Pixel art of Budapest at sunset, the Chain Bridge and Parliament on the Danube
Pixel art portrait of Aron Szabo

Platforms people depend on. Devices people connect.

Fractional CTO and embedded security tester. For the investors who buy connected products and the companies that run them.

For investors Technical due diligence The device, the platform behind it and its compliance posture.
For product companies Modernize and secure I modernize the platform, test the device, and work with your team to harden both.
Book a 30 min call (opens in a new tab) Budapest, Hungary. Remote, US and EU

What I do

IoT and SaaS legacy modernization, embedded security testing, and compliance with the EU Cyber Resilience Act (CRA), RED / EN 18031, IEC 62443 and the EU Machinery Regulation (MR 2023/1230). I build the team, then drive the transformation with them.

IoT & SaaS legacy modernization

Fractional CTO for SaaS platforms with connected devices behind them.

I build the team and the architecture, keep delivery predictable and quality high, and work closely with product, DevOps and the other engineering leads as the platform grows.

Call me when

  • Every release takes longer, and nobody can say why
  • Releases are manual and risky
  • One engineer holds the whole system in their head
  • Your stack is outdated and hard to hire for
  • Investors or a buyer want clear answers about your tech

Track record

  • IoT device management platform
  • Fixed the process, architecture and scaling of a platform that did not scale
  • Donation portal integrating a bank and three mobile carriers
  • Built out secure update systems and delivery pipelines
  • Leading a team on a vehicle cybersecurity SaaS platform for ISO/SAE 21434 compliance testing

Embedded security testing

IoT and hardware penetration testing of the device itself: board, debug ports, buses, radio and boot chain.

Call me when

  • A customer wants a device security test report
  • You are preparing a device for certification
  • A researcher reported a flaw in your device
  • Your device ships and has not been security tested
  • Your device runs in critical infrastructure and regulators are asking

Track record

  • Penetration tests of gateways, telematics units and other embedded devices across automotive, medical and consumer IoT
  • Fault injection by voltage glitching and EMFI
  • Hardware Security Module firmware development

Compliance Cyber Resilience Act (CRA), RED / EN 18031, IEC 62443, MR 2023/1230

The defensive side, as a reviewer and advisor. I run the threat analysis and risk assessment and guide your engineers through the requirements and how to implement them.

Call me when

  • Your team needs a guide through the compliance requirements
  • Your device's security architecture needs to be planned
  • A vulnerability report arrives and nobody owns it
  • Your radio product needs proof of testing
  • You want to maintain compliance with every release

Track record

  • CRA gap analyses and readiness reviews
  • Set up vulnerability handling processes
  • Automated security testing in CI pipelines
  • Built IoT hacking trainings and CTFs, so security teams learn to think like an attacker
  • Security design reviews for connected products

Technical due diligence

For investors in IoT and SaaS companies. An independent look at the technology before you invest or buy, from every angle that affects its value.

You get a written report: what works, the risks, and what fixing them would take.

Call me when

  • You are about to invest in a company that sells connected products
  • You are buying a device maker, or a SaaS platform with devices behind it
  • The pitch says the platform scales and you want to know if it does
  • You want an independent view of the tech before you sign

What I look at

  • Architecture, scalability and technical debt of the platform
  • Code quality, delivery process and release practice
  • Hardware and firmware security of the device
  • Security of the cloud, the apps and the update path
  • Compliance with the regulations its markets require
  • The team: skills, structure and key-person risk
  • What fixing the findings would cost in time and people

Who I help

Companies with a connected product, a device and the platform it reports to, that now has to meet new security rules or the standards its industry requires.

Hardware makers without a security team

Mid-size manufacturers with product lines that are still selling and have not been security tested.

Machinery, agricultural and robotics OEMs

Machines built on CAN, J1939 and ECUs, with telematics.

Medical device makers

Devices that pair with a phone app and send patient data to the cloud.

IoT startups

Device plus cloud, selling into the EU, with a growing fleet and a small team.

About

Engineering leader who builds teams and platforms, and looks at every device with an attacker’s mindset.

The deliverable is not my presence. It is a team and an architecture that no longer need me.

Experience and skills

From web agencies and hosting, through automotive firmware and hardware penetration testing, to SaaS platforms for connected devices.

  1. 2024 - now

    ObscureSignal Fractional CTO

    Builds and leads the engineering team of a cybersecurity SaaS platform for connected vehicles, does security research on robotics, and helps companies with compliance.

  2. 2020 - 2024

    Deloitte Hungary Senior Specialist Lead

    Hardware penetration testing of vehicles and IoT devices. Helped build the automotive security team, and trained security teams.

  3. 2018 - 2020

    thyssenkrupp Team Leader

    Safety-critical automotive firmware. Gateway, HSM, bootloader, RTOS.

  4. 2008 - 2018

    REON Systems, REON Digital Co-Owner & Lead Developer

    Digital agencies and a clustered hosting platform. Built the team that delivered high-load websites, web applications and payment integrations.

Skills

Leadership
Team leadership, architecture, migration strategy, mentoring, hiring
Platforms
SaaS and web platforms, APIs, databases, containers, infrastructure as code, cloud
Embedded
C/C++, microcontrollers, various RTOSes, embedded Linux, various build systems and frameworks, RS485, CAN, FlexRay and other vehicle buses
Security
Embedded security testing, fault injection, secure boot, PKI, EU CRA, RED / EN 18031, IEC 62443
AI-assisted dev
MCP, RAG, code factories with CI quality control

Technologies I've used

Languages
ASM, C, C++, C#, Java, Python, PHP, JavaScript
Web and cloud
Node.js, React, Laravel, Stripe, PostgreSQL, MySQL, Redis, Docker, Kubernetes, Terraform, Jenkins, AWS
Embedded
STM32, Infineon AURIX / TriCore, Microchip PIC, ESP32, Nordic nRF, Raspberry Pi, Toradex, FreeRTOS, Zephyr, Yocto, Buildroot, embedded Linux, lwIP, mbedTLS, OpenCV
Buses and radio
CAN, CAN-FD, FlexRay, UDS, XCP, J1939, AUTOSAR SecOC, UART, SPI, I²C, RS485, Ethernet, BLE, Zigbee, Thread, sub-GHz
Security tools
IDA Pro, Ghidra, radare2, Unicorn Engine, ChipShouter, ChipWhisperer, Vector tools, Metasploit, hashcat, GNU Radio, HackRF
Hardware
KiCad, Altium, Eagle, Fusion 360, FPGA, Lauterbach TRACE32, SEGGER J-Link, measurement instruments, etc.

Public work

YearProjectTypeWhat
2026tcprogToolFlash programmer for Infineon AURIX TC2xx/TC3xx over FTDI debug probes. Reverse-engineered the DAP protocol from captured USB traffic
2025libopencm3Upstream fixFixed clock source selection
2022HacktivityWorkshopCo-presented “Introduction to Automotive CAN Bus Hacking”, 7 October 2022
2021bluemanUpstream fixIncreased the status icon visibility timeout. I made everyone wait more.
2015Linux kernel, OCFS2Bug report, patchFound the broken hard links bug and sent a patch, then tested the reworked fix that was merged
2012lirc_rpiLinux driverAuthor of the Raspberry Pi infrared GPIO driver, vendored into 260+ public source trees
2008Linux kernel, em28xxPatchAdded support for the GrabBeeX+ USB2800 video capture device