Stefanos Flokos
Automotive Cybersecurity Engineer
Automotive Cybersecurity Engineer with a strong technical foundation in software development and system hardening. Specialized in securing embedded automotive architectures through Threat Analysis and Risk Assessment.
My objective is to contribute to the safety and security of connected vehicles by ensuring compliance with industry standards and implementing robust defense mechanisms against emerging automotive cyber threats.
Professional Experience
Automotive Cybersecurity Engineer
Software Competitiveness International- Performed Threat Analysis and Risk Assessment (TARA) per ISO/SAE 21434 across Over-the-Air (OTA) update and Telematics Control Unit (TCU) architectures for connected-vehicle programs, covering embedded Android infotainment and Linux-based ECUs.
- Analyzed and triaged Common Vulnerabilities and Exposures (CVEs) affecting the automotive software stack (Android, Linux kernel), assessing exploitability and defining mitigation strategies.
Compulsory Military Service
Hellenic Armed Forces- Fulfilled mandatory national service obligation.
Junior Software Developer
Business & Bytes Ltd- Developed a Windows application for remote server monitoring with custom rules for system/database checks (.NET Framework, SQLite).
- Created a secure web interface for rule status reporting and business statistics (Postgres, Razor Pages, Docker).
Software Developer Intern
Business & Bytes Ltd- Led the frontend development team for a COVID-19 health monitoring system (European funded project).
Education
University of Piraeus
Department of Informatics
MSc in Cybersecurity and Data Science
Program details
Master Thesis (in progress):
Reliability of ML-DSA Hardware Implementation Under Fault
Injection
National and Kapodistrian University of Athens
Department of Informatics and Telecommunications
BSc in Computer Science
↳ Conforming to ACM “Computer Science” curriculum
Department
Bachelor Thesis:
JSON Web Token vulnerabilities and their Mitigation
Certifications
Technical Background
Systems Programming & Cryptographic Engineering
C, LLVM, Linux
- Cryptographic Engineering: integrating secure libraries and cryptographic operations into embedded firmware on STM32 / Zephyr RTOS, for resource-constrained environments.
- C & Operating Systems: systems programming in C covering process management, IPC (semaphores, shared memory) and a custom heap-file storage engine.
- Cross-Platform Development: portable C/C++ builds and debugging with the LLVM/Clang toolchain across architectures.
- Secure Software Development: applying secure-coding practices and security controls across the software development lifecycle.
Offensive Security & Exploitation
C, Assembly, Python
- Binary & Cryptographic Exploitation (CTF): memory-corruption exploitation (stack overflows, format strings), exploit development against remote C services and cryptographic attacks such as padding oracles.
- Application Vulnerability Assessment: white-box review of a production LMS (OpenEclass) - XSS, SQL injection, CSRF.
- Penetration Testing: network and system-level methodology and tooling, privilege escalation and pivoting.
- Malware Analysis & Digital Forensics: static and dynamic analysis of malicious binaries; disk and memory forensics for incident reconstruction.
FPGA & Hardware Security
VHDL, Vitis HLS, Vivado
- RTL Design: register-transfer-level design in VHDL, through synthesis and on-board validation in Vivado.
- High-Level Synthesis: raising C/C++ to RTL with Vitis HLS.
- Hardware Attacks & Countermeasures: fault-injection (voltage/clock glitching) and side-channel (power/EM) analysis; countermeasures with redundancy, error-detecting codes and masking.
- Reliability Engineering: fault-tolerant design and dependability assessment of embedded and FPGA-based systems.
Infrastructure & Web
Linux, Docker, Nginx, .NET, Angular, React
- Self-Hosted Server: hardened Linux server with iptables network segmentation and Docker service isolation.
- Secured Deployments: containerized hosting behind Nginx for OpenASC (open-source automotive security catalogs) and CodebaseIt (personal tech blog).
- Full-Stack Development: side projects spanning .NET back-ends and Angular / React front-ends.
Skills
Automotive
Programming
Hardware / FPGA
Infra & Web
Spoken
Soft Skills