Security data lakes
Open-format detection at scale: Parquet and an Iceberg-compatible catalog, Sigma evaluated at both stream time and query time, no per-gigabyte licence.
ジュリアン・B・グルニエ · Vancouver, BC — open to roles in Japan, in British Columbia, or remote
Security assumptions have to be tested systematically, or they are just hope.
Twenty years on both sides of the security line: running red-team engagements, and building the detection meant to catch them. Today I lead a global breach-and-attack-simulation and remediation practice, and I build the platforms — security data lakes, validation pipelines, SOC tooling — that make the work measurable rather than anecdotal.
Open-format detection at scale: Parquet and an Iceberg-compatible catalog, Sigma evaluated at both stream time and query time, no per-gigabyte licence.
ATT&CK-aligned control validation, and the remediation lifecycle that turns a red cell into closed risk rather than a slide.
Multi-month engagements, C2 tradecraft, EDR and control bypass — run alongside the defenders so detections improve during the exercise.
Live ransomware, business email compromise, and espionage cases; digital forensics, malware analysis, and fleet-wide evidence collection.
Building with frontier models daily, and running local ones where the data cannot leave. The argument for owning your model, not renting it.
Risk treatment from finding to closure, with posture and coverage reported to senior leadership in terms the business can act on.
Leads the global breach-and-attack-simulation and remediation functions: continuous, threat-informed control assurance, and ownership of the risk-treatment lifecycle through to closure.
24/7 MXDR service operations for enterprise clients; detection platform engineering, threat-intelligence integration, and recurring control-validation testing across EDR, firewall, and application allow-listing.
Scaled a startup-born detection function into a globally aligned MDR service, managing up to 25 people; threat hunting, forensics, and penetration testing across client environments.
Moved into security through a high-stakes insider-threat investigation; monitoring, vulnerability assessment, and internal investigations.
Fibre-optic test instruments on the shop floor, then the systems around them: e-commerce, ERP integration, reporting, and infrastructure.
Five years on the plant floor, including preventive maintenance systems. Where I learned that a control which stops the line is a control nobody keeps.
| Credential | Issuer | Year |
|---|---|---|
| CISSP | ISC2 | 2016 |
| OSCP — Offensive Security Certified Professional | OffSec | 2017 |
| GXPN — Exploit Researcher & Advanced Penetration Tester | GIAC | 2018 |
| GCFA — Certified Forensic Analyst | GIAC | 2021 |
| GCIH — Certified Incident Handler | GIAC | 2016 |
| GCFE — Certified Forensic Examiner | GIAC | 2015 |
| GRID — Response and Industrial Defense | GIAC | 2022 · expired 2026-06, not renewed |
| ATT&CK Adversary Emulation Methodology | MITRE Engenuity | 2022 |
Full list, including the three MITRE Engenuity ATT&CK certifications and credentials currently in progress (CISA, CRISC, HTB Certified Offensive AI Expert), on the About page.
Open to individual-contributor and supervisory roles — relocating to Japan, based in British Columbia, or remote across Canada and the US. For a role in Japan I am eligible for the Spouse of Japanese National status of residence, so no employer sponsorship is required.