Nick Cano's Resume

I have been coding for over 20 years and have max skill points in security, C++, and automation. I am a full-stack, full-product engineer who has led engineering teams and efforts, and I can code anything in any language.

In the age of AI, I work agentic-first: using agents to tackle large, long-horizon engineering efforts while I focus on architecture, requirements, invariants, and validation. Using my broad experience and attention to detail, I bring end-to-end testing, robustness, security, and understandability to agent-generated code, with an emphasis on keeping complex systems maintainable as both the codebase and the agents working on it scale.

This is a web-friendly resume, a good ol' .pdf version is available upon request. An unfragmented list of my publications is here.

Employment History

Amazon AWS

Sys Sec, L6
Lead, Client Detection Engineering

Oct 2023 - Present

I joined Amazon as technical lead for a greenfield security-sensitive client/server platform, leading work across Windows kernel mode and user mode, Linux, cryptographic trust, secure RPC, behavioral telemetry, reverse engineering, cloud coordination, and a customer-facing integration SDK.

I owned design and development of major parts of the security model, including verified execution, authenticated and encrypted communications, process and image validation, and supporting anti-tamper mechanisms. I also drove the foundational engineering that made those systems durable: shared architecture and tooling; memory and lifecycle safety; logging and diagnostics; automated testing and fuzzing; static analysis; obfuscation; and virtualization.

I designed and built the server-side SDK responsible for coordinating dozens to hundreds of client instances per server, across a fleet of thousands to tens of thousands of servers. Those systems coordinate with cloud services to collect telemetry, complete proofs of work, and attest hardware security state under extremely tight network, CPU, and memory budgets. Performance-critical work is explicitly chunked, measured, and scheduled at roughly 100 ns granularity.

As the platform matured, I expanded major components to Linux, re-architected the codebase, build system, and CI to support compilation across multiple specialized hardware platforms, evolved the public SDK and integration model, built release and packaging infrastructure, drove telemetry and performance work, and led integration, adversarial validation, security review, and release efforts.

Agentic

Internally at AWS, our team has been held up as an example of an AI-forward engineering team moving at the pace these tools enable. I have contributed to that by using agents to dramatically increase my own output, while building the systems, harnesses, and tooling needed to keep that output trustworthy: agentic orchestration of fleet-scale end-to-end tests, microbenchmarks, review cycles, and validation.

Skills Used

agentic engineering, systems security, cryptography, SDK/API architecture, performance engineering, fuzzing, static analysis, CI/CD, reverse engineering, technical leadership, C++, Python, C, CMake, debugging, Windows kernel development, Windows internals, Linux


Google

Software Engineer, L5
Lead, Fuchsia OS Security Reviews

Oct 2021 - Jan 2023

I worked on the Fuchsia security team, where my primary work was reviewing design documents, RFCs, and source code to build threat models, identify security boundaries, quantify attack surface, locate vulnerabilities, recommend fixes or mitigations, and, in some cases, block insecure launches. I did this in partnership with development teams for everything from the Zircon kernel, down to the bootloader and drivers, all the way up to Google Assistant applications, and all across multiple networking stacks. In this job, I particularly aimed to identify systemic security issues so we could fix them at the source.

I took over technical leadership of reviews after a few months, where my focus narrowed to pairing, training, and delegating work to other members of the team as a means of growing our capacity and effectiveness.

In addition, I also wrote code for our package retrieval system, implemented new fuzzers for various codebases, and built an automated code scanning tool to help engineers and security reviewers in their day-to-day work. Further, I play tested the 2022 Google CTF and managed to score high while also being the first to solve a few challenges.

Skills Used

code auditing, fuzzing, vulnerability analysis, exploit development, operating system development, security engineering, filesystems, networking drivers, device drivers, bootloader and firmware security, syzkaller, Rust, C++, Python, Go, open source, leadership, communication


Blackberry/Cylance

Research Architect, Staff

Feb 2017 - Sept 2021

My first role at Cylance was researching, developing, and architecting advanced EDR technologies as part of the Office of the CTO initially, and as part of a dedicated research group later on. My job often found me temporarily embedded in existing teams, working with them to bring my prototypes into production. I occasionally led cross-company efforts with technology partners to drive development forward.

After the BlackBerry acquisition, I moved into a group working on DLP where I contributed multiple proof-of-concept technologies and guided the architecture for their implementation. I later moved to the IVY team where I was one of four architects responsible for designing the system and leading the development.

Patents

Secured Code Package for Browser Plugin
US11880451B2 · Filed Jan 2021 · Granted Jan 2024

Method and System for Data Object Identification in Vehicles
US12175772B2 · Filed April 2022 · Granted Dec 2024

Publications

Relocation Bonus: Attacking the Windows Loader Makes Analysts Switch Careers
DEFCON 26
Aug 2018 | Slides | Video | Code

Skills Used

Windows kernel development, file format analysis, malware analysis, machine learning, user mode hooking, filesystems, PE file format, Windows internals, security engineering, application security, web security, Web Extensions, nodejs, cryptography, reverse engineering, C++, C#, C, Python, JavaScript, SQL, cross-functional collaboration, leadership


Bromium

Senior Security Engineer

Jan 2014 - Feb 2017

Bromium's core technology pioneered using hardware-backed micro-virtualization to isolate untrusted applications. I worked on the malware analysis and detection systems around that platform, turning low-level execution events into behavioral detections, correlated security telemetry, and actionable threat intelligence.

My work spanned malware reverse engineering, vulnerability research, behavioral detection, event correlation, and analysis infrastructure. Major projects included refactoring our correlation engine, building a robust packer detection system, creating a framework for intercepting Java applet execution, and implementing the first version of our threat cloud. I also built internal offensive-security tooling, including an exploit framework that weaponized several CVEs for demos and product testing.

The role sat at the intersection of containment, runtime observability, reverse engineering, and detection: safely execute hostile code, understand what it does, and turn that behavior into useful security signals.

Publications

Attacking Packing: Captain Hook Beats Down on Peter Packer
DerbyCon 5.0
Hacker Halted
Sept 2015 | Video | Code

Skills Used

Windows kernel development, malware analysis, user mode hooking, PE file format, Windows internals, reverse engineering, exploit development, security research, C++, C#, C, Python, Lua, Java, SQL


XenoBot

Founder
Doer of All Things

Dec 2010 - Nov 2017

XenoBot is an autonomous agent that can intelligently play a specific video game. I started writing it at age 15, and turned it into a business in 2010 when I was 17. At its peak, it had nearly 2,000 paid monthly users.

Engineering

The core of XenoBot is written from scratch, and is comprised of a code hooking library, a hand-rolled GUI engine, a packet capturing interface, a packet spoofer, a process memory manipulation library, proprietary code and function call injection routines, a memory fingerprint scanner, and a Lua binding around the aforementioned components.

The Lua binding also interoperates with the higher-level functionality, including a multi-dimensional, trainable, modified A* search, a state-machine based actuation controller, and a game state ensemble which correlates data from memory, packets, and hooks in the game's graphics engine.

Sysadmin & Security

XenoBot was supported by a variety of services, including a landing webpage, a VBulletin-based forum, an email server, redundant licensing servers, redundant update servers, and various DDoS protection technologies. I implemented all of these things and kept them running, up-to-date, and secure.

A non-trivial amount of my time was spent preventing DDoS, hardening licensing code against cracks, monitoring for suspicious activity, and actively fighting attacks such as DDoS, credential stuffing, targeted spam, and attempted intrusions.

Executive Duties

Aside from building the software, I also had to handle payments, provide customer support, draw up work contracts, hire consultants, pay invoices, run advertising and marketing campaigns, manage the business and registration, purchase code signing certificates, and moderate a forum.

Skills Used

graph theory, control theory, search algorithms, reinforcement learning, automation, reverse engineering, game design, game AI, game hacking, graphics programming, UI programming, Windows internals, Apache, cPanel, Cloudflare, Linux, Postfix, VBulletin, C++, Lua, Assembly, C, php, JavaScript, CSS, HTML, Python, SQL, Visual Basic, developer relations, leadership, communication, entrepreneurship


Tech Safari

Programmer Analyst

July 2012 - Jan 2014

I worked on large-scale data processing systems operating over tens of millions of records at a time, with workloads running on machines with up to 128 CPU cores and a terabyte of RAM. I was responsible for transforming, matching, standardizing, and classifying large datasets, while also scheduling and running the jobs and delivering results against customer deadlines.

The work included a custom JIT-based grammatical pattern matching engine for names, dates, and addresses; phonetic deduplication using Soundex; geographic queries using orthodromic distance; and fuzzy column-wise matching using radix trees. I also built a transpiler that converted formally-written statistical models for classifying medical data into scripts for a proprietary processing language.

Because much of the data was medical, I also owned the operational side of moving and processing it securely, including encrypted transfers and HIPAA-compliant handling.

Skills Used

Distributed systems, algorithms, data structures, Linux administration, concurrency, cryptography, C++, Lua, Perl, Java, PostgreSQL


Additional Work

I can't help but hack, even in my spare time.

Talks

Game Runner 2049: The Battles Fought by King of the Replicants
DEFCON 26 Skytalks
Aug 2018

XenoScan: Scanning Memory Like a Boss
DEFCON 25
Aug 2017 | Slides | Video | Code

+1,000,000 -0: Cloning a Game Using Game Hacking and Terabytes of Data
DerbyCon 6.0
Sept 2016 | Slides | Video

The Hidden World of Game Hacking
HOPE X
July 2014 | Video

Ownage From Userland: Process Puppeteering
DerbyCon 3.0
Sept 2013 | Video