santrancisco.net

Profile

Security engineer with seventeen years across government, banking and SaaS, now leading application security for a cloud database. I like taking things apart to see how they work, and I like automating anything that gets done twice. Lately that means designing AI-agent workflows so that a small security team can triage, review, fix and track at the pace of a much larger one.

Pentester by training, builder by habit: most of what I've shipped in the last decade has been tooling that made a team faster or a platform safer.

Experience

  1. Senior Application Security Engineer

    ClickHouse June 2022 – present

    ClickHouse is the fastest open-source column-oriented database; ClickHouse Cloud is the managed service built by its original creators.

    • Own application security for ClickHouse Cloud: vulnerability management across every component, security testing of features as they are built, and design reviews alongside engineering.
    • Maintain and extend fuzzing in CI for both the open-source and private ClickHouse builds.
    • Runtime monitoring on our Kubernetes clusters, alerting, and automated triage that routes issues to the owning team.
    Scaling the team with AI workflows (2025 – present)
    • Bugcrowd triage, end to end. An agent workflow that reviews incoming findings, validates and rates them, handles payout, tracks resolution with the responsible engineers, and nudges them through an SLA reminder bot.
    • Intake automation. Requests and tasks raised by the team in Slack are captured, classified and turned into tracked work without a human copying tickets around.
    • Distributed AI code review. A shared system for internal product-security work where we assign reviews and tasks to AI agents, collaborate on their output and feed the results back to engineering.
    • “Skynet”. An isolated, centrally managed platform for AI agents built by internal staff, with endpoint protection, runtime detection and network filtering enforced by default, so experimentation doesn't become exposure.
  2. Security Engineer

    CM Group (Campaign Monitor) Sep 2018 – Jun 2022

    Email-marketing group of seven SaaS brands; Campaign Monitor alone sends around three billion emails a month.

    • Ran application security for all seven platforms: pentesting, Bugcrowd triage, and fixing findings myself or reviewing the fix across several languages.
    • Designed in-house security products for the whole group, including a single solution to AWS access control across the acquired companies and a tool for sharing sensitive data with clients.
    • Deployed and ran logging on Splunk Cloud and Elasticsearch; reviewed infrastructure and system designs as part of the DevOps and security crew.
    • Built developer security training, including an in-house CTF and regular technical sessions.
  3. Principal Cyber Security Specialist

    Digital Transformation Office → Australian Cyber Security Centre Apr 2016 – Sep 2018

    The DTO rebuilt how citizens interact with the Australian Government online; the security team later moved into the ACSC.

    • Pentested DTO projects, other agencies' systems and third-party services; researched the cloud technology the office relied on.
    • Built tools that watched public GitHub for leaked credentials and flagged when agile projects needed a pentest.
    • Ran the platform as well as testing it: Pivotal Cloud Foundry on AWS with CloudFormation, Terraform, Ansible and BOSH; CI/CD onboarding for developers; logging and security alerting.
  4. Principal Penetration Tester

    Commonwealth Bank of Australia Mar 2015 – Apr 2016
    • Joined the new in-house pentest team in the Digital Protection Group; delivered project and BAU tests on mobile apps, web applications and internally built thick clients.
    • Managed internal clients and external vendors from scoping to remediation; improved the framework, rules of engagement and methodology; trained junior testers; supported incidents needing log analysis and malware reversing.
  5. Senior Security Analyst

    Reserve Bank of Australia Nov 2013 – Feb 2015
    • Helped stand up the Bank's new Security Analysis and Testing team: methodology, rules of engagement, the pentest and incident-response lab, and training for existing staff.
    • Tested biometric authentication, secure data-exchange and internal applications, including unannounced tests; automated Nessus compliance reporting; ran lunch-and-learn demos for the wider Bank. Security Officer of the Year, 2014.
  6. Vulnerability Analyst · IT Security Auditor

    Australian Taxation Office Aug 2008 – Nov 2013
    • Five years in the Vulnerability Management and Research team: internal and external pentests, security evaluation of new products (mobile devices, endpoint security, secure drives, DECT headsets), incident response, malware and phishing analysis, and custom tooling for all of it.
    • Started as a security auditor: compliance reviews against the ASD Information Security Manual, system security plans, and a more technical review template. Commissioner's Award for Technical Excellence, 2012.

Awards & achievements

  • 2014Security Officer of the Year — Reserve Bank of Australia
  • 2014FireEye Flare-On reverse-engineering challenge finisher
  • 2014Global CyberLympics — Australian regional champion
  • 2013Global CyberLympics — Australian regional champion
  • 2013EMC Galaxy Award, Trusted IT
  • 2012ATO Commissioner's Award for Technical Excellence
  • 2012ATO Line Award (team)
  • 2011AusCERT Award for Organisational Excellence in InfoSec (team)
  • 2009SC Magazine Highly Commended for Innovation (team)
  • 2007EY Ethical Hacking University Challenge (team)

References available on request.