Luke Ericksen Software engineer. Security background. Automation habit.
I build software in TypeScript and NestJS, and I run it in production. Four years in security and IT operations taught me how it breaks.
// condensed from rs-api-portfolio async canActivate(ctx: ExecutionContext) { const token = bearerToken(ctx); if (!token) throw statusError(401, 'Unauthorized'); const user = this.tokens.verifyAccessToken(token); if (!isSiteKey(user.roles)) { const account = await this.loadAccount(user.id); // revoked by logout if (account?.token_version !== user.tv) throw statusError(401, 'Unauthorized'); } if (!canAccess(user.roles, method(ctx))) throw statusError(403, 'Forbidden'); return true; }
Security taught me how systems break.
Now I build them.
Most of what I’ve built replaces a manual process: imaging machines one at a time, pulling threat indicators out of reports by hand, running a league’s operations in spreadsheets.
I came to software through systems administration and security operations, so I build with failure in mind: validate every input, authenticate before authorizing, and roll back anything that would leave data in a bad state.

Luke Ericksen
- based
- Richmond, VA
- focus
- Software engineering
- background
- Cybersecurity
- status
- Open to work
Where I've worked.
Building the league platform for an established competitive league on NestJS, Prisma and PostgreSQL, in alpha against real stakeholder deadlines.
Designed, shipped and operated a production esports platform across seven competitive seasons, serving 7,100 users with no unplanned downtime.
Detection engineering and threat hunting across a Fortune 500 enterprise, plus the ingestion pipeline and API integrations that fed the SIEM.
Network and endpoint security assessments across client environments, with hardening and remediation recommendations.
Windows, networking and security infrastructure across 90+ client environments, including a PXE imaging server and Proxmox lab builds.
What I've built.
Projects I build or lead, from schema to deploy.
League management platform for an established competitive league, replacing spreadsheet operations with a database-driven system built against stakeholder deadlines.
Platform for a competitive Rocket League circuit, with one NestJS API at the center: written to by a Discord bot and read by a Nuxt site across seven seasons.
Content blocker for Chromium browsers. Ten community filter lists compile to about 130,000 Manifest V3 rules at build time, and the lists ship inside the extension. It has no server behind it and asks for nothing but a daily check for a new release.
Threat Intelligence Ingestion Pipeline
case studyIndicators used to be pulled out of PDF, Excel, CSV and JSON reports and entered by hand. The pipeline parsed and normalized those inconsistently formatted reports and onboarded the indicators into a SIEM as detection-ready content.
Community project with a small group of developers: one player profile across games, replay stats, scrim finding and events.
Where I studied.
The formal half of how I got here.

What I reach for.
The tools I actually use, grouped by where they fit.
- TypeScript
- JavaScript
- Python
- PowerShell
- SQL
- Node.jsNestJS
- Next.jsReact
- NuxtVue
- REST APIsPrisma
- PostgreSQLMySQLMariaDB
- JWTOAuthRBAC
- DockerLinuxProxmox
- PM2
- GitHub Actions
- AWS S3IAMEntra ID
- CloudflareDigitalOcean
- Detection Engineering
- SIEMSplunkElasticsearch
- EDR/XDRLog Analysis
- Threat Hunting
- MITRE ATT&CKIncident Response





