You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Jean De Bonfils LavernelleJD

Jean De Bonfils Lavernelle

Embedded Systems Security Consultant

€750/day
Bordeaux, FR
3-7 years

Average response time: 1 hour

About Jean

Who am I ?

My name is Jean, I hold a PhD in Embedded Systems Security with three years of industry experience at Thales as an Embedded Systems Security Engineer. My main areas of expertise include virtualization security, software isolation, and related low-level mechanisms in ARM-based embedded systems.

I have a strong experience in security analysis and testing of software architecture in embedded systems. I also have expertise in embedded systems security research with proven experience in finding and reporting security vulnerabilities in hyperisors and comlex SoC firmware (e.g, CVE-2025-48507, CVE-2025-0038).

What can I bring?

I provide services in embedded systems security, including but not limited to:

Security analysis and security design reviews of software architectures in embedded systems.
Threat modeling, security testing and code review of low-level software.
Design of software protection and mitigation in embedded systems.
Security training and awareness sessions for teams and individuals.
Preparation of security guidelines, best practices, and checklists.

Main Skills and Qualifications

- Very strong knowledge of Zynq UltraScale MPSoCs and related security support
- Strong experience in threat modeling, analysis and research on low-level software security in embedded systems.
- Extensive experience in hardware JTAG debugging (Trace32) of hypervisors and firmware in embedded systems.
- Strong experience conducting Proof-of-Concepts of advanced software attacks in ARM embedded systems.
- Strong knowledge of hypervisors and virtualization architectures (e.g., Xen, KVM).
- Strong knowledge of virtualization and security supports in ARM-based systems (e.g., TrustZone, SMMU).
- Good knowledge of ARM, SoC architecture, Linux kernel internals, and HW/SW interactions (e.g., DMA, device tree).
- Practical experience with embedded Linux, bootloaders, device drivers and build systems (e.g., Yocto).

  • French

    Native or bilingual

  • English

    Native or bilingual

  • Chinese

    Basic

Can work on-site
Bordeaux (up to 50km)

Experience

  • Thales
    Embedded Systems Security Engineer
    AVIATION AND AEROSPACE
    October 2022 - December 2025 (3 years and 2 months)
    La Ciotat, France
    - Security research on virtualization and hypervisor security in ARM embedded systems.
    - Conduct Proof-of-Concepts of advanced software attacks in ARM embedded systems.
    - Security analysis and testing of low-level software and firmware in embedded systems.
    - Support and consulting activities to define secure architectures relying on virtualization.
    - Hardware JTAG debugging (Trace32) of hypervisors, and complex SoCs firmware.
    - Led security training sessions and produced technical documentation and presentations.
    Firmware Security Awareness Training Systèmes embarqués Cybersécurité sécurité systèmes embarqués
  • Thales
    Security Engineer Intern
    AVIATION AND AEROSPACE
    March 2022 - October 2022 (7 months)
    La Ciotat, France
    - Security review and pentesting of Jailhouse hypervisor.
    - Hardware JTAG debugging (Trace32) of Jailhouse hypervisor.
    - Study of low-level virtualization and isolation mechanisms on ARM.
    sécurité embarqué test sécuritaire sécurité systèmes embarqués Analyse des menaces
  • Groupe Crédit Agricole (AE)
    Application pentester
    BANKING AND INSURANCE
    June 2021 - August 2021 (2 months)
    Limoges, France
    - Security analysis and pentesting of banking websites using code review and SAST tools.
    - Multiple OWASP Top10 security flaws discovered (e.g., XSS, SSRF, SQL injection).
    - Writing vulnerability reports on identified security flaws, their impact, and mitigations.

Recommendations

Be the first to recommend Jean

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • PhD./Doctorat
    Thales & XLIM
    2025
    Embedded Systems Security
  • Master's degree
    University of Limoges
    2022
    Cryptography & Cybersecurity

Skill set

Categories