Llorenç Roma

Offensive Security | Penetration Tester | OSCP

📧[email protected] 🔗llori.me
📍Bern, Switzerland
LinkedIn: @llorencroma GitHub: @llorencroma

Summary

Offensive security specialist and penetration tester with 5+ years of experience across network, web, wireless, mobile, IoT/embedded, and OT environments. Combines hands-on penetration testing, vulnerability research, responsible disclosure, and security tool development. Presented drone security research at Black Hat Arsenal, represented Switzerland at NATO CWIX, and holds Swiss Federal Personnel Security Clearance (PSP).

Work

Cyber-Defence Campus, armasuisse
Penetration Tester, IT Security
  • Led end-to-end penetration testing engagements across network, web, wireless, mobile, IoT/embedded, and OT environments, including scoping, execution, reporting, and remediation guidance.

  • Advised technical and non-technical stakeholders on security risks and remediation strategies aligned with NIST CSF and CIS Controls.

  • Managed responsible disclosure and vulnerability coordination with vendors and system developers.

  • Conducted vulnerability research in UAV/drone systems, VoIP, side-channel attacks, and automotive security; developed open-source security tools and proof-of-concepts.

  • Represented Switzerland at NATO CWIX, contributing to the Secure Voice Working Group and national cyber strategy development.

  • Supervised 7+ master’s thesis projects with ETH Zürich, EPFL, and Eurecom on drone security, SCION, and P4 networking.

Certificates

OffSec Certified Professional (OSCP)
OffSec

Projects

Vulnerability Research and Bug Hunting
Responsible disclosure of vulnerabilities across multiple vendors and platforms
  • Discovered and responsibly disclosed vulnerabilities across multiple vendors and platforms — including web applications, mobile apps, and IoT devices

  • Findings include CVEs, GitHub security advisories, and vendor-acknowledged disclosures

  • Acknowledged in Garmin's Hall of Fame; DJI: responsible disclosure, CVE pending (expected Jul 2026)

Drone Security Research
Radio attacks on commercial drones and open-source Remote ID tools
  • Performed radio attacks on commercial drones: signal jamming, GPS spoofing, and drone hijacking

  • Analyzed PII leakage from commercial drone mobile applications

  • Developed open-source Remote ID spoofer and receiver tools; presented at Black Hat Arsenal Europe 2023 and Asia 2026

Side-channel Attacks (TEMPEST)
TEMPEST-based HDMI data exfiltration attacks
  • Conducted TEMPEST-based HDMI data exfiltration attacks, critical in restricted environments

  • Developed an open-source software pipeline for reproducing these attacks, raising awareness of hardware vulnerabilities

Publications

Drone Remote ID spoofer and low cost receiver application v2
Black Hat Arsenal Asia 2026, Singapore
On Building Secure Wide Area Networks over Public Internet Service Providers
CyCon 2024, Estonia
Drone Remote ID spoofer and low cost receiver application
Black Hat Arsenal Europe 2023, London
High Data Throughput Exfiltration through Video Cable Emanations
CRITIS 2022, Munich

Skills

Security Architecture & Risk

Threat modeling, architecture reviews, risk assessment, security advisory

Programming & Scripting

Python, Bash, PowerShell, Go

Tools

Burp Suite, Metasploit, Cobalt Strike, Nmap, Wireshark, BloodHound, Ghidra, Frida

Frameworks

MITRE ATT&CK, NIST CSF, CIS Controls, OWASP Testing Guide, PTES

Education

EURECOM Research Center / University of Turku
Master, Cyber Security, Score: 3.93/4
University of Balearic Islands
Bachelor, Telematics Engineering, Score: 8.08/10

Languages

Spanish: Native or Bilingual Proficiency
Catalan: Native or Bilingual Proficiency
English: Full Professional Proficiency
German: Working Professional Proficiency, Goethe B2
French: Working Professional Proficiency

Awards

Double Master's Degree Scholarship
European University Program

Awarded a fully funded scholarship to a double master's degree program at two European universities.

ICT for Health Summer School Scholarship
European Commission

Awarded 1 out of 40 scholarships in Europe to attend a European ICT for Health Summer School in Castres, France.