John
Breton.
Engineer working on open-source security at Canonical, where Ubuntu is hardened, vulnerabilities are triaged, and complex disclosures are made legible for the community.
My work.
Canonical · Software Engineer I
- Applied AI tooling to the Ubuntu Security Notice pipeline, turning noisy vulnerability data and draft reports into clear, actionable disclosures for the open-source community.
- Authored and led comprehensive threat modeling for the Ubuntu Archive, enforcing strict SDLC principles and a "secure by default" posture for core open-source infrastructure.
- Refactored legacy Python tooling into concurrent CVE and security-notice processors, reducing execution time by more than 70%.
- Onboarded and mentored new team members into high-priority security engineering workflows.
Canonical · Associate Software Engineer
- Triaged, assessed and patched hundreds of CVEs across Ubuntu packages, maintaining rapid deployment and high compliance across supported releases.
- Developed QA tests for supported packages, improving coverage by ~10% while safeguarding stability.
- Spearheaded internal + public documentation, growing content by over 100% and building knowledge-base articles that now anchor Ubuntu's security workflows.
Carleton University · CyberSEA Research Assistant
- Designed and implemented a security analysis tool that raises the security posture of software system designs in the earliest stages of development.
- Authored and presented novel research on security metrics and threat detection at two leading cybersecurity conferences.
- Ran interactive problem-solving sessions for 20+ students covering risk assessment, access control models and network security.
Carleton University · Teaching Assistant
- Ran lab sessions and assessed coursework for five upper-year courses, including Network and Software Security, Algorithms, and Real-Time Concurrent Systems.
- Reviewed group projects and gave feedback on design patterns, concurrent programming and system security principles.
- Built and shared lab solutions and resources used across the teaching team.
Ericsson · 5G/LTE Software Developer Intern
- Built automated test cases in a Java framework to validate critical 5G and LTE functionalities.
- Led internal knowledge-sharing sessions introducing new test automation initiatives to the baseband team.
- Piloted a transition program for 50+ engineers, shifting manual testing toward automation and cutting LTE turnaround by 20%.
Empress Effects · Project Developer
- Designed, built and tested an open-source Python patch manager that has since passed 6,000+ downloads across releases.
- Collected user stories and authored the software requirements specification that drove development planning.
- Used PyQt to build a responsive desktop GUI with backend queries for real-time updates, distributing releases via GitHub.
My projects.
Nonogram 101
Picture nonograms you can solve alone or race through against 100 players at once. An installable React PWA that also ships as an Android app, with cookieless analytics and a theme that never flashes white on load.
TicTacBombs
A chaotic re-imagining of tic-tac-toe with bombs that reshape the board mid-game, built as a study in small-scope game design and turn-based state management.
Dubhe
The implementation behind my M.A.Sc. thesis. Dubhe reads UML activity diagrams and determines a system's behavioural security posture before a line of it is written.
ZOIA Librarian
Patch management for the Empress ZOIA pedal: a PyQt desktop app for browsing, organizing and syncing user-created patches. Started at Empress Effects, now community maintained, past 6,000 downloads.