Josh Lemon
Principal InstructorChief Digital Forensics and Incident Response Investigator at SoteriaSec
Specialities
Digital Forensics and Incident Response, Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response, Cloud Security

Today, as Director of the global Managed Detection and Response team at Uptycs, Josh helps to protect some of the largest international brands from cyberattacks. In addition to his role at Uptycs, Josh also works as an independent digital forensics and incident response expert in Australia, providing advice to legal, government, and commercial clients. Further to his technical expertise, Josh is the co-author for the FOR509: Enterprise Cloud Forensics and Incident Response course, and the SANS DFIR NetWars tournaments. Josh also teaches the SANS FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics, and the FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response courses. Josh holds several certifications, including GCFA, GCIH, GNFA, GPEN, GDAT, GPYC, and GREM.
With a keen interest in both computers and investigative work and a passion for teaching those around him, Josh Lemon is perfectly fit for his cybersecurity and incident response job and his role as a SANS instructor. In the years before cybersecurity roles were the norm, Josh started out building, managing, and securing large, complex computer networks and software systems. He worked in various fields providing incident response, digital forensics, and penetration testing services to government, law enforcement, and the commercial sector before eventually taking on a full-time incident response role. "I took the chance and never looked back," he says.
Before his current role, Josh was a Managing Director at Ankura, leading Ankura's APAC Digital Forensics and Incident Response practice where he assisted government and commercial clients with investigating sophisticated compromises, maturing their cyber defence and response programs and threat hunting for malicious adversaries. Josh has also been a Director at Salesforce.com in their international Salesforce Security Response Centre (SSRC). He led the Strategic Response and Research Unit responsible for looking at new cutting-edge techniques for incident response at scale. He was also the CSIRT Manager for the Commonwealth Bank of Australia, where he built a team of advanced responders that investigated malicious security incidents for local and international operations. Before that, he worked as a Managing Consultant for BAE Systems Applied Intelligence, where he was responsible for all technical cybersecurity services for the Asia Pacific region, including overseeing large and complex incident response and offensive security engagements.
Josh stays busy co-authoring two SANS courses: FOR509: Enterprise Cloud Forensics and Incident Response course, and the SANS DFIR NetWars content. When he’s not busy writing content, he also teaches both the classes he has co-author for, along with the FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics and FOR572: Advanced Network Forensics: Threat Hunting, Analysis, and Incident Response classes. He also currently serves as an Advisory Board Member to Cydarm Technologies, a young Australian company making collaboration for incident response easier.
Josh says that even with all the different roles he's held, every job has included a component of teaching others. Josh's teaching skills are so evident that a former manager and SANS principal instructor encouraged him to explore an instructor role after observing Josh teaching his clients during his time as a consultant.
The SANS curriculum is a perfect fit from Josh's perspective. "One of the reasons I enjoy teaching for SANS is their DFIR courses are continually updated and tuned to include the most current techniques seen in the wild," says Josh. "I always want to make sure my students are armed with the most up-to-date information to uncover attacks and be able to investigate them efficiently." When it comes to developing and authoring classes, Josh says “having spent time teaching for SANS, I’m incredibly excited to be able to author content and have input into the skills that students learn”, Josh goes on to say, “being able to share what I’ve learnt in the field and know that students can take those techniques to catch threat actors is incredibly rewarding”.
In the classroom, Josh sees the extensive amount of highly technical information students must consume over the span of only six days as the biggest challenge for his students. "It can be overwhelming for new students and seasoned professionals alike", he says. To address this, Josh keeps students focused on the elements they can start using as soon as class ends. "I always leave students with more information to read in the future and encourage them to start keeping a file of 'interesting things to read about later,'" he says.
In addition to his work with students, a highlight of Josh's career has been seeing his cases in court. "While the results of court cases are always different, being able to find enough evidence to successfully determine who the malicious actor is behind the keyboard and see law enforcement carry out their work has been a huge highlight for me," says Josh. "It's rare that DFIR professionals ever get to put a face to someone conducting malicious activity, however, finally seeing a criminal in court or law enforcement carry out a warrant brings a large sense of closure to an investigation you've worked hard on."
Josh also has a deep interest in operational efficiency for teams and is continually working to understand how to improve the work environment for DFIR professionals. "The challenges and stresses of doing DFIR work are fairly unique, and that's usually why we see DFIR professionals only spend approximately two years at the cold face of chasing malicious actors around networks," he says. "Understanding how to make that environment better for our industry has been an interest of mine ever since I started managing teams of people."
Josh's current work on tools, technologies, techniques, and automating IR processes has allowed him to see IR and SOC teams become more efficient, motivated, and focused on their operational IR work, rather than trying to struggle with tools that aren't well suited to DFIR work.
When he's not helping his clients, students, or chasing malicious actors around a computer network, Josh stays busy in his role as Dad, spending time with his son and close family.
Joshua Lemon is amazing. He has the professional experience to significantly enhance and supplement course content, and modernizes all of his examples and information so that the course is immediately relevant to my job.
The course was very interesting and very well presented. Josh gave fantastic explanations and examples.
Great delivery! Josh has great knowledge all about the topic.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Now in its third year, this independent, vendor-neutral survey captures both a snapshot and a trendline—offering critical insights into what’s working, what’s lagging, and where the industry is heading. Join us as we break down the results and uncover how real-world teams are cutting through noise to focus on signals that matter.

Threat hunting is no longer just a niche skill—it’s a critical pillar of modern defense.

Join Josh and Phill as they discuss the latest trends, practical use cases, and the challenges of integrating AI into modern DFIR workflows.

The SANS 2025 Detection and Response Survey webcast will delve into the current state of cybersecurity operations, questioning whether the heavy emphasis on endpoint detection is creating new blind spots.

On this webcast, SANS Principal Instructor Josh Lemon will delve into results from the SANS 2025 Threat Hunting Survey.

On this webcast, SANS Certified Instructor Josh Lemon will provide insights into the prevalence of organisations maintaining separate detection and response teams, shedding light on the reasons behind such decisions and their implications for overall security posture.

In the age of artificial intelligence (AI) and ever-evolving cyber threats, the landscape of security operations has witnessed a transformative shift. Our 2024 Detection & Response Survey delves into how organizations address critical aspects of detection, response, and the integration of these vital functions within organizations. On this webcast, SANS Certified Instructor Josh Lemon will provide insights into the prevalence of organizations maintaining separate detection and response teams, shedding light on the reasons behind such decisions and their implications for overall security posture.

On this webcast, SANS Certified Instructor Josh Lemon will provide insights into the prevalence of organizations maintaining separate detection and response teams, shedding light on the reasons behind such decisions and their implications for overall security posture.

人工知能(AI)と進化し続けるサイバー脅威の時代において、セキュリティ運用の状況は変化しています。検知とレスポンスに関する調査(2024年)では、検知、対応、およびこれらの重要な機能の組織内での統合の重要な側面について、組織がどのように取り組んでいるかを掘り下げています。この講演では、SANS インストラクターのJosh Lemonが、組織が検出チームと対応チームを別々に維持していることの普及に関する洞察を提供し、そのような決定の背後にある理由と全体的なセキュリティ態勢への影響に光を当てます。

デジタルフォレンジック&インシデントレスポンス(DFIR)の素晴らしい新世界へようこそ! 人工知能(AI)は私たちの町に新しく配属された保安官であり、ハッカソン中のカフェイン中毒のプログラマーのようにいろいろなことをスピードアップさせることができます。

Welcome to the brave new world of Digital Forensics and Incident Response (DFIR), where Artificial Intelligence (AI) is the new sheriff in town, ready to speed things up like a caffeine-addicted programmer during a hackathon.

In recent years, the cyber threat landscape has evolved significantly, blurring the lines between tactics, techniques, and procedures (TTPs) used by cybercrime and nation-state-sponsored attacks. On this webcast, SANS certified instructors Mat Fuchs and Josh Lemon will explore results of our 2024 Threat Hunting Survey, and reveal how organizations are changing their proactive hunting activities and their use of hunting for unusual patterns, behaviors, and artifacts within network traffic and endpoints to catch threat actors who continually try to side-step detections. Register for this webcast now, and you will automatically receive the companion white paper upon publication.

There is a common tug-of-war between SOC staff, detection engineers and CSIRT/DFIR professionals when determining how important or severe an alert or detection is. Detection engineers are continually pushed to find new and creative ways of catching threat actors, whereas SOC and CSIRT staff are on the receiving end of triaging alerts and actioning them.

There is a common tug-of-war between SOC staff, detection engineers and CSIRT/DFIR professionals when determining how important or severe an alert or detection is.

As vendors develop new software or tools for threat hunting, we need to remember that threat hunting is predominantly a human-based activity in looking for incidents that our automated tools have not yet found, or cannot yet detect. This year, our survey will focus on the hunters themselves and how their organizations support threat hunting. Are hunters asked to complete multiple tasks at once? How much focus is given to threat hunting compared with other cybersecurity tasks? We look further at the skills that threat hunters must hone as that are just starting out, to skillsets of those who have been hunting for many years. We again will compare year-on-year trends to see how organizations have shifted their perspectives on threat hunting.

データの保管場所や方法が変わると、そのデータに関するフォレンジックが不要になったという思い込みが生じることがあるようです。しかしクラウドでは、オンプレミスの環境では存在しない新しいデジタルフォレンジックのケイパビリティや奥の深さが存在します。ただしクラウド環境における証拠保全のための正しい設定やセットアップの方法を理解しておく必要があります。

Review relevant educational resources made with contribution from this instructor.