LIVING RÉSUMÉ
Luke Wescott
Detection Engineer specializing in ML-driven, detection-as-code systems — designing and tuning the detections that catch real threats at global scale. M.Sc in AI & Machine Learning. Off the clock: French lessons, hockey, books, and new music.
EXPERIENCE
Tap any line to expand it — or flip to verbose.
- Detection Engineer II Sublime SecurityMay 2025 — Present Remote
- Curate atomic detection rules that shape ML-based verdicts — giving detection engineering direct influence over model outcomes to maximize efficacy.
- Continuously update, manage, and expand the ruleset while tuning false-positive and false-negative rates against constantly evolving threats.
- Mentor a growing team of 3 junior detection engineers, support customer escalations, and interview candidates — helping grow the team from 5 to 13.
-
- Detection Engineer NuHarbor SecurityJun 2024 — May 2025 Colchester, VT
- Designed and deployed detection-as-code CI/CD pipelines, improving threat detection by 40%.
- Automated threat detection using Python and SPL, reducing false positives by 30%.
- Conducted threat modeling and attack-path analysis and collaborated with intelligence teams to integrate new threat feeds, expanding detection coverage.
- Built proprietary tools to automate SOC workflows, improving tuning efficiency by 50%, and optimized detection systems for GCP and Azure environments.
-
- Security Engineer NuHarbor SecurityJun 2023 — Jun 2024 Colchester, VT
- Built and administered Splunk environments that gave SOC analysts real-time insight and improved data-collection efficiency.
- Aligned detection strategies to client requirements, improving alert fidelity.
-
- IT Staff Evergreen Parks & Recreation District2021 — 2022 Evergreen, CO
- Resolved technical issues across POS systems and networks, and built a Python ticket-management app that cut response time by 25%.
-
- Technology & Merchandising Pro Apple2019 — 2021 Denver, CO
- Deployed and managed the entire fleet of demo products via internal MDM, and led the merchandising reset for the flagship store relocation.
-
EDUCATION
M.Sc — Artificial Intelligence & Machine Learning
Colorado State University Global
Jan 2025 · GPA 3.96
B.Sc — Computer Science
Colorado State University Global
2023 · GPA 3.9
CERTIFICATIONS
Splunk Certified Enterprise Admin · exp. Aug 2026
Splunk Certified Power User · exp. Aug 2026
CAPABILITIES
PythonSplunk / SPLDetection-as-CodeGitOps · CI/CDMachine LearningTensorFlowCloud Security (AWS·Azure·GCP)MITRE ATT&CKAnomaly DetectionEmail AnalysisMicrosoft SentinelLinux
SELECTED WORK & WRITING
“Prompt injection attacks don’t look like the headlines”
Sublime Security ↗
“Using AI signals within malicious email”
Sublime Security ↗
“You’ve been invited to join a Meta for Business scam!”
Sublime Security ↗
Content-Sync Deployment Automation
−70% manual deploy time · Bash + Python
ML SPL Generator — M.Sc capstone
Turns threat-writeup IOCs into Splunk SPL