Adrian Barreira Romero

AdrianBarreira Romero

Ingénieur en informatiqueComputer engineer

CybersécuritéCybersecuritySystèmes embarquésEmbedded systemsDéveloppementSoftware development

Ouvert aux opportunités en Suisse romandeOpen to opportunities in French-speaking Switzerland

Portrait d'Adrian Barreira Romero
Bachelor
HEIG-VD · 2025
Master
HES-SO · en coursHES-SO · in progress
LanguesLanguages
FR · ES · EN · DE
RégionBased in
Riviera vaudoiseVaud Riviera

Qui je suisWho I am

ProfilProfile

Titulaire d'un Bachelor en informatique orienté cybersécurité (HEIG-VD, 2025), je poursuis à temps partiel un Master en systèmes embarqués à la HES-SO. J'aime comprendre un système jusqu'au bas niveau, pour mieux le construire et le sécuriser.

I hold a Bachelor's in Computer Science with a cybersecurity focus (HEIG-VD, 2025) and I am studying part-time for a Master's in embedded systems at HES-SO. I like to understand a system right down to the lowest level, so I can build it and secure it better.

  • LargeurBreadth

    Du matériel au systèmeFrom hardware to systems

    Firmware C/C++ sous RTOS (Zephyr), programmation bas niveau et concurrente, jusqu'à l'administration Windows et Linux et au cloud Azure.

    C/C++ firmware on an RTOS (Zephyr), low-level and concurrent programming, through to Windows and Linux administration and the Azure cloud.

  • Fil rougeCommon thread

    La sécurité dès la conceptionSecurity by design

    Analyse de risques STRIDE, tests d'intrusion, durcissement et référentiels ISO 27001, NIST et CIS.

    STRIDE risk analysis, penetration testing, hardening and the ISO 27001, NIST and CIS frameworks.

  • AtoutEdge

    Technique et métierTechnology and business

    Une formation commerciale et un stage en controlling avant l'ingénierie : je comprends les besoins métier et je sais les traduire en exigences techniques.

    Commercial training and a controlling internship before engineering: I understand business needs and can turn them into technical requirements.

4 domaines4 domains

CompétencesSkills

SEC

CybersécuritéCybersecurity

Offensive et défensive, de l'analyse de risques à la réponse à incident.Offensive and defensive, from risk analysis to incident response.

OffensifOffensive

  • Tests d'intrusionPenetration testing
  • Nmap
  • Metasploit
  • Burp Suite
  • Nessus
  • OWASP
  • Reverse engineering
  • Revue de codeCode review

Défensif & gouvernanceDefensive & governance

  • Analyse de risques (STRIDE)Risk analysis (STRIDE)
  • Gestion des vulnérabilitésVulnerability management
  • DurcissementHardening
  • IAM & Zero Trust
  • SIEM · EDR/XDR
  • Elastic Stack
  • Réponse à incidentIncident response
  • ISO 27001 · NIST · CIS
  • CryptographieCryptography
EMB

Systèmes embarquésEmbedded systems

Du registre au temps réel, sur microcontrôleur et FPGA.From registers to real time, on microcontrollers and FPGAs.

  • C / C++
  • Zephyr RTOS
  • RP2040
  • FPGA (Artix-7)
  • Linux embarquéEmbedded Linux
  • AssembleurAssembly
  • Programmation concurrenteConcurrent programming
  • Programmation systèmeSystems programming
  • Tests sur cible (gcov)On-target testing (gcov)
  • Intégration hardware/softwareHardware/software integration
  • Systèmes logiquesDigital logic
DEV

Développement logicielSoftware development

Du script au web, avec les pratiques du génie logiciel.From scripts to the web, with sound engineering practice.

  • Python
  • C#
  • PHP
  • JavaScript
  • HTML / CSS
  • Bash
  • SQL
  • Git
  • CI/CD · GitHub Actions
  • TestsTesting
  • POOOOP
  • Agile · SDLC
  • Android
SYS

Systèmes & infrastructureSystems & infrastructure

Administration, identités, réseau et cloud.Administration, identity, networking and cloud.

  • Windows Server
  • Active Directory · LDAP
  • Linux
  • Azure
  • Entra ID · Intune · Defender
  • Microsoft 365
  • Docker
  • VirtualisationVirtualisation
  • Réseaux TCP/IPTCP/IP networking
  • VPN
  • Support ITILITIL support

2018 → 2025

ExpérienceExperience

  1. 02.2025 – 10.2025

    Analyse cybersécuritéCybersecurity analysis

    Optamed · Fribourg

    Analyse de risques (STRIDE) d'un système d'échange de données confidentielles entre quatre acteurs (Optamed, Infomaniak, thérapeutes, patients), dimensionné pour des centaines à plusieurs milliers d'utilisateurs. Modélisation des menaces, cartographie de l'architecture réseau, recommandations de chiffrement et de stockage, documentation technique.

    STRIDE risk analysis of a confidential data exchange system linking four parties (Optamed, Infomaniak, therapists, patients), sized for hundreds to several thousand users. Threat modelling, network architecture mapping, recommendations on encryption and storage, and technical documentation.

    • STRIDE
    • Modélisation des menacesThreat modelling
    • ChiffrementEncryption
    • Documentation
  2. 12.2024 – 01.2025

    PentesterPenetration tester

    ASRIMM · Yverdon-les-Bains (Y-Parc)

    Campagne de test d'intrusion : identification et évaluation des vulnérabilités d'un système, puis rapport des résultats.

    Penetration testing campaign: identifying and assessing a system's vulnerabilities, then reporting the findings.

    • Nessus
    • Nmap
    • Metasploit
    • RapportReporting
  3. 08.2019 – 06.2021

    Informaticien d'entrepriseIT technician

    ETML · Lausanne · école de métiersETML · Lausanne · vocational school

    Formation professionnelle complète à plein temps : administration Windows et Linux, Active Directory et LDAP, réseaux, développement (C#, PHP, JavaScript, Bash), bases de données et support selon ITIL. Travail pratique individuel (TPI) en fin de formation.

    Full-time vocational training: Windows and Linux administration, Active Directory and LDAP, networking, software development (C#, PHP, JavaScript, Bash), databases and ITIL-based support. Individual practical project (TPI) to complete the diploma.

    • Windows · Linux
    • Active Directory
    • RéseauxNetworking
    • ITIL
  4. 09.2018 – 08.2019

    Stage en contrôle de gestionFinancial controlling intern

    CSD Ingénieurs · Givisiez

    Stage au département controlling : contrôle de gestion financière et compréhension des besoins métier.

    Internship in the controlling department: financial controlling and a solid grasp of business needs.

2015 → aujourd'hui2015 → today

FormationEducation

  1. 2026 – en courspresent

    Master of Science in Engineering (MSE)

    HES-SO · Lausanne · systèmes embarqués · temps partielHES-SO · Lausanne · embedded systems · part-time

    Au programme : FPGA (Artix-7), temps réel et protocoles d'héritage de priorité sous Zephyr, tests embarqués sur cible, reverse engineering, calcul haute performance, deep learning.

    Coursework includes: FPGA (Artix-7), real time and priority inheritance protocols on Zephyr, on-target embedded testing, reverse engineering, high-performance computing, deep learning.

  2. 2021 – 2025

    Bachelor of Computer Science

    HEIG-VD · Yverdon-les-Bains · orientation sécurité informatique · 180 ECTSHEIG-VD · Yverdon-les-Bains · information security track · 180 ECTS

    Modules clés : sécurité des réseaux, sécurité logicielle haut et bas niveau, cryptographie, sécurité des systèmes d'exploitation, programmation concurrente, cloud computing, gouvernance des données.

    Key modules: network security, high- and low-level software security, cryptography, operating system security, concurrent programming, cloud computing, data governance.

  3. 2019 – 2021

    CFC d'informaticienFederal VET Diploma in IT (CFC)

    ETML · Lausanne

  4. 2015 – 2019

    CFC d'employé de commerce et maturité professionnelleFederal VET Diploma & Vocational Baccalaureate in Business

    Gymnase de Burier · La Tour-de-Peilz

Échelle CECRCEFR scale

LanguesLanguages

  • FrançaisFrench
    Langue maternelleNative
  • EspagnolSpanish
    Langue maternelleNative
  • AnglaisEnglish
    C1
  • AllemandGerman
    B2

Clarens · VD

Contact

Un poste en cybersécurité, en systèmes embarqués ou en développement ? Je serai ravi d'en discuter.

Have a role in cybersecurity, embedded systems or software development? I would be glad to talk.