initializing system...
identity:Andrei Visoiu
alias:k33w3
domain:infrastructure / security / systems

I build secure systems that hold under pressure.

From cybersecurity infrastructure to production platforms, I design and deploy systems built to scale, hold under load, and fail predictably.

Execution over ideas. Systems over shortcuts.
System Architecture // Layers 00–05
L-00

Foundation

core identity / skills

Third-year CS student at Maastricht University focused on applied security and cloud systems.

Certifications & Rankings

  • CNSS
  • eJPT
  • Google IT Support
  • HackTheBox: Top 0.01%
  • TryHackMe: Top 1%

Technical Stack

  • AWS (Lambda, API GW, DynamoDB, CloudFront, S3/SES)
  • Python / Node.js
  • Terraform / CDK
  • AuthN/Z & Threat Modeling
  • CI/CD, SBOM/SCA
  • Structured Logging / IR Notes
L-01

Experience

runtime / operations

System history spanning cloud deployments, offensive security, organizational leadership, and academia.

Teaching Assistant: Computer Security, HPC, Communication & English

Maastricht University · Faculty of Science and Engineering // Jan 2026–Present

Architected and deployed a fully automated AWS-based lab platform for a 6-week cybersecurity course, provisioning isolated, per-student container instances via ECS Fargate for secure independent environments. Designed for zero-touch operation with reliable availability beyond scheduled lab hours. Additionally TA for the High Performance Computing course covering GPU programming (CUDA), CPU parallelism (OpenMP, MPI), and performance profiling.

Founder & President

MaaSec (ACM Student Chapter) // Jan 2025–Present

Founded the first ACM Student Chapter in the Netherlands focused on cybersecurity, infrastructure, and hands-on technical learning. Built from scratch to 60+ members, founded the university's first CTF team, now ranked #2 nationally on CTFtime. Organizing regular meetups for CTFs and hackathons, expanding into technical workshops, research collaborations, and hosting the university's first CTF and ICPC competitions.

Co-Founder & CTO

OneTicket // Oct 2024–Present

Co-founded a digital ticketing platform serving thousands of users across 86+ hosted events. Designed and implemented the entire technical infrastructure: backend architecture, AWS-based deployment, secure email delivery systems, and real-time ticket validation.

Full Stack Engineer & Technical Advisor

NebulaLabs · Internship // Jan 2022–Oct 2022

Developed and maintained backend infrastructure on AWS, implemented security features, and contributed to frontend development. Ensured platform reliability and supported end-to-end product delivery.

L-02

Security

hardening / research

Security-first methodology applied across production workloads, academic research, and client-facing consulting.

Intel CET Indirect Branch Tracking on Linux x86-64

BSc Thesis

Evaluating how Intel CET's IBT component performs in practice. Comparing ENDBR64 instrumentation across GCC and Clang LTO variants, and measuring the attack surface exposed by mixed CET/legacy deployments.

Static + Dynamic Analysis //

ENDBR64 counting, ROP gadget enumeration, and functional classification across libpng, libtiff, and libxml2 (Magma suite). AFL++ fuzzing for reachability validation.

Exploitation //

Attempted CVE exploitation in libpng to demonstrate practical consequences of over-instrumentation and glibc's permissive IBT fallback.

Security Consulting for Startups

Pro Bono

Led 4-person team delivering security consulting to hardware startup. Client implemented all recommendations.

Role & Delivery //

Led team selection, client interviews, and requirements scoping. Coordinated deliverable production and presented final security brief to stakeholders.

Scope //

Security assessment report with architecture recommendations, threat model, infrastructure guidance, and compliance overview.

L-03

Deployments

application / production

Systems designed, built, and shipped to production. Measured by uptime, not aesthetics.

OneTicket

Production
oneticket.one →

Digital ticketing platform serving thousands of users across 86+ hosted events. Designed and implemented the entire technical infrastructure end-to-end.

Stack //

React frontend, AWS serverless backend (API Gateway, Lambda, DynamoDB), CloudFront CDN, S3/SES. Terraform IaC with staging/production isolation. Payment processing, admin panels, real-time scanner (20ms avg).

Security //

Least-privilege IAM, JWT/HMAC rotation, rate limiting, input validation. HMAC webhook verification with replay protection. Structured logging, alerting, automated backup testing.

MaaSec

ACM Chapter
maasec.com →

Founded the first ACM Student Chapter in the Netherlands. 0 to 60+ members, CTF team ranked #2 nationally.

CTF & Infrastructure //

Founded the university's first CTF team, now ranked #2 nationally on CTFtime. Contributed to CSLab infrastructure serving 1,700+ students. Secured €4k faculty budget for activities.

Events & Speakers //

Hosted Microsoft Security and DARPA AIxCC winner (Georgia Tech). UM Student Award 2025 finalist. Guest on Observant Podcast (Ep. 8). Cross-university events with TU Delft, Twente, Radboud, VU Amsterdam.

L-04

Writeups

output / logs

Technical logs, vulnerability research, and security investigation reports.

L-05

Interface

comms / contact

Establish a connection for internships, engineering, or security inquiries.

Open to summer 2026 internships and research opportunities.