About
I’m Josh Rickard: a threat research engineer and security practitioner who builds software, systems, and automation that help defenders solve complex problems at scale.
Over a 14+ year career, I’ve worked across security operations, digital forensics and incident response, detection engineering, security architecture, product leadership, and software engineering. I’ve built open-source tools, led products used by more than 18 million people, and helped build Go and Python services that process billions of security events each day.
I’m especially interested in the intersection of threat research, behavioral detection, security automation, event-driven systems, and agentic tooling. My bias is toward practical work: reducing operational toil, improving reliability, and keeping human judgment where it matters.
Now
I work on threat research and detection engineering at Sublime Security, with a focus on improving phishing defense through better behavioral detections, research workflows, and tooling.
This site is where I share what I learn: detection and automation ideas, open-source projects, defensive security research, and occasional thoughts on the social and technical consequences of AI.
Experience
Threat Research Engineer
Sublime Security / June 2026 to Present
I research threats and build detections, tooling, and frameworks that help make phishing defense more effective, scalable, and understandable.
Detection Engineer 2
Sublime Security / June 2025 to June 2026
Joined Sublime Security’s detection organization to help defend people from phishing at scale.
- Evaluated commercial and open-source threat intelligence against the core technique-based rule corpus, helping validate coverage, reduce spend, and establish a future intelligence roadmap
- Improved behavioral detections by increasing true positives and reducing false positives across the corpus
- Researched, authored, and validated new detection rules based on emerging threats and attacker behavior
Senior Software Engineer - Threat Detection
AppOmni / March 2023 to March 2025
Architected and developed distributed Golang microservices powering an event-driven ETL platform that processed billions of audit-log events daily.
- Designed and managed event enrichment services that scaled to more than 90,000 queries per second
- Built libraries and standards for unary and streaming gRPC/Protobuf services
- Worked on ETL, normalization, caching, logging, and observability in an event-driven architecture
- Helped automate deployments across multi-tenant Kubernetes environments
- Standardized service documentation and operational practices to support SRE and on-call teams
Senior Detection Validation Engineer
Red Canary / Colorado / October 2022 to January 2023
Worked within the Detection Enablement organization to build platforms and infrastructure that validated detection capabilities at scale across modern attacker techniques.
- Developed a Ruby on Rails application to streamline testing of attacker techniques, tooling, and detection logic
- Built automation with Terraform and Ansible to deploy and execute attack-testing frameworks across operating systems and EDR products
- Improved the repeatability and scalability of detection validation through standardized workflows
Senior Security Solutions Architect
Swimlane / Colorado / December 2018 to October 2022
Designed security automation solutions, integrations, and open-source tooling that enabled enterprise security teams to automate complex workflows and improve operational efficiency.
- Built security automation workflows used by large private-sector, public-sector, and government organizations
- Implemented integrations across numerous security operations platforms
- Released open-source tools including pyattck, atomic-operator, and soc-faker
- Authored technical content and presented on security automation, threat research, and defensive security
- Took internal tools and frameworks from early ideas through implementation and adoption
Manager, Reporter Solutions Engineering
Cofense / Virginia / December 2015 to November 2018
Led product, support, and engineering efforts for the Cofense Reporter product line as it scaled from roughly one million to more than 18 million global installations.
- Managed product development from concept through release while coordinating internal and external engineering teams
- Designed automation systems for product generation, validation, and support, reducing engineering effort and operational support costs
- Served as Technical Product Owner for three Scrum teams consisting of nine software engineers and six QA engineers
- Helped scale one of the industry’s most widely deployed phishing-reporting platforms through engineering leadership and product innovation
Security Analyst - Specialist
University of Missouri / May 2012 to December 2015
Worked across digital forensics and incident response, enterprise security operations, systems administration, and tool development.
- Managed enterprise vulnerability-management and endpoint-protection programs
- Created and maintained secure Group Policy configurations across the organization
- Automated operating-system deployment and endpoint-management services
- Managed servers and systems across multiple departments
- Built internal and open-source tools to support security operations
Open-Source Projects
You can see a full list of my open-source projects on GitHub. Here are a few highlights.
- pyattck - A Python package for interacting with the MITRE ATT&CK Framework
- atomic-operator - A Python package for executing Atomic Red Team tests across multiple operating-system environments
- soc-faker - A Python package for generating fake data for security operations and automation
- opencti-enrichment - A Golang service that enriches OpenCTI observables and identifies indicators of compromise
- ai-router - A Python CLI tool that routes local Ollama models based on available system resources
✍ Blog & Writing
I write here on Lets Automate It about threat detection, automation, software, security research, and the changing relationship between people and AI. You can find additional writing, interviews, and mentions on the Press page.
✍ Publications
- Beyond the Prompt: The Social Costs of Generative Artificial Intelligence (with J. Scott Christianson) - Examines the environmental, societal, and infrastructure costs of the generative-AI boom
Recognitions
- Official maintainer of the Atomic Red Team project
- Past President and Board Member of the Central Missouri InfraGard chapter
- 2019 SC Media Reboot Leadership Awards Influencer
- Contributing author to Tribe of Hackers: Blue Team
Past Presentations
I’ve presented on detection, automation, phishing, incident response, Windows security, and AI at conferences, universities, and webinars. You can view past presentations and recordings here.