About

Julien B. Grenier

ジュリアン・B・グルニエ · Security engineering & research

For twenty years I have worked both sides of the security line: running red-team engagements, and building the detection meant to catch them. The conviction that stuck is simple — security assumptions have to be tested systematically, or they are just hope.

On defence, I have been part of the teams that stood up managed detection and response services from nothing, and I have led high-severity incident response through ransomware, business email compromise, and espionage, backed by digital forensics, threat hunting, and detection engineering. On offence, multi-month red-team engagements with C2 frameworks, EDR and control bypass, and MITRE ATT&CK coverage assessments that pinpoint the gaps. Purple team is where the two meet, and it is the work I care about most.

Today I lead a global breach-and-attack-simulation and remediation practice: continuous, ATT&CK-aligned control validation that turns assumptions into evidence and findings into closed risk, maturing toward CTEM. I work across SOC and MDR, identity, threat intelligence, incident response, security architecture, and enterprise risk — and I build the teams that do it.

That experience is split between in-house roles and client-facing consulting at two Big Four firms, so I am equally comfortable owning a capability from the inside and being accountable to an external client for it.

What building it twice taught me

The lesson

I helped build a Canadian detection-and-response startup from the ground up. It was acquired by a Big Four professional services firm, and I moved across with it — then spent the following years turning what had been a nimble startup function into a globally aligned MDR service, managing up to 25 people through that transition. The acquisition was the right outcome, and I contributed to the part of it that made the company worth acquiring: a working service with real customers behind it.

The more useful half of the story is what happened next. A comparable team later set out to build an improved variation of the same idea inside an even larger organisation, and it was materially harder. The technology was largely off-the-shelf both times — that was never the differentiator. What actually carried the first effort was the operating model, the people who remembered why each decision had been made, and the customer relationship that funded the learning.

The platform is the easy part. The judgement about which decisions matter, and the accountability for them, is what does not transfer in a slide deck.

That is the single most useful thing I know about building security capability, and it is why I evaluate a plan by what it will still be doing in year three rather than by what it demonstrates in the first quarter.

Why I build my own platforms

Conviction

I build tooling with AI every day, and the practice keeps returning me to one point: when a model can write the code, the value was never the code. What lasts is judgement — knowing which decisions matter — and accountability, because a machine cannot take responsibility. Someone still has to vet the work and sign it.

The conclusion I draw from that is not that AI matters less. It is that the durable form of AI in enterprises and in countries is not a rented API. It is the ability to build your own software, on your own infrastructure, over open formats and your own data — and to control the model that does the writing. Sovereignty over the data plane and the model is what turns AI from a dependency into a capability.

So I build the things I argue for. JuniLake, JuniBas, JuniSoc, and JuniFleet are working systems, not prototypes: open formats, self-hostable, no per-gigabyte licence, and honest about their limits. They are how I demonstrate that the argument holds up in code.

Japan

Since 2006

I lived in Japan in 2006 and 2007, studying full-time at the Yamasa Institute in Okazaki, and I have returned every year since — for conferences, for industrial and factory tours, and to keep watching how the country changes.

That start date turned out to be a piece of luck. I arrived when the folding feature phone was still the centre of Japanese consumer technology — a device more capable than anything sold in North America at the time, with mobile payments and digital television already routine — and I have watched the whole arc since: the smartphone's arrival, what it displaced, and what it did not. Two decades of annual visits is a rare vantage point on an industry, and it shaped how I think about the difference between technology that is genuinely adopted and technology that is merely announced.

Japanese is the language spoken at home. My own level is around JLPT N3; I have not sat the examination, and there is a great deal I still have to learn. I keep working at it.

Contributing that experience inside a Japanese organisation, in Japanese and English both, is the move I am most actively working toward.

Career history

2001 – present
  • 2026-02 –
    Manager, Governance / IT Risk & Compliance
    Big Four professional services firm

    Leads the global Breach and Attack Simulation and Remediation functions. Runs ATT&CK-aligned adversary simulation to validate control effectiveness across detection, prevention and response; owns the remediation and risk-treatment lifecycle for BAS and red-team findings end to end; partners across SOC/MDR, IAM, threat intelligence, incident response, security architecture and enterprise risk; reports posture, coverage and risk closure to senior leadership and governance forums.

  • 2023-01 – 2026-02
    Manager, Managed Extended Detection & Response (MXDR)
    Big Four professional services firm

    24/7 MXDR service operations for enterprise clients: scheduling, analyst training, process standardisation, and operational metrics. Led technical improvements to the detection platform including threat-intelligence integration and automated response workflows, and ran recurring security control validation across EDR, firewall and application allow-listing to find coverage gaps. Subject-matter expert for threat hunting, incident response and malware analysis across global delivery centres.

  • 2021 – 2022-11
    Manager, Managed Detection & Response (MDR)
    A second Big Four firm

    Scaled a startup-born detection and response function into a mature, globally aligned MDR service. Evolved SOC processes and playbooks blending threat intelligence, behavioural analytics and automation; directly managed up to 25 team members through significant organisational change; provided subject-matter expertise in incident response and digital forensics.

  • 2018 – 2021
    Senior Consultant, Threat Hunting & Offensive Security
    Joined through the acquisition of a Canadian security startup

    Senior threat hunter and analyst: led escalations from Tier I and II analysts during high-priority investigations, hunted using ATT&CK, the Cyber Kill Chain and the Diamond Model, and performed forensic investigation, reverse engineering, and static and behavioural malware analysis. On the offensive side: infrastructure and application penetration testing across web, mobile and cloud, social engineering and phishing simulations, and custom endpoint evasion techniques.

  • 2013 – 2018
    IT Security Analyst
    Telecom instrumentation manufacturer

    Moved into security through a high-stakes insider-threat investigation, which grew into a broader security operations and internal investigations role: network and monitoring alerts, vulnerability assessment and web application testing, investigation of tampering in accounting systems, and behavioural timeline reconstruction to support investigations.

  • 2007 – 2018
    Metrology technician → interim QC manager → webmaster & ERP developer
    Telecom instrumentation manufacturer

    Started on fibre-optic telecom test instruments as a metrology technician, then interim quality control manager. Moved into the systems around the product: webmaster and web marketing for the e-commerce platform, ERP customisation and API connectors, Crystal Reports and database work, SharePoint and documentation control, and Windows and Linux server administration.

  • 2006 – 2007
    Full-time Japanese study — AIJP
    The Yamasa Institute, Okazaki, Aichi

    A year and a half in Japan on the Academic Intensive Japanese Program. See Education below.

  • 2001 – 2006
    Manufacturing IT — summer employment, then weekend part-time, then intern, then contract
    IBM

    Five years on and around the plant floor, working up from a summer job to contract engagements, including preventive maintenance systems. The origin of a bias I still hold: production environments have real constraints, and a control that stops the line is not a control anyone will keep.

People and technical leadership

How I want to work

I have managed up to 20–25 onshore and offshore resources, both remotely and in the same room, and I currently lead an international team of around ten. I am comfortable with that work — hiring, developing analysts, running a service that has to be awake at three in the morning.

What I want more of is technical leadership and technical strategy: architecture decisions, standards, choosing what to build and what to buy, and staying close enough to the system to be accountable for the answer. I am open to individual-contributor and supervisory roles alike; the role I would be best in is a CTO, Principal, or head-of-technical-strategy shape, where the judgement and the implementation are not separated from each other.

Specialty areas

Domains
  • Security Data Lake
  • Breach & Attack Simulation
  • CTEM / Adversarial Exposure Validation
  • Purple Teaming
  • Red Teaming
  • MITRE ATT&CK
  • Detection Engineering
  • Sigma
  • Threat Hunting
  • Digital Forensics & Incident Response
  • Ransomware Response
  • Malware Analysis
  • Velociraptor
  • osquery / Fleet
  • Penetration Testing
  • SOC & MDR Operations
  • CrowdStrike
  • Microsoft Defender
  • Jupyter / JupyterLab
  • Local LLMs (Ollama, Hugging Face)
  • Governance, Risk & Compliance
  • Risk Treatment & Remediation
  • Cloud Security (AWS / Azure)
  • ERP & Manufacturing IT

Certifications

Credentials
CredentialIssuerYear
CISSPISC22016
OSCP — Offensive Security Certified ProfessionalOffSec2017
GXPN — Exploit Researcher & Advanced Penetration TesterGIAC2018
GCFA — Certified Forensic AnalystGIAC2021
GCIH — Certified Incident HandlerGIAC2016
GCFE — Certified Forensic ExaminerGIAC2015
GRID — Response and Industrial DefenseGIAC2022 · expired 2026-06, not renewed
ATT&CK Adversary Emulation MethodologyMITRE Engenuity2022
ATT&CK Cyber Threat IntelligenceMITRE Engenuity2022
ATT&CK Security Operations Center AssessmentMITRE Engenuity2021
MCPS — Microsoft Certified ProfessionalMicrosoft2013

In progress

CredentialIssuerStatus
CISA — Certified Information Systems AuditorISACAIn progress
CRISC — Certified in Risk and Information Systems ControlISACAPreparing
Certified Offensive AI ExpertHack The BoxStudying
Next SANS / GIAC certificationGIACPreparing

The Hack The Box AI credential — built with Google and aligned to its Secure AI Framework — covers prompt injection, model privacy attacks, adversarial machine learning, and AI supply-chain and deployment risk, and is assessed by a seven-day practical examination. CISA and CRISC are the natural complement to my current work in a governance and IT risk function.

Education & training

Institutions
Justice Institute of British Columbia
2016 – 2017

Investigation & Enforcement Skills Certificate — law-enforcement investigation and interviewing.

The Justice Institute of British Columbia is a public post-secondary institution in Canada dedicated entirely to justice and public-safety education. Its Police Academy delivers the provincially mandated basic training for every new municipal police recruit in British Columbia, alongside programs for paramedics, sheriffs, corrections officers, firefighters and emergency managers. The certificate is the applied investigation and interviewing training used by peace officers, public-sector regulatory investigators and private-sector investigators.

The Yamasa Institute
Okazaki, Aichi · 2006 – 2007

AIJP — Academic Intensive Japanese Program, one and a half years of full-time study.

The AIJP is not a conversation course or a JLPT preparation class. It is a full-time academic program designed to bring students to the level required to enter and study at a Japanese university or vocational college, or to work inside a Japanese company — explicitly aimed beyond everyday conversation. Students are placed across six ability levels by entrance testing and work through reading, writing, speaking and listening as separate disciplines over four daily periods. Entry is by application and selection rather than enrolment; in my case admission required demonstrating academic writing ability in English and French before I was accepted.

SANS Institute
Selected courses
SEC660 Advanced Penetration Testing, Exploit Writing and Ethical Hacking; FOR500 Windows Forensic Analysis; MITRE ATT&CK Defender (MAD) fundamentals and SOC assessment training; OffSec PWK and AWAE.

Affiliations

Memberships
GIAC Advisory Board
Since 2015

Member.

The GIAC Advisory Board is an invitation-only forum of GIAC-certified practitioners. Invitations are extended only to candidates who score 90% or above on a GIAC certification exam; members sign a non-disclosure agreement and are consulted as subject-matter experts on certification content and courseware. It is a standing peer group rather than a credential, and membership is not a thing you can apply for.

ISACA
Member for several years, renewing annually each December. Currently working toward the CISA designation and preparing for CRISC, with direct experience in a governance and IT risk function.
ISC2
CISSP holder since 2016.

Languages

Proficiency
French
Native.
English
Bilingual, professional. Sixteen years living and working in British Columbia; all professional work, all client communication, and every certification examination in English.
Japanese
Around JLPT N3 — not certified. Spoken at home daily; one and a half years of full-time study at the Yamasa Institute, and continued study since. There is still a great deal to learn, and I am working on it.

Where I want to work

Location & eligibility
Location
Currently Vancouver, British Columbia. Open to relocating to Japan — the move I am most actively working toward — and equally open to roles in British Columbia or remote across Canada and the US.
Eligibility — Japan
Eligible for the Spouse or Child of Japanese National status of residence (日本人の配偶者等). No restriction on the category of work, and no visa sponsorship required from an employer.
Eligibility — Canada
Authorised to work in Canada; sixteen years living and working in British Columbia.
Roles
Individual contributor or supervisory. Best fit: CTO, Principal, or head of technical strategy — security engineering, detection and validation platforms, or a security data platform function.

Contact

Happy to talk about roles, or about any of the above.