M.Sc. · Cybersecurity
Securing industrial IoT at the edge
Where the network meets the machine. The idea works; the details are .
Highest distinction
Application Security Engineer Cyber-Physical Systems
Hello — thanks for stopping by.
I build machines. Then I break them — before anyone else can.
Most engineers pick a side. Hardware or software. Builder or breaker. I never saw the line. I design the system, then attack it until it holds. Because the systems that matter now live where code touches the physical world.
Radu-Cristian Todea
Mechatronics engineer turned application security engineer. Three degrees — each with highest distinction.
Chapter I2020 — 2024
It started with machines that had to find their own way.
Mechatronics taught me to build things that sense, decide and move on their own. My rover began as a sketch and became a machine: the chassis, the electronics, and the software that lets it map a room it has never seen and plan its own way through it. A year of electronics in Norway widened the lens.
Chapter II2022 — 2025
Then came safety-critical — where “almost right” is a failure mode.
In automotive R&D, for a global supplier, I built the automation that engineering teams relied on to keep electronic components right — for brake and suspension systems, where a mistake doesn’t crash a web page. It reaches the road.
Verification is a mindset, not a step.
Chapter III2024 — 2026
Two master’s degrees, in parallel. One question: what happens when machines are attacked?
M.Sc. · Cybersecurity
Where the network meets the machine. The idea works; the details are .
Highest distinction
M.Sc. · Advanced Mechatronics
Teaching machines to notice when something is wrong — before a person has to.
Highest distinction
Both theses met in one machine: a portable lab I designed, wired and built by hand. Around them, an independent engineering practice — custom IoT devices built on Raspberry Pi, ESP32 and Arduino, embedded hardware and full-stack web platforms.
Chapter IV2026 — Now
Now I break software for a living — so it’s already fixed when someone else tries.
As an application security engineer, I audit code and test applications the way an adversary would, model threats before they become incidents — and then make sure the same bug can never quietly come back.
05How I think
Keep scrolling →
01
See the whole system.
From the circuit to the cloud API — code, configuration, containers and the people who run them. You can’t defend what you haven’t traced end to end.
02
Think like them — first.
Every architecture has a story an attacker wants to tell. I write it down before they do.
03
Test until it tells the truth.
Assumptions are hypotheses. I test them methodically and safely — and every verdict comes with its evidence.
04
Fix what matters. Prove it holds.
Findings ranked by real risk, fixed with the team, then tested again. Closed means closed — with proof.
A test that runs once is a snapshot. A test in the pipeline keeps watch. Security isn’t a state — it’s a loop.
Every system becomes a physical system eventually.
Trust is a configuration, not a feeling.
If it hasn’t been tested, it’s a rumour.
An attacker needs one wrong assumption. I go looking for all of them.
A bug fixed once is luck. A bug turned into a rule is progress.
Good security tooling knows when to stay quiet.
Report less. Fix more.
The best security is the kind nobody has to think about.
07Your turn
Most attacks don’t start with code — they start with a link. One of these is where you’d really sign in; the others are traps of the kind that land in real inboxes every day. Pick the real one.
Round 1 of 3
Where would you sign in to LinkedIn?
The habit that beats most of these: read the address from the right, up to the first single “/”. That part is who you’re really talking to.
08What I bring
White-box code audits and grey-box pentests — access control, business logic and the bugs scanners miss. Every finding with its cause, its impact and a fix your developers can actually ship.
Attacker-first architecture reviews and attack chains, risk rated honestly and mapped to recognised frameworks — with a risk register someone actually owns.
Security for systems that touch the physical world — devices, firmware and industrial networks, where a bug can move a motor.
From schematic to deployment: embedded firmware, robotics, automation and web platforms — secure from the first line.
Firewalls and segmentation, container images, infrastructure-as-code and cloud configuration — hardened against recognised benchmarks, least privilege by default.
Every finding becomes a check that runs forever: custom rules and scanners wired into CI, results where developers already look — in code review — and silence when there’s nothing to say.
09Toolbox
The tools rotate — there’s a new one on my bench most weeks. What stays is knowing which kind of tool a problem needs, and when none of them will do.
Offensive testing & analysis
Detection, hardening & response
Security in the pipeline
Hardware, machines & software
10Selected work
Some of it is public. Some of it is need-to-know — ask me about the rest.
A guardian that lives on the factory floor instead of the cloud, and decides — on its own — what to trust. It fits in a case you can carry into a plant. How it does that is .
Machine learning that watches industrial networks for what doesn’t belong — and can explain why it raised the alarm.
A segmented cloud environment built as infrastructure-as-code, then put under a full attack chain to see which walls actually hold.
Every device has habits. This learns them, and flags the moment one starts acting like something else.
Designed and built from scratch — chassis, electronics and software. Mecanum wheels to move in any direction, a LiDAR to see, and the autonomy to map a space it has never been in and find its own way through it.
An industrial IoT system that watches a process, adapts to it, and diagnoses trouble early.
11Credentials
01Network & security operations
02Secure development & identity
03Automation & languages
12Off the clock
Something is always half-soldered.
Weekends lost to CTFs. No regrets.
Teaching models to notice what people miss.
Breaking robots virtually is cheaper.
The best debugging happens away from a screen.
13Questions
Both, honestly. I started with robots and circuit boards and ended up breaking web apps for a living. The problems I like most live right where the two meet.
I look at software the way an attacker would — reading the code, poking at the running app — to find what could go wrong before someone else does. Then I help fix it, and automate the check so it can’t quietly come back.
Systems that touch the real world — cars, factories, robots — and the everyday platforms people trust with their data. Anywhere getting security right actually matters.
Some work belongs to the people I did it for, and some ideas are still mine. The interesting parts are better told over a coffee.
Nobody keeps up with all of it — but I try. A new tool or technique most weeks, CTFs at the weekend, and a certification when it’s worth it. The credentials above are a snapshot, not a finish line.
Look around — it’s a static site with nothing behind it, and it even audits itself: take a look under the hood ↗︎. On a keyboard, hold X to x-ray it. Find something real, tell me, and your name goes in the hall of fame. Just keep it to this site.
Right below — hold the button to decrypt my email — or find me on LinkedIn. I read everything, even if a reply sometimes takes a day.
14Encrypted channel
So do I. My contact details aren’t in this page’s source — they’re encrypted, and only decrypt for a human. Check for yourself ↗︎
Keyboard: press and hold Space or Enter for about a second.
Locked · AES-256-GCM · key rotates every build
Honest footnote: anything a browser can show, a determined person can read. This is friction for harvesters, not secrecy — the same principle I apply to real systems. Raise the cost. Shrink the exposure.
Focus
Application · IoT / OT · Secure engineering
Open to interesting conversations
Local time
--:--:--
Romania · EET
End of transmission
Keep scrolling to reboot the story.
Application Security Engineer · Cyber-Physical Systems · Romania
Application security engineer with a mechatronics background, specialising in autonomous robotics and industrial cybersecurity. I design embedded and cyber-physical systems, then run the penetration testing and threat modeling that make them ready for production.
Ropardo — Software Engineering
Freelance / Consultancy
Continental Automotive Systems
English-taught
HonoursGraduated with highest distinction.
ThesisMonitoring and securing IoT communications: attack detection and traffic encryption.
HonoursGraduated with highest distinction.
ThesisDesign and implementation of an IIoT mechatronic system for industrial process monitoring and diagnosis.
English-taught
HonoursGraduated with highest distinction.
ThesisAutonomous mobile rover: SLAM implementation.
Erasmus+Scholarship (Electronics), University of South-Eastern Norway (2021–2022).