Security engineering & research

Julien B. Grenier

ジュリアン・B・グルニエ · Vancouver, BC — open to roles in Japan, in British Columbia, or remote

Security assumptions have to be tested systematically, or they are just hope.

Twenty years on both sides of the security line: running red-team engagements, and building the detection meant to catch them. Today I lead a global breach-and-attack-simulation and remediation practice, and I build the platforms — security data lakes, validation pipelines, SOC tooling — that make the work measurable rather than anecdotal.

What I work on

In detail

Security data lakes

Open-format detection at scale: Parquet and an Iceberg-compatible catalog, Sigma evaluated at both stream time and query time, no per-gigabyte licence.

BAS, CTEM & exposure validation

ATT&CK-aligned control validation, and the remediation lifecycle that turns a red cell into closed risk rather than a slide.

Red & purple teaming

Multi-month engagements, C2 tradecraft, EDR and control bypass — run alongside the defenders so detections improve during the exercise.

Incident response & forensics

Live ransomware, business email compromise, and espionage cases; digital forensics, malware analysis, and fleet-wide evidence collection.

AI-native engineering

Building with frontier models daily, and running local ones where the data cannot leave. The argument for owning your model, not renting it.

Governance, risk & compliance

Risk treatment from finding to closure, with posture and coverage reported to senior leadership in terms the business can act on.

Selected experience

2001 – present
  • 2026 –
    Manager, Governance / IT Risk & Compliance
    Big Four professional services firm

    Leads the global breach-and-attack-simulation and remediation functions: continuous, threat-informed control assurance, and ownership of the risk-treatment lifecycle through to closure.

  • 2023 – 2026
    Manager, Managed Extended Detection & Response
    Big Four professional services firm

    24/7 MXDR service operations for enterprise clients; detection platform engineering, threat-intelligence integration, and recurring control-validation testing across EDR, firewall, and application allow-listing.

  • 2018 – 2022
    Senior Consultant → Manager, MDR & Offensive Security
    A second Big Four firm — joined through the acquisition of a Canadian security startup

    Scaled a startup-born detection function into a globally aligned MDR service, managing up to 25 people; threat hunting, forensics, and penetration testing across client environments.

  • 2013 – 2018
    IT Security Analyst
    Telecom instrumentation manufacturer

    Moved into security through a high-stakes insider-threat investigation; monitoring, vulnerability assessment, and internal investigations.

  • 2007 – 2018
    Metrology technician → QC manager → web & ERP developer
    Telecom instrumentation manufacturer

    Fibre-optic test instruments on the shop floor, then the systems around them: e-commerce, ERP integration, reporting, and infrastructure.

  • 2001 – 2006
    Manufacturing IT — summer, part-time, intern, then contract
    IBM

    Five years on the plant floor, including preventive maintenance systems. Where I learned that a control which stops the line is a control nobody keeps.

Full career history

Credentials

Certifications
CredentialIssuerYear
CISSPISC22016
OSCP — Offensive Security Certified ProfessionalOffSec2017
GXPN — Exploit Researcher & Advanced Penetration TesterGIAC2018
GCFA — Certified Forensic AnalystGIAC2021
GCIH — Certified Incident HandlerGIAC2016
GCFE — Certified Forensic ExaminerGIAC2015
GRID — Response and Industrial DefenseGIAC2022 · expired 2026-06, not renewed
ATT&CK Adversary Emulation MethodologyMITRE Engenuity2022

Full list, including the three MITRE Engenuity ATT&CK certifications and credentials currently in progress (CISA, CRISC, HTB Certified Offensive AI Expert), on the About page.

Platforms I have built

All research
  • JUNILAKE Security data lake Sigma detection at stream time and query time over Parquet on object storage, with a DuckLake / Iceberg-compatible catalog — one Docker Compose project on a single machine. Detail
  • JUNIBAS CTEM / BAS / AEV A program spine for offensive-security work: engagement → finding → remediation → re-test, with four BAS platform integrations behind one vendor-agnostic adapter. Detail
  • JUNISOC SOC case management Alert triage, incident workflow, customer advisories and portal, threat hunts, and ATT&CK coverage — server-rendered, deployable in one script. Detail
  • JUNIFLEET Endpoint visibility A private internal fork of Fleet (osquery) adding forensic carving, MFA, a vulnerability dashboard, and self-authored CIS policies. Detail

Contact

Open to individual-contributor and supervisory roles — relocating to Japan, based in British Columbia, or remote across Canada and the US. For a role in Japan I am eligible for the Spouse of Japanese National status of residence, so no employer sponsorship is required.