About
Lucas Rose-Winters
Security engineering, formal verification and operating systems.
Security engineer, based in Launceston, Tasmania, and Melbourne. Five years in security: penetration testing at CyberCX, detection engineering at Movember and SecurITon, application security at EnergyAustralia.
Since 2025, full-time research and development under the name Sanguine Host: formal verification, operating systems, programming languages and AI architecture, with occasional contract work for AI training companies. Current projects, in Rust, Lean 4 and Slang, are on the work page. Open to contract and consulting work. Contact lucas@sanguinehost.com or on LinkedIn.
Experience
- Jun 2025 – now
Independent research and development · Sanguine Host
Full-time research and development: a Rust algebra library with Lean refinements, an operating system and language built up from assembly, and simulation and game systems on the same basis. Occasional contract work through Upwork, mostly data work for AI training companies.
- Feb – May 2026
AI Trainer and Reviewer · Alignerr (contract)
Wrote and graded coding tasks used to train coding agents at frontier labs. Promoted from tasker to reviewer, auditing other contributors' submissions for correctness and rubric compliance until the project closed.
- Oct 2023 – May 2025
Application Security Engineer · EnergyAustralia
Helped set up application security as a function. Root cause analysis on security incidents, cloud security engineering, CI/CD work, and aggregating and reporting vulnerabilities. PCI DSS scope.
- Apr – Oct 2023
Security Engineer · Movember
Rolled out Microsoft Sentinel with custom detection rules and automated response. Connected Tenable to Jira in Python so vulnerabilities became tickets without anyone copying them. Handled every security ticket in the environment.
- Nov 2022 – Apr 2023
Cloud Engineer · SecurITon Technologies
Secured hybrid cloud environments and assessed them against industry baselines. Deployed FortiSIEM monitoring with custom detection rules, and met IRAP compliance standards.
- Nov 2021 – Nov 2022
Security Consultant · CyberCX
Penetration testing for clients across Australia. Mostly web applications (XSS, IDOR), server and infrastructure misconfiguration, and vulnerable dependencies, Log4Shell included.
- Mar – Sep 2020
IT Support Officer · Database Consultants Australia
Ran vulnerability scanning for PCI DSS compliance, worked breach incidents alongside security specialists, and wrote the documentation for secure remote work.