# Sofia Reis > Software security researcher and consultant specializing in software supply-chain security, CRA technical gap analysis, SAST, vulnerability detection & management, and secure code generation. PhD in Computer Science from Instituto Superior Técnico, University of Lisbon. Industry experience at AWS and Meta. Maintainer of security-commits.org. ## About Sofia Reis is a researcher and software engineer working at the intersection of software security, artificial intelligence, and static analysis. She holds a PhD in Computer Science from Instituto Superior Técnico (University of Lisbon), supervised by Rui Abreu. She has industry experience at Amazon Web Services (AWS) and Meta. She is the creator and maintainer of [security-commits.org](https://security-commits.org), a curated dataset of security-related commits that received the FOSS Impact Paper Award at MSR'22 and was mentioned at BlackHat'22 and GitHub Universe'22. As an Invited Assistant Professor at FEUP (Faculty of Engineering, University of Porto), she restructured the Secure Software Engineering graduate course. She also founded CODERS School, a coding school for kids, teens, and adults. ## Research Interests - Software Security - Static Application Security Testing (SAST) - Vulnerability Detection and Management - Secure Code Generation - AI for Software Engineering - Mining Software Repositories ## Selected Publications - [ICST'26] "Do Language Models Prefer Vulnerable Code? A Probabilistic Study of Insecure Code Preference" — Rui Melo, Sofia Reis, Andre Catarino, Rui Abreu (to appear) - [EMSE'25] "An Empirical Study of Large Language Models for Type and Call Graph Analysis" — Ashwin Venkatesh, Rose Sunil, Samkutty Sabu, Amir Mir, Sofia Reis, Eric Bodden (https://doi.org/10.1007/s10664-025-10704-3) - [MSR'25] "Towards Security Commit Message Standardization" — Sofia Reis, Rui Abreu, Corina Pasareanu - [ASE'22] "Leveraging Practitioners' Feedback to Improve a Security Linter" — Sofia Reis, Rui Abreu, Marcelo d'Amorim, Daniel Fortunato (https://doi.org/10.1145/3551349.3560419) - [MSR'22] "SECOM: Towards a convention for security commit messages" — Sofia Reis, Rui Abreu, Hakan Erdogmus, Corina Pasareanu — FOSS Award Winner (https://doi.org/10.1145/3524842.3528513) - [EMSE'21] "Fixing Vulnerabilities Potentially Hinders Maintainability" — Sofia Reis, Rui Abreu, Luis Cruz (https://doi.org/10.1007/s10664-021-10019-z) - [IJCAI'19] "Demystifying the Combination of Dynamic Slicing and Spectrum-based Fault Localization" — Sofia Reis, Rui Abreu, Marcelo D'Amorim (https://doi.org/10.24963/ijcai.2019/661) ## Consulting Sofia offers technical advisory, training, and implementation engagements in software supply-chain security and product security for EU software companies. Advisory is always the starting point — every engagement ends with a written, prioritised action plan that clearly names what Sofia can implement, what the client's team can handle, and what requires a different specialist. ### Advisory engagements - **Software Supply-Chain Security Assessment** — 5–7 weeks. Dependency/SBOM maturity, vulnerability management, build pipeline and release integrity, CVE response and coordinated disclosure, supply-chain threat modelling. - **Secure SDLC Assessment** — 6–8 weeks. Phase-by-phase review of the software development lifecycle (requirements, design, implementation, testing, deployment, maintenance) against secure-by-design principles, plus cross-cutting practices (developer training, security metrics and governance, post-incident feedback loop). Deliverable: maturity scoring per phase and prioritised action plan. - **CRA Technical Gap Analysis** — 6–8 weeks. Structured technical gap analysis against the essential requirements of the EU Cyber Resilience Act ([Regulation 2024/2847](https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng)). Covers product classification and conformity assessment route scoping, product cybersecurity risk assessment, vulnerability handling and coordinated disclosure, supply-chain component due diligence, SBOM, support period and security updates policy, security-by-design, technical documentation and evidence-trail, and incident reporting readiness. A technical lens only: does not interpret the law, does not perform conformity assessment, does not certify readiness. - **Product Security Review (AppSec)** — 5–7 weeks. Architecture/threat modelling, SAST/SCA/secrets tooling review, authN/authZ/secrets review, API security (OWASP API Top 10), cryptography and data protection, security telemetry and incident-response readiness. - **AI-Generated Code Risk Assessment** — 3–5 weeks. Measurement-first assessment of security risk introduced by AI-assisted development. Covers attribution and policy, code-level measurement (SAST finding rate in AI-assisted vs baseline code, known LLM failure patterns), dependency hygiene (slopsquatting, hallucinated packages), and process guardrails. ### Training - **Secure-Coding Workshop** — 1-day or 2-day. Hands-on training with real CVE case studies from open-source projects teams depend on. Covers secure-coding patterns by language, finding vulnerabilities (SAST tooling: Semgrep, CodeQL, manual review), safe patching, security commit messages and coordinated disclosure. Language-specific tracks: Java, Python, JavaScript/TypeScript, Go. Onsite (EU) or remote. - **AI-Assisted Coding Security Workshop** — 2-day. For teams shipping with Copilot, Cursor, or Claude Code. Covers LLM-specific failure patterns, dependency risks (slopsquatting, hallucinated packages), prompt injection in coding agents, review gates and AI-use policies, and hands-on review of AI-generated code. Onsite (EU) or remote. ### Implementation engagements - **Security Engineering Sprint** — 2–4 weeks. Ship a focused security tool with small scope, production code, and clean handover. Includes discovery and scoping, weekly demos, work-for-hire code, and a repository with tests, CI configuration, deploy scripts, operational documentation, and handover session. Examples: SBOM diff alerts, dependency monitoring dashboards, AI attribution tooling, LLM-powered code review assistants, custom Semgrep rules, authZ test harnesses, VHP automation, conformity evidence pipelines. - **Security Engineering Project** — 6–10 weeks. Production-grade security system with engineering embedded from discovery through handover. Includes discovery and architecture sign-off, iterative build with weekly demos, tests, CI/CD, observability, technical documentation, operational playbook, and 30-day post-launch support. Examples: end-to-end vulnerability handling systems, agentic triage workflows with human-in-the-loop, SAST/SCA orchestration platforms with dedup and routing, secure-by-default service templates. - **Embedded Build** — 1–2 days/week, 3 months minimum. Embedded presence (architecture reviews, code review, pairing, technical mentoring) alongside the client's team. Written scope, monthly milestones, and agreed exit criteria. Best for scaleups with an engineering team ready to embed security engineering into. ### Key CRA Deadlines - **September 2026**: Mandatory vulnerability reporting to ENISA within 24 hours - **December 2027**: Full application — CE marking, SBOM, conformity assessment - Non-compliance fines: up to €15M or 2.5% of global turnover ### Why Sofia - PhD researcher specializing in exactly the domains CRA regulates (SAST, vulnerability detection, secure development) - Industry experience at AWS and Meta - Invited Assistant Professor at FEUP, teaching Secure Software Engineering - Author of SECOM, SECOMlint, and security-commits.org Contact: soreis@fe.up.pt | https://sofiaoreis.com/en/consulting ## Links - Website: https://sofiaoreis.com - GitHub: https://github.com/sofiaoreis - LinkedIn: https://www.linkedin.com/in/sofiaoreis/ - Google Scholar: https://scholar.google.com/citations?user=jP79vaIAAAAJ&hl=en - SECOM: https://security-commits.org - CODERS School: https://coders-school.pt