João Sousa
@joosousa2
Security-focused engineer specializing in threat detection, incident response, and adversary emulation through automation and reverse engineering.
What I'm looking for
I’m a security-focused Computer Engineering graduate specializing in threat detection, incident response, and adversary emulation. I combine deep-dive binary reverse engineering and malware behavior analysis with proactive threat hunting to optimize enterprise detection rules, verify log correlations, and mitigate high-impact infrastructure vulnerabilities.
In my defensive engineering work, I build automated security telemetry in C and Python, translating attacker behaviors into actionable SIEM use cases. I’ve developed capabilities spanning SIEM use case lifecycle and event correlation, traffic anomaly analysis, and incident investigation, alongside low-level kernel telemetry, memory forensics, and binary exploitation research using Ghidra/GDB and pwntools.
Experience
Work history, roles, and key accomplishments
Malware Forensics Sandbox
Ex-NihilOS
Engineered a custom 64-bit bare-metal kernel to observe low-level system calls and interrupt handling for malware behavior analysis. Performed memory forensics to isolate buffer overflow and memory injection vulnerabilities.
Adversary Emulation & Detection
Offensive-Lab
Developed cross-platform C implants for process-level execution telemetry and remote command execution to generate SIEM alerts. Built C2 traffic anomaly analysis and Python-based automation to emulate multi-vector APT scenarios and test incident response playbooks.
Binary Exploitation & CTF Research
RE-Lab
Dissected 64-bit ELF/PE binaries using Ghidra and GDB, building CFGs to identify malicious control-flow paths and persistence components. Developed automated polymorphic solvers with pwntools to bypass validation logic for mitigation research.
Education
Degrees, certifications, and relevant coursework
Universidade da Madeira
Bachelor of Science, Computer Engineering (Engenharia Informática)
B.Sc. in Computer Engineering (Engenharia Informática) at Universidade da Madeira, completed June 2026. Final-year study included an Erasmus+ deployment at Politehnica of Bucharest.
Politehnica of Bucharest (UPB)
Academic Exchange (Erasmus+), Computer Engineering (Erasmus+ Exchange)
Erasmus+ academic deployment at Politehnica of Bucharest during the final year of the B.Sc. program. Focus areas included network security, distributed systems, and operating systems.
Tokio School
Cybersecurity Specialization, Cybersecurity
Completed a Cybersecurity specialization focused on network defense, vulnerability assessment, and ethical hacking.
TryHackMe
Junior Penetration Tester, Penetration Testing
Achieved TryHackMe certification: Junior Penetration Tester.
TryHackMe
Pre-Security, Cybersecurity Fundamentals
Completed the TryHackMe Pre-Security certification track.
TryHackMe
Cyber Security 101, Cybersecurity Fundamentals
Completed the TryHackMe Cyber Security 101 certification.
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring João?
You can contact João and 90k+ other talented remote workers on Himalayas.
Message JoãoGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
