Julien B. Grenier
ジュリアン・B・グルニエ · Security engineering & research
For twenty years I have worked both sides of the security line: running red-team engagements, and building the detection meant to catch them. The conviction that stuck is simple — security assumptions have to be tested systematically, or they are just hope.
On defence, I have been part of the teams that stood up managed detection and response services from nothing, and I have led high-severity incident response through ransomware, business email compromise, and espionage, backed by digital forensics, threat hunting, and detection engineering. On offence, multi-month red-team engagements with C2 frameworks, EDR and control bypass, and MITRE ATT&CK coverage assessments that pinpoint the gaps. Purple team is where the two meet, and it is the work I care about most.
Today I lead a global breach-and-attack-simulation and remediation practice: continuous, ATT&CK-aligned control validation that turns assumptions into evidence and findings into closed risk, maturing toward CTEM. I work across SOC and MDR, identity, threat intelligence, incident response, security architecture, and enterprise risk — and I build the teams that do it.
That experience is split between in-house roles and client-facing consulting at two Big Four firms, so I am equally comfortable owning a capability from the inside and being accountable to an external client for it.
What building it twice taught me
I helped build a Canadian detection-and-response startup from the ground up. It was acquired by a Big Four professional services firm, and I moved across with it — then spent the following years turning what had been a nimble startup function into a globally aligned MDR service, managing up to 25 people through that transition. The acquisition was the right outcome, and I contributed to the part of it that made the company worth acquiring: a working service with real customers behind it.
The more useful half of the story is what happened next. A comparable team later set out to build an improved variation of the same idea inside an even larger organisation, and it was materially harder. The technology was largely off-the-shelf both times — that was never the differentiator. What actually carried the first effort was the operating model, the people who remembered why each decision had been made, and the customer relationship that funded the learning.
The platform is the easy part. The judgement about which decisions matter, and the accountability for them, is what does not transfer in a slide deck.
That is the single most useful thing I know about building security capability, and it is why I evaluate a plan by what it will still be doing in year three rather than by what it demonstrates in the first quarter.
Why I build my own platforms
I build tooling with AI every day, and the practice keeps returning me to one point: when a model can write the code, the value was never the code. What lasts is judgement — knowing which decisions matter — and accountability, because a machine cannot take responsibility. Someone still has to vet the work and sign it.
The conclusion I draw from that is not that AI matters less. It is that the durable form of AI in enterprises and in countries is not a rented API. It is the ability to build your own software, on your own infrastructure, over open formats and your own data — and to control the model that does the writing. Sovereignty over the data plane and the model is what turns AI from a dependency into a capability.
So I build the things I argue for. JuniLake, JuniBas, JuniSoc, and JuniFleet are working systems, not prototypes: open formats, self-hostable, no per-gigabyte licence, and honest about their limits. They are how I demonstrate that the argument holds up in code.
Japan
I lived in Japan in 2006 and 2007, studying full-time at the Yamasa Institute in Okazaki, and I have returned every year since — for conferences, for industrial and factory tours, and to keep watching how the country changes.
That start date turned out to be a piece of luck. I arrived when the folding feature phone was still the centre of Japanese consumer technology — a device more capable than anything sold in North America at the time, with mobile payments and digital television already routine — and I have watched the whole arc since: the smartphone's arrival, what it displaced, and what it did not. Two decades of annual visits is a rare vantage point on an industry, and it shaped how I think about the difference between technology that is genuinely adopted and technology that is merely announced.
Japanese is the language spoken at home. My own level is around JLPT N3; I have not sat the examination, and there is a great deal I still have to learn. I keep working at it.
Contributing that experience inside a Japanese organisation, in Japanese and English both, is the move I am most actively working toward.
Career history
-
2026-02 –
Manager, Governance / IT Risk & ComplianceBig Four professional services firm
Leads the global Breach and Attack Simulation and Remediation functions. Runs ATT&CK-aligned adversary simulation to validate control effectiveness across detection, prevention and response; owns the remediation and risk-treatment lifecycle for BAS and red-team findings end to end; partners across SOC/MDR, IAM, threat intelligence, incident response, security architecture and enterprise risk; reports posture, coverage and risk closure to senior leadership and governance forums.
-
2023-01 – 2026-02
Manager, Managed Extended Detection & Response (MXDR)Big Four professional services firm
24/7 MXDR service operations for enterprise clients: scheduling, analyst training, process standardisation, and operational metrics. Led technical improvements to the detection platform including threat-intelligence integration and automated response workflows, and ran recurring security control validation across EDR, firewall and application allow-listing to find coverage gaps. Subject-matter expert for threat hunting, incident response and malware analysis across global delivery centres.
-
2021 – 2022-11
Manager, Managed Detection & Response (MDR)A second Big Four firm
Scaled a startup-born detection and response function into a mature, globally aligned MDR service. Evolved SOC processes and playbooks blending threat intelligence, behavioural analytics and automation; directly managed up to 25 team members through significant organisational change; provided subject-matter expertise in incident response and digital forensics.
-
2018 – 2021
Senior Consultant, Threat Hunting & Offensive SecurityJoined through the acquisition of a Canadian security startup
Senior threat hunter and analyst: led escalations from Tier I and II analysts during high-priority investigations, hunted using ATT&CK, the Cyber Kill Chain and the Diamond Model, and performed forensic investigation, reverse engineering, and static and behavioural malware analysis. On the offensive side: infrastructure and application penetration testing across web, mobile and cloud, social engineering and phishing simulations, and custom endpoint evasion techniques.
-
2013 – 2018
IT Security AnalystTelecom instrumentation manufacturer
Moved into security through a high-stakes insider-threat investigation, which grew into a broader security operations and internal investigations role: network and monitoring alerts, vulnerability assessment and web application testing, investigation of tampering in accounting systems, and behavioural timeline reconstruction to support investigations.
-
2007 – 2018
Metrology technician → interim QC manager → webmaster & ERP developerTelecom instrumentation manufacturer
Started on fibre-optic telecom test instruments as a metrology technician, then interim quality control manager. Moved into the systems around the product: webmaster and web marketing for the e-commerce platform, ERP customisation and API connectors, Crystal Reports and database work, SharePoint and documentation control, and Windows and Linux server administration.
-
2006 – 2007
Full-time Japanese study — AIJPThe Yamasa Institute, Okazaki, Aichi
A year and a half in Japan on the Academic Intensive Japanese Program. See Education below.
-
2001 – 2006
Manufacturing IT — summer employment, then weekend part-time, then intern, then contractIBM
Five years on and around the plant floor, working up from a summer job to contract engagements, including preventive maintenance systems. The origin of a bias I still hold: production environments have real constraints, and a control that stops the line is not a control anyone will keep.
People and technical leadership
I have managed up to 20–25 onshore and offshore resources, both remotely and in the same room, and I currently lead an international team of around ten. I am comfortable with that work — hiring, developing analysts, running a service that has to be awake at three in the morning.
What I want more of is technical leadership and technical strategy: architecture decisions, standards, choosing what to build and what to buy, and staying close enough to the system to be accountable for the answer. I am open to individual-contributor and supervisory roles alike; the role I would be best in is a CTO, Principal, or head-of-technical-strategy shape, where the judgement and the implementation are not separated from each other.
Specialty areas
Certifications
| Credential | Issuer | Year |
|---|---|---|
| CISSP | ISC2 | 2016 |
| OSCP — Offensive Security Certified Professional | OffSec | 2017 |
| GXPN — Exploit Researcher & Advanced Penetration Tester | GIAC | 2018 |
| GCFA — Certified Forensic Analyst | GIAC | 2021 |
| GCIH — Certified Incident Handler | GIAC | 2016 |
| GCFE — Certified Forensic Examiner | GIAC | 2015 |
| GRID — Response and Industrial Defense | GIAC | 2022 · expired 2026-06, not renewed |
| ATT&CK Adversary Emulation Methodology | MITRE Engenuity | 2022 |
| ATT&CK Cyber Threat Intelligence | MITRE Engenuity | 2022 |
| ATT&CK Security Operations Center Assessment | MITRE Engenuity | 2021 |
| MCPS — Microsoft Certified Professional | Microsoft | 2013 |
In progress
| Credential | Issuer | Status |
|---|---|---|
| CISA — Certified Information Systems Auditor | ISACA | In progress |
| CRISC — Certified in Risk and Information Systems Control | ISACA | Preparing |
| Certified Offensive AI Expert | Hack The Box | Studying |
| Next SANS / GIAC certification | GIAC | Preparing |
The Hack The Box AI credential — built with Google and aligned to its Secure AI Framework — covers prompt injection, model privacy attacks, adversarial machine learning, and AI supply-chain and deployment risk, and is assessed by a seven-day practical examination. CISA and CRISC are the natural complement to my current work in a governance and IT risk function.
Education & training
- Justice Institute of British Columbia
2016 – 2017 -
Investigation & Enforcement Skills Certificate — law-enforcement investigation and interviewing.
The Justice Institute of British Columbia is a public post-secondary institution in Canada dedicated entirely to justice and public-safety education. Its Police Academy delivers the provincially mandated basic training for every new municipal police recruit in British Columbia, alongside programs for paramedics, sheriffs, corrections officers, firefighters and emergency managers. The certificate is the applied investigation and interviewing training used by peace officers, public-sector regulatory investigators and private-sector investigators.
- The Yamasa Institute
Okazaki, Aichi · 2006 – 2007 -
AIJP — Academic Intensive Japanese Program, one and a half years of full-time study.
The AIJP is not a conversation course or a JLPT preparation class. It is a full-time academic program designed to bring students to the level required to enter and study at a Japanese university or vocational college, or to work inside a Japanese company — explicitly aimed beyond everyday conversation. Students are placed across six ability levels by entrance testing and work through reading, writing, speaking and listening as separate disciplines over four daily periods. Entry is by application and selection rather than enrolment; in my case admission required demonstrating academic writing ability in English and French before I was accepted.
- SANS Institute
Selected courses - SEC660 Advanced Penetration Testing, Exploit Writing and Ethical Hacking; FOR500 Windows Forensic Analysis; MITRE ATT&CK Defender (MAD) fundamentals and SOC assessment training; OffSec PWK and AWAE.
Affiliations
- GIAC Advisory Board
Since 2015 -
Member.
The GIAC Advisory Board is an invitation-only forum of GIAC-certified practitioners. Invitations are extended only to candidates who score 90% or above on a GIAC certification exam; members sign a non-disclosure agreement and are consulted as subject-matter experts on certification content and courseware. It is a standing peer group rather than a credential, and membership is not a thing you can apply for.
- ISACA
- Member for several years, renewing annually each December. Currently working toward the CISA designation and preparing for CRISC, with direct experience in a governance and IT risk function.
- ISC2
- CISSP holder since 2016.
Languages
- French
- Native.
- English
- Bilingual, professional. Sixteen years living and working in British Columbia; all professional work, all client communication, and every certification examination in English.
- Japanese
- Around JLPT N3 — not certified. Spoken at home daily; one and a half years of full-time study at the Yamasa Institute, and continued study since. There is still a great deal to learn, and I am working on it.
Where I want to work
- Location
- Currently Vancouver, British Columbia. Open to relocating to Japan — the move I am most actively working toward — and equally open to roles in British Columbia or remote across Canada and the US.
- Eligibility — Japan
- Eligible for the Spouse or Child of Japanese National status of residence (日本人の配偶者等). No restriction on the category of work, and no visa sponsorship required from an employer.
- Eligibility — Canada
- Authorised to work in Canada; sixteen years living and working in British Columbia.
- Roles
- Individual contributor or supervisory. Best fit: CTO, Principal, or head of technical strategy — security engineering, detection and validation platforms, or a security data platform function.
Contact
Happy to talk about roles, or about any of the above.