Julio Araujo
Director of Security @ Rocket.Chat
Orléans, France
Actions
Brazilian security professional based in France, Julio Araujo is currently a Director of Security at Rocket.Chat. With over 6 years of experience in the offensive and application security spaces, his challenge revolves around securing an open-source project that is used in critical industries.
Area of Expertise
Topics
After the Breach: Lessons from a Year of Supply Chain Attacks
2026 brought a wave of supply chain attacks that exposed how deeply modern software relies on trust, automation, and third-party code. This session looks back at the year’s most important incidents, the patterns they revealed, and the defensive lessons teams can take forward.
We’ll look at TeamPCP, Shai-Hulud, GitHub’s reported VS Code extension compromise, and other real-world incidents to understand how attackers compromised dependencies, maintainers, and CI/CD pipelines, then turn those lessons into practical strategies for prevention, detection, and response.
Building Layne: Scaling Security Scanning @ Rocket.Chat
Shifting security left is hard to operationalize at scale - especially with a small security team. Every team reinventing its own CI pipeline integration leads to inconsistent coverage and blind spots that slip into production.
Layne is how Rocket.Chat's security team scales appsec without scaling headcount. It's a GitHub App that centralizes Semgrep (SAST), Trufflehog (secret detection), and Claude across repositories - without touching a single workflow file. Every pull request gets scanned in parallel, with results surfacing as native GitHub Check Run annotations that block merges on high-severity findings.
We'll cover the architecture, the lessons learned deploying it at Rocket.Chat, and an honest take on where LLMs genuinely add value in a security pipeline.
https://github.com/RocketChat/layne
From Scratch: Creating AppSec Program And Its Challenges
This presentation will take attendees inside a journey to build a practical, scalable Application Security program supported by open-source technologies and content. Instead of focusing on a single process or tool, we will highlight the broader ecosystem we rely on and how it enables a small security team to manage risks effectively across a large and fast-moving codebase. The session will outline how to integrate security into development workflows, introduce automation that enhances visibility, and promote a security mindset throughout engineering.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top