Group Purchasing
Group Purchasing

Andy Smith

Certified InstructorHead of Security Architecture at Sage

Specialities

Cyber Defense

Andy Smith

About Andy Smith

Andy Smith helps defenders turn security architecture from a compliance task into a strategic advantage. As a Certified Instructor for the SANS Institute, he teaches SANS SEC530: Defensible Security Architecture and Engineering, guiding students to design secure, resilient systems that withstand complex real-world threats, giving professionals the confidence to champion architecture decisions within their organizations. In his current role as Head of Enterprise Security Architecture at Sage, Andy leads initiatives to embed scalable, reliable, and defensible security across customer-facing products, technology platforms, and internal IT services. His leadership experience helps students understand how architectural principles drive business resilience, Zero Trust maturity, and the secure integration of AI systems.

Before joining Sage, Andy spent 18 years at BP, progressing from IT Graduate to Principal Security Architect. Working there he designed strategies and operating models to secure emerging technologies, including AI and machine learning platforms, IoT, industrial control systems, blockchain, and multicloud environments. His work laid the architectural groundwork for scalable and accountable AI adoption, helping enterprises balance innovation with security assurance. He also served as BP’s Regional Information Security Officer for Europe and North America, balancing regulatory risk with the fast-moving transformation of the energy sector. Having spent two decades securing everything from energy infrastructure to global cloud ecosystems, Andy brings lessons forged in enterprises where security failures have real-world consequences.

Andy’s current research and community leadership extend deeply into AI security. As an entry lead and contributing author for the OWASP LLM Top 10, he helps shape the industry’s first open security standard for large language model applications. This work informs his teaching on securing AI integrations within modern enterprise architecture. His public talks and writing often explore the intersection of AI, architectural assurance, and practical risk management, helping defenders understand how to adapt trusted design principles to emerging technologies.

Andy’s approach blends technical mastery with architectural pragmatism. He holds advanced credentials including GIAC Defensible Security Architecture (GDSA), GIAC Defending Advanced Threats (GDAT), and Certified Cyber Risk Management Practitioner (CCRMP) certifications, alongside CISSP and CRISC. He earned a Master of Research in Security and Cryptography and a Bachelor of Engineering in Computers and Networks from the University of Essex. A frequent conference speaker, his recent publications include “How to Prepare for a Secure Post-Quantum Future” (TechTarget 2024) and “Taming the Chaotic Toddler: Threat Modeling LLM Apps” (SANS Amsterdam July 2025).

Students often describe Andy’s classes as the moment security architecture finally “clicked” for them. Known for his clarity, humor, and pragmatic teaching style, he ensures students leave class ready to apply what they have learned the very next day. He believes secure design starts with curiosity: the courage to ask why before deciding how. Outside of security, Andy enjoys outdoor activities, walking his dog, and DIY projects at home; outlets for the same curiosity and problem-solving instinct he brings to every class.

Qualifications Summary
  • Master of Research in Electronic Systems Engineering, Security and Cryptography, University of Essex
  • Bachelor of Engineering in Computers and Networks, University of Essex
  • SANS Certified Instructor, SEC530: Defensible Security Architecture & Engineering: Implementing Zero trust for Hybrid Enterprise
  • Head of Enterprise Security Architecture, Sage
  • Former Principal Security Architect, BP
  • Former Digital Security and Risk Officer, BP
  • GIAC Certifications: GDAT, GDSA, GCAD
  • CCRMP Certified
  • Entry Lead and Contributing Author for OWASP LLM Top 10

Press & Media