Lucas Christian
Senior Security Engineer
Employment
Databricks
Seattle, WA
Senior Security Engineer - Enterprise Security
Oct. 2022 to Current

Zero Trust Implementation - Deployed an OSQuery-based tool fleet-wide, designed posture checks for device health assessment during Single Sign-On (SSO) authentication, and enforced policy-based blocking for unhealthy devices accessing specific SaaS resources.

Security Tooling Enhancement - Led efforts to revamp existing security tools in monitoring and enforcement domains while managing multiple endpoint security tools. Collaboration with stakeholders led to optimized tooling for reduced performance overhead. Implemented and enforced Role-Based Access Control (RBAC) in cloud consoles and developed an API inventory to help manage token lifecycle.

Architecture Review - Conducted security implementation and architecture assessments for various internal and SaaS projects. Additionally, authored guidelines and Security Technical Implementation Guides (STIGs) for internal tech teams.

Leadership and Team Contribution - Played a key role in the team by regularly formulating team strategies and initiatives. Also provided mentorship to junior team members and delivered presentations and demos to the broader security organization.

Active Directory Hardening and Redesign - Identified and addressed hardening and patch deficiencies in the Active Directory system, collaborating with stakeholders. Additionally, I proposed design changes to align the network with best practices for enhanced security.

Uber Technologies Inc
Seattle, WA
Security Engineer II - Enterprise Security
Apr. 2020 to Oct. 2022

Endpoint Detection and Response - Served as the platform owner for the enterprise's EDR solution, protecting 50k hosts and designing and implementing numerous workflows to deploy security enhancements, track API key inventory, and address process failures.  Collaborated regularly with partner teams and subsidiaries to ensure through testing of new features and configuration changes, and programmatically implemented RBAC to enforce the principle of least privilege for all platform users. Additionally, I created a methodically for doing sensor regression testing to monitor performance issues caused by new sensor versions. I am also a routine bug submitter to our EDR vendor.

Data Loss Prevention - Derisked the environment by deploying security controls to specific cohorts with unique regulatory needs and during high risk events, divestitures, employee termination) to help mitigate the likelihood of data theft or leakage.  Also, developed a custom service that monitored  Google Drive sharing activity and automatically revoked inappropriate sharing, reducing the risk of data leakage and theft.

Merger/Acquisitions/Divestitures - Designed secure architecture, deployed security tools to meet compliance and stakeholder requirements, and engineered custom tooling to assist with transfer of sensitive data. Supported all major M&A activities end-to-end since 2020.

Operational Enhancements - Created and improved documentation, runbooks, and technical documentation for my products, and regularly enhanced monitoring capabilities, control policies, and exception management to improve efficiency and reduce the operational burden for the team.

Audits and Compliance - Participated as a key contributor in multiple audits, penetration tests, and business activities, identifying optimizations and guiding risk management decisions to ensure compliance and security in Uber's evolving technical landscape.

Custom Tooling - Improved the features, local testing, and overall efficiency of in-house malware scanning tooling, and created comprehensive documentation for Ops members to use and maintain the tooling.

Susquehanna International Group, LLP
Bala Cynwyd, PA
Information Security Engineer
July 2018 to Apr. 2020

• Engineered solutions in multiple languages to secure privileged accounts, published internal modules for secure credential retrieval, hardened systems, and automate routine system maintenance and upgrades

• Developed and implemented security baselines for the entire Windows workstation fleet and servers, based on risk profile and industry best practices

• Designed and maintained a testing and deployment framework for modern Windows 10 security controls such as Credential Guard and Exploit Guard, ensuring the security and compliance of the enterprise fleet.

• Conducted an audit of the enterprise PKI lifecycle and removed deprecated and weak authentication protocols to improve security and compliance

• Deployed a production-grade service that automates the enrollment and rotation of root passwords into the enterprise password manager, improving security and reducing the risk of password-related incidents

• Initiated and led multiple grass-roots projects focused on improving efficiency, automation, and security best practices across the organization

• Participated actively in the vulnerability management working group, contributing expertise and insights to improve the organization's vulnerability management processes and outcomes

MCPlus, LLC
Remote
Senior Security Consultant
2015 to 2021

• Performed penetration testing and vulnerability assessments for SMBs to identify security weaknesses and strengthen posture.

• Collaborates with clients to offer personalized and actionable recommendations for improving their security programs and procedures.

• Designs and develops custom tools and scripts to automate internal processes and improve field work efficiency.

• Manages and executes infrastructure upgrades and migrations for internal and customer systems, ensuring minimal downtime and maximum security.

• Provides hands-on training and guidance to junior staff on how to use tooling and procedures to efficiently and effectively perform security assessments.

Activities
RITSEC (RIT Security Club) · Alumnus
2014 to Current

• Regularly attends annual club meetups at Shmoocon to stay up-to-date with industry trends and network with peers.

• Served as a club member, presenter, and former club secretary (Spring 2015), actively participating in the club's events and initiatives

• Delivered a presentation at RIT's annual innovation conference (ImagineRIT 2015) focused on teaching the public about common security vulnerabilities and how to protect themselves.

• Acted as a white team member/volunteer during multiple security competitions, providing guidance and support to participants.

Team Contagion (RIT CTF Team) · Founder & Former Captain
2016 to 2019

• 1st place - Shmoocon Novetta CTF 2019, Bsides ROC CTF 2018, Parsons Cyber CTF 2017, RC3CTF 2017, Bsides ROC CTF 2017, Hack The Arch 2016, RC3 Semester CTF Fall 2015, RC3 Semester CTF Fall 2014

• 2nd place - RC3CTF 2015, Alfred State CTF 2015

• 4th place - MITRE CTF 2016, RC3CTF 2014

Security Competitions

Attack/Defend 

• National Collegiate Cyber Defense Competition (CCDC) - 2nd Place Regional 2016

• National Collegiate Pentesting Competition (CPTC) - 4th Place 2017, 3rd Place 2016, 2nd Place 2015

• Information Security Talent Search (ISTS) - 3rd Place 2017, 3rd Place 2016

• Incident Response Competition (IRSeC) - 1st Place 2016

Education
Rochester Institute of Technology
2014 to 2018
B.S. Computing Security
Minor Criminal Justice
Certifications
Certified Information Systems Security Professional (CISSP)
Offensive Security Certified Professional (OSCP)
Cisco Certified Network Associate Cyber Ops (CCNA Cyber Ops)
Skills
Security-centric Skills
Automation
Endpoint Security
Engineering
IAM Policies and Configuration
Infrastructure Hardening
Penetration Testing
Privileged Account Management
Product Evaluation
Vulnerability Management
Personal
Demonstrates Leadership Qualities
Identifies Process Inefficiencies
Personable
Security Driven
Self-Starting
Team Player
Troubleshooting
Volunteering
AFA: U.S. Cyber Patriot · Mentor
2015 to 2018

• Mentored the local Cyber Patriot team, presenting and teaching through demonstrations and hands-on activities.

• Taught students how to secure Windows and Linux-based operating systems, covering key security concepts and providing hands-on experience.

Rhode Island Hackathon 2015 · Infrastructure Lead

• Designed and implemented the network and infrastructure for the hackathon event, providing ongoing maintenance and support throughout the event.

• Participated actively in the planning and organization of the hackathon event, contributing ideas and expertise to the event planning team.

RIT Computing Security Department · Student Ambassador
2015 to 2017

• Served as a student ambassador, interacting with prospective students and their parents to provide information and support on becoming RIT Computing Security students.

• Assisted with technical demonstrations for prospective students, showcasing the program's facilities and capabilities.

Projects
Crypto Market Data Feed Graphing
2019 to 2019

• Archived crypto currencies in InfluxDB, using the Coinbase API to query the data and store in a structured and easily accessible format for analysis and visualization.

• Visualized key metrics in Grafana, and created customizable dashboards to allow users to explore and analyze the data.

Pastebin Data Scraper and Visualization
2017 to 2018

• Designed a Pastebin data scraper and visualization tool, which allows users to analyze and explore relevant data.

• Implemented an alerting and notification system, which triggers alerts via email/SMS when flagged keywords is posted on Pastebin.

Home Monitoring Project
2016 to 2018

• Implemented Pfsense as the Internet firewall for the home monitoring project, providing robust security features and integrating it with Snort for IDS/IPS.

• Utilized Security Onion for collection and analysis of network traffic data, and providing a Splunk frontend for real-time visualization and analysis of the data.

• Configured Squid as a proxy server which provided efficient proxying of HTTP traffic through caching.