Skip to content

João Carlos Chavatte

Backend Engineering | AppSec | DevSecOps

Summary

Technology professional with hands-on experience in Application Security (AppSec), DevSecOps, and Backend Engineering. Since 2022, building SecOps tools, APIs, automations, and offensive security research labs, connecting software development, Linux/cloud infrastructure, and security. Experience with Node.js/TypeScript, Python, and Java, Docker, CI/CD, databases, and security automation, with a focus on Shift-Left, supply chain security, and resilient solution design.

Skills

Application Security

  • AppSec
  • OWASP Top 10
  • DevSecOps
  • Shift-Left
  • Hardening
  • Secure Architecture

Offensive Security

  • Red Team
  • Threat Hunting
  • OSINT
  • Security Research
  • DNS Analysis
  • Stress Testing

Backend Engineering

  • Node.js
  • TypeScript
  • Express
  • Java
  • Python
  • FastAPI
  • REST APIs
  • Authentication
  • Authorization
  • Software Architecture

Cloud & Infrastructure

  • Linux
  • Shell
  • Docker
  • CI/CD
  • Git
  • GitHub
  • AWS
  • Azure
  • WSL2
  • ARM
  • Raspberry Pi

Data & Automation

  • PostgreSQL
  • MongoDB
  • SQLite
  • Security Automation
  • AI Automation
  • Observability
  • Risk Analysis

Engineering Practices

  • Scrum
  • Git Flow
  • TDD
  • Clean Code
  • SOLID
  • Design Patterns

Work Experience(1)

Dec 2021 - Current
Security Researcher & Software Developer
Chavatte Security
  • AppSec
  • DevSecOps
  • SecOps
  • Red Team
  • Backend Engineering
  • Node.js
  • TypeScript
  • Python
  • Java
  • Docker
  • Linux
  • Supply Chain Security

Applied research and development across AppSec, DevSecOps, SecOps, backend engineering, and offensive security.

  • Conducted and published a PoC targeting Android/Open DNS Resolvers on a LAN, including DNS tunneling analysis and a 1,500 QPS stress test.

  • Developed Sentinel OPS for GitHub repository scanning, automated vulnerability and exposed-credential detection, and risk governance support.

  • Architected Enoch Engine API, a production-grade Node.js/Express backend boilerplate with Anti-DoS, Token Versioning, Graceful Shutdown, streaming uploads, and Docker-based Multi-Schema orchestration.

  • Designed ParrotOS-WSL-Installer to automate deployment of a WSL2 analysis environment with GUI and XRDP.

  • Managed a private ARM-based lab environment using Raspberry Pi/CasaOS, monitoring, and DNS Sinkholing via Pi-hole.

Projects(6)

Sentinel Forge
  • Electron
  • React
  • Vite
  • Node.js
  • EDR
  • Supply Chain Security
https://github.com/chavatte/sentinel-forge

Tactical EDR & Supply Chain Defense Toolkit.

  • Desktop security toolkit focused on tactical detection, response, and supply-chain defense.

Sentinel Git-OPS
  • Node.js
  • GitOps
  • Security Operations
  • Windows
  • Linux
https://github.com/chavatte/sentinel-git-ops

Git operations platform/CLI with auditing, branch management, and response controls.

  • Operational auditing and branch management for Windows/Linux.

  • Resume reference version: 2.3.0.

Sentinel OPS
  • Node.js
  • SQLite
  • Docker
  • OSV
  • Supply Chain Security
  • SecOps
https://chavatte.vercel.app/projects/sentinel-ops

Node.js dependency and supply-chain security dashboard with risk analysis and governance automation.

  • OSV integration.

  • SQLite engine.

  • Threat Analytics and governance automation.

Enoch Engine API
  • Node.js
  • Express
  • PostgreSQL
  • Docker
  • API Security
https://github.com/chavatte/Enoch-Engine

Production-grade backend boilerplate focused on security, authentication, PostgreSQL, and Docker.

  • Anti-DoS.

  • Token Versioning.

  • Graceful Shutdown.

  • Streaming uploads.

  • Docker-based Multi-Schema orchestration.

Enoch Engine SOC
  • Node.js
  • Threat Intelligence
  • Phishing
  • Safe Browsing
https://chavatte.vercel.app/projects/enoch-soc

Phishing triage and threat intelligence pipeline.

ParrotOS-WSL-Installer
  • WSL2
  • Parrot OS
  • Automation
  • Linux
  • XRDP
https://github.com/chavatte/ParrotOS-WSL-Installer

Automation for deploying a WSL2 analysis environment with GUI and XRDP.

Education(3)

Professional Program Cybersecurity
Hackers do Bem
  • Red Team Residency
  • Red Team Specialization
  • Fundamental Level
  • Basic Level
University Extension Market Share Analysis (Android vs. iOS)
UFSCar
Web Full Stack Degree Full Stack Web Development
Let's Code / Ada

Certificates(17)

CyberOps Associate
Cisco
Network Defense
Cisco
CCNA1: Introduction to Networks
Cisco
Cybersecurity Essentials
Cisco
Endpoint Security
Cisco
Red Team Residency & Specialization
Hackers do Bem / MCTI / SENAI
Fundamental Level
Hackers do Bem / MCTI / SENAI
Basic Level
Hackers do Bem / MCTI / SENAI
Azure AI Fundamentals
Microsoft
AI Agents
Microsoft / Training Programs
Generative AI Fundamentals / Claude 3
Training Programs
Java Cloud Native
Bradesco / DIO
Backend with Java
Santander / DIO
Python AI
Vivo / DIO
Backend APIs
freeCodeCamp
JavaScript
freeCodeCamp
Responsive Web Design
freeCodeCamp

Publications(5)

PoC - Android Open Resolver
in Chavatte Security

Offensive research on DNS exploitation, Open Resolvers, and stress testing; 1,500 QPS stress-test highlight.

Docker Engine AuthZ Bypass: Anatomy of CVE-2026-34040 and Root Escalation
in Chavatte Security

Technical research in container security.

eBPF Rootkits: The Dark Side of Observability in Kubernetes (PoC)
in Chavatte Security

Technical research in cloud security.

Wasm-Jacking: SAST Evasion and Hidden Malware in Node.js Dependencies
in Chavatte Security

Research in supply chain security.

AI PR Reviewer Hijacking: Prompt Injection Directly into the Pipeline (CVE-2026-40112)
in Chavatte Security

Research in AI security.