the exposure.

Focus

Application · IoT / OT · Secure engineering
Open to interesting conversations

Elsewhere

LinkedIn ↗︎
GitHub ↗︎
Under the hood ↗︎

Local time

--:--:--
Romania · EET

End of transmission

000

Keep scrolling to reboot the story.

Application Security Engineer · Cyber-Physical Systems · Romania

Radu-Cristian Todea

Application security engineer with a mechatronics background, specialising in autonomous robotics and industrial cybersecurity. I design embedded and cyber-physical systems, then run the penetration testing and threat modeling that make them ready for production.

Experience

  1. Application Security Engineer

    May 2026 — Present

    Ropardo — Software Engineering

    • I built and maintain a Linux security-testing environment for running SAST, DAST & OAST assessments against web applications and APIs.
    • I run penetration tests and threat models, mapping findings to OWASP API Security Top 10, MITRE ATT&CK, NIST SP 800-53 and ISO/IEC 27001 so reports line up with what auditors expect.
    • I set up the vulnerability-management process end to end and keep the risk register, ranking issues by severity and turning findings into concrete remediation priorities.
    • I automated the repetitive parts of assessment and reporting, so each cycle covers more ground and the documentation stays consistent.
    • SAST / DAST / OAST
    • OWASP API Top 10
    • MITRE ATT&CK
    • NIST SP 800-53
    • ISO/IEC 27001
  2. Independent Engineering & Development

    2025 — May 2026

    Freelance / Consultancy

    • Custom embedded & IoT systems: I design and build devices around Raspberry Pi, ESP32, STM32 and Arduino, taking each from prototype to a working product.
    • Full-stack web development: I build and deploy web platforms with React, Vue and Node.js, covering both the interface and the backend.
    • End-to-end delivery: I carry projects from hardware schematics through to deployed, working software.
  3. R&D Software Developer

    Nov 2022 — Jan 2025

    Continental Automotive Systems

    • I architected and deployed a suite of custom automation tools (Python / VBA) that streamlined the electronic component lifecycle for global R&D teams.
    • I engineered high-precision solutions for SAP data verification and circuit analysis, ensuring validation integrity for safety-critical electronic brake and suspension modules.
    • I facilitated the hardware-to-software transition, translating complex physical requirements into robust utilities that optimised the circuit design workflow.

How I work

Map
See the whole system, end to end.
Model
Think like an attacker — first.
Break
Test safely, with evidence.
Harden
Fix what matters. Prove it holds.

Education

M.Sc. Cybersecurity

2024 — July 2026

English-taught

HonoursGraduated with highest distinction.

ThesisMonitoring and securing IoT communications: attack detection and traffic encryption.

M.Sc. Advanced Mechatronics Systems

2024 — July 2026

HonoursGraduated with highest distinction.

ThesisDesign and implementation of an IIoT mechatronic system for industrial process monitoring and diagnosis.

B.Sc. Mechatronics

2020 — 2024

English-taught

HonoursGraduated with highest distinction.

ThesisAutonomous mobile rover: SLAM implementation.

Erasmus+Scholarship (Electronics), University of South-Eastern Norway (2021–2022).

Selected projects

Autonomous Robot Motion Planning ROS 2
Collision-avoidance and 3D trajectory-generation algorithms for autonomous rovers, with dynamic pathfinding in ROS 2.
AI-Driven Cybersecurity for SCADA Systems IDPS
An intrusion detection & prevention system for critical infrastructure — LSTM / XGBoost models that spot active threats in real time.
Full-Stack Secure IoT Platform ESP32
A secure IoT network with its own intrusion-prevention layer, validated against live attacks, with Grafana dashboards.
AWS Cloud Penetration Testing Cloud
A full kill-chain simulation on AWS — lateral movement and persistence — to test cloud defences.
IoT Behavioral Profiling System Python
Real-time anomaly detection in Python and Pandas that flags suspicious behaviour in device fleets.

Conferences & development

CyberSea Festival 2025
Cybersecurity workshops and CTF competitions; exchanges with industry leaders and DNSC on national cyber defense.
Scientific Communications Session 2024
Presented the research paper “Autonomous Rover Navigation” (SLAM, ROS 2) before an academic panel.
Cybersecurity Industry Meetup CCIB
Networking sessions on emerging cyber threats and corporate defense.