Summary
Joseph Rocha is a senior security engineer with a decade of hands-on experience in threat hunting, adversary emulation, and offensive tooling for large enterprise and cloud environments. Based in San Antonio, he has built and deployed custom payloads and automation in C++, Python, Go and PowerShell to evade EDR/AV and uncover gaps across tens of thousands of endpoints. At USAA and Amazon he translated red team findings into production detections and scalable hunt capabilities that analyze trillions of artifacts daily. He combines deep Windows internals and malware development expertise with practical incident response and detection engineering. Colleagues rely on him to bridge offensive tradecraft and defensive scale, turning unconventional attack techniques into measurable security improvements. Outside work he’s intensely curious about low-level behavior and threat emulation, which informs innovative detection strategies rather than theoretical research alone.
10 years of coding experience
4 years of employment as a software developer
University of Texas at San Antonio