Skip to content

Available for engagements - Brașov, Romania

Petre Radu
Cătălin
- Senior Penetration Tester & Offensive Security Professional

Senior Penetration Tester @ NTT DATA

Offensive Security · Red Team · Cloud & AI Security

I'm Petre Radu Cătălin, a Senior Penetration Tester with 4+ years of offensive security experience spanning enterprise, B2B2C, and B2C environments. I break Active Directory forests, cloud estates, and complex web applications - then deliver the remediation plan that closes the gap.

  • OSCP-Level PT Experience
  • HackTheBox Holo Tier
  • OpenAI Cyber Practitioner
Petre Radu Cătălin - Penetration Tester based in Brașov, Romania
● ONLINEsituated: BRASOV, RO

// whoami

About Petre Radu Cătălin

Senior offensive security professional with 4+ years in penetration testing · Penetration Tester at NTT DATA · Based in Brașov, Romania. Known as Petre Radu to clients, peers, and the security community.

Petre Radu Cătălin - About, penetration tester in Brașov, Romania

Who I am

I'm Petre Radu Cătălin - often simply known as Petre Radu - a senior offensive security professional with 4+ years of penetration testing experience across enterprise, B2B2C, and B2C environments. I currently work as a Penetration Tester at NTT DATA, based in Brașov, Romania. Every day I probe enterprise networks, web applications, and cloud infrastructure for the flaws that attackers are paid to find, and I translate them into risk owners can understand and engineers can fix.

My philosophy

My approach to security is simple: real risk over noise. Anyone can produce a spreadsheet of low-severity findings. My work focuses on what actually matters - the vulnerabilities that persist, the paths that lead to domain compromise, and the remediation guidance that a security team can act on the same day. Every report I ship includes a clear, prioritized, and technically accurate plan to get from 'vulnerable' to 'defended'.

The journey

Before NTT DATA, I spent two years as a freelance penetration tester delivering B2B2C assessments through agency partnerships and B2C engagements directly to businesses - covering web applications, APIs, Active Directory estates, and cloud environments. That freelance foundation carried me into enterprise testing at NTT DATA, where I now lead assessments against production systems at scale. The Master's programme in Cyber Security at Universitatea Transilvania din Brașov (2024-2026) complemented this hands-on work with advanced cyber defense, red and blue team operations, and security auditing theory.

Beyond the enterprise

Between full-time engagements, I work as a Bug Bounty Hunter on Intigriti and as a Vulnerability Researcher on HackerOne, hunting for flaws in production systems through responsible disclosure. This freelance work keeps me sharp: real bug bounty programs are a constant grind of edge cases, business logic abuse, and access control failures that no lab environment can reproduce.

Beyond testing

My scope extends past traditional pentesting into AI security evaluations - testing LLM applications for prompt injection, data exfiltration, and excessive agency - and into the regulatory world through GDPR assessments and NIS2 implementation support. Security is a moving target, so I treat continuous learning as part of the job: new platforms, new tools, new attack classes, every single week.

100+
Certifications
98+
Skills
4+
Years Experience
1000+
LinkedIn Followers

// capabilities

Expertise

Four interlocking disciplines. My offensive work is grounded in an understanding of defense - every assessment I run, from web penetration testing to cloud security review, is built to produce actionable defense.

Offensive Security

Hands-on exploitation across the full attack surface - from web apps to the domain.

  • Web & API penetration testing (OWASP Top 10)
  • Active Directory exploitation & privilege escalation
  • Network security audits
  • Red Team emulation aligned to MITRE ATT&CK
  • Automated recon & exploit development (Python, Bash)

Cloud & AI Security

Breaking and hardening modern, ephemeral attack surfaces before attackers do.

  • Multi-cloud assessments (AWS, Azure, GCP)
  • IAM & identity misconfiguration exploitation
  • AI/ML security evaluations
  • Cloud incident response

Compliance & Governance

Turning regulatory requirements into measurable, defensible security posture.

  • GDPR assessments & data protection reviews
  • NIS2 implementation support
  • Security policy review
  • Technical risk assessment

Defensive Foundation

Knowing the defender's playbook sharpens every offensive engagement.

  • SIEM / SOAR engineering (Splunk)
  • Threat hunting & detection engineering
  • Secure code review
  • Purple-team collaboration

// history

Experience

Enterprise penetration testing, bug bounty hunting, and a Master's in Cyber Security - a career built on finding real vulnerabilities and fixing them for good.

  1. I

    Intigriti

    Freelance

    Bug Bounty Hunter

    May 2026 - PresentRemote

    • Discovered 14 high-impact vulnerabilities across production SaaS platforms - including 3 critical IDOR chains leading to cross-tenant data exposure.
    • Triaged findings by real-world exploitability rather than CVSS score, prioritizing business-logic flaws and privilege escalation paths that scanners miss.
    • Coordinated disclosure with vendor security teams across 8 programs, achieving 100% confirmation rate on reported criticals.
    • Mapped attack surfaces across authentication, authorization, and API layers using Burp Suite Pro, ffuf, and custom fuzzing wordlists.
  2. ND

    NTT DATA, Inc.

    Enterprise

    Senior Penetration Tester

    Nov 2025 - PresentRomania · Remote

    • Led 12 enterprise penetration tests across production web applications, APIs, and Active Directory estates - identifying 47 critical and high-severity findings including RCE, SQLi, and broken access control.
    • Architected full-chain attack simulations from unauthenticated foothold to domain compromise, mapping every technique to MITRE ATT&CK and delivering remediation playbooks to SOC teams.
    • Designed cross-cloud lateral movement paths chaining AWS IAM misconfigs with on-premise AD exploitation - reducing client attack surface by 60% within 90 days of remediation.
    • Built Python and Bash automation toolkit that cut assessment turnaround by 30% - automated subdomain enumeration, credential harvesting, and report generation across concurrent engagements.
  3. H

    HackerOne

    Freelance

    Vulnerability Researcher

    May 2025 - Sep 2025Remote

    • Discovered and disclosed 9 vulnerabilities across production applications - XSS, IDOR, CSRF, and access control flaws - triaged by impact over severity-score theater.
    • Chained low-severity findings into high-impact attack paths, escalating 4 reports from informational to critical after demonstrating real-world exploitability.
    • Partnered with vendor security teams to validate remediation within SLA, building a 100% disclosure compliance record across all submitted reports.
  4. S

    Self-Employed

    Freelance

    Penetration Tester (B2B2C)

    Jun 2024 - Oct 2025Romania · Remote

    • Delivered 18 penetration tests for enterprise clients through tier-one security consultancy partnerships - full-stack assessments covering web applications, APIs, and network infrastructure.
    • Performed cloud security assessments on AWS and Azure environments, identifying IAM privilege escalation paths, exposed S3 buckets, and over-permissive role assumptions.
    • Led Active Directory security audits for mid-market and enterprise clients, mapping attack chains from initial foothold to domain admin using BloodHound, Impacket, and Kerberos exploitation.
    • Produced executive-ready reports with prioritized remediation guidance, driving an 85% repeat business rate across 6 agency partnerships.
  5. S

    Self-Employed

    Freelance

    Penetration Tester (B2C)

    Nov 2023 - May 2024Remote

    • Delivered 12 penetration tests directly to businesses - web application security assessments, API testing, and infrastructure reviews across fintech, e-commerce, and SaaS verticals.
    • Identified business-logic flaws and access-control vulnerabilities that automated scanners miss - including 3 critical broken access control issues leading to privilege escalation.
    • Established responsible disclosure workflows with 9 vendors, achieving 100% remediation confirmation on reported findings and building a track record of trusted partnerships.
  6. Universitatea Transilvania din Brașov

    Master's, Cyber Security

    2024 - 2026

    • Completed advanced offensive curriculum: red team operations, network exploitation, security auditing, and adversarial simulation under Dr. ing. Radu-Emil Precup.
    • Achieved team rank 6 out of 20,220 teams in TryHackMe Industrial Intrusion CTF - top 0.03% field placement.
    • Selected for Google.org Cybersecurity Seminars (Mar 2025 - Jul 2025) - competitive programme focused on applied defensive thinking and threat analysis.

// featured_work

Projects

Selected projects from research, development, and real engagements - static malware analysis, forensic tooling, and the automation that powers my assessments.

MalwarePeek - PE File Analyzer for Static Malware Analysis project by Petre Radu Cătălin

MalwarePeek

PE File Analyzer for Static Malware Analysis

MalwarePeek is a Python-based portable executable analyzer built for malware analysts and reverse engineers. It parses PE headers, fingerprints packers, and scans samples against YARA rules - then generates clean HTML reports for triage.

Python
Malware Analysis
Reverse Engineering
Signature Stealer - Educational PoC - Authenticode Signature Extraction project by Petre Radu Cătălin

Signature Stealer

Educational PoC - Authenticode Signature Extraction

A focused educational proof-of-concept that inspects authenticated code-signing metadata inside signed PE files. It demonstrates how signature blocks remain queryable and how tooling can surface embedded certificate chains for forensic review.

Python
Digital Forensics
Reverse Engineering
Custom Pentest Automation Toolkit - Recon & Vulnerability-Scanning Automation project by Petre Radu CătălinPrivate

Custom Pentest Automation Toolkit

Recon & Vulnerability-Scanning Automation

An internal toolkit of Python and Bash scripts that automate reconnaissance, endpoint enumeration and vulnerability scanning. Used to deliver faster, repeatable assessments and cut end-to-end testing time by roughly 30% at NTT DATA.

Python
Bash
Automation
Offensive Security
Private repoCase study

// credentials

Certifications & Achievements

100+ certifications earned across security, cloud, and AI disciplines - backed by 4+ years of real-world penetration testing and Red Team experience.

100+ Certifications Earned

Curated highlights below - full list available on request.

eLearnSecurity Certified Penetration Tester (eCPPT)

INE / eLearnSecurity

OpenAI Cyber Practitioner

OpenAI · PartnerU

Microsoft AI Skills Fest 2026

Microsoft

AZ-700: Azure Networking Solutions

Microsoft Certified

Teaching the AI Fluency Framework

Anthropic

Puppet Environment Lab

Skillsoft

Google.org Cybersecurity Seminars

Google.org

CTF Achievements

Offensive security is a competitive sport. These results are how I train between engagements.

  • HackTheBox Season 9

    Holo Tier

  • TryHackMe Industrial Intrusion CTF

    Team Rank 6 / 20,220

  • TryHackMe Honeynet Collapse CTF

    Solo Rank 66 / 960

// arsenal

Tools Arsenal

The tools I reach for daily - offensive platforms, cloud CLIs, and the defensive stack I know well enough to test around.

tools.sh

Cobalt Strike

Sliver

Nighthawk

BloodHound CE

SharpHound

Rubeus

KrbRelayUp

NetExec

Impacket

Responder

Evil-WinRM

Ligolo-ng

Burp Suite Pro

Nuclei

ffuf

Pacu

AzureHound

GCPwn

Prowler

Garak

$ echo "recon --enumerate --exploit --report" | sudo tee /dev/arsenal

// write_ups

Insights from Petre Radu Cătălin

Technical write-ups on offensive security, cloud threats, and AI security - the lessons from real engagements, published to help the community.

9 min read

From Web App to Domain Admin: A Red Team Playbook

A practical, phase-by-phase breakdown of how a single web application flaw can be chained into full Active Directory compromise - and the detection gaps that let it happen.

Penetration Testing
Red Team
Active Directory
Read More

// connect

Work with Petre Radu Cătălin

Available for remote and on-site engagements. Based in Brașov, Romania.

Requests open the email client - no data is stored on this site.