Bryce Galbraith
Principal InstructorFreelance Consultant at Layered Security
Specialities
Offensive Operations

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations

Bryce Galbraith is a SANS Principal Instructor who teaches multiple SANS courses, including SANS’s flagship courses SEC504: Hacker Tools, Techniques, and Incident Handling, SEC599: Defeating Advanced Adversaries - Purple Team Tactics & Kill Chain Defenses, and SEC699: Advanced Purple Teaming - Adversary Emulation & Detection Engineering, where he equips security professionals with the skills to detect, emulate, and defend against sophisticated adversaries. In addition to his role with SANS, Bryce provides consulting services through Layered Security, supporting organizations aggressively targeted by nation-state actors. Heavily focused on adversary engagement operations, aligning deception strategies, detection engineering, and defensive operations with frameworks such as MITRE Engage to better observe, influence, and disrupt adversary behavior.
Bryce’s career began in the early days of enterprise network security, working with Internet service providers and Fortune 500 companies before moving into senior engineering roles focused on large-scale infrastructure security. He later joined Foundstone as a Senior consultant and instructor, where he contributed to one of the industry’s seminal hands-on ethical hacking training programs. These experiences shaped his deep expertise in penetration testing, adversary simulation, adversary engagement operations, and enterprise defense, which directly inform the real-world scenarios and methodologies embedded throughout the course labs.
Bryce holds numerous certifications spanning a variety of cybersecurity topics. He is a contributing author to the internationally recognized book, “Hacking Exposed: Network Security Secrets & Solutions", a foundational text in the cybersecurity field, as well as “Offensive Countermeasures: The Art of Active Defense,” which helps organizations defend against some of the most advanced adversaries in operation today. His work spans decades of hands-on research and instruction, helping define modern approaches to ethical hacking and defensive operations. Bryce Galbraith is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition.
In the classroom, Bryce is known for his practical, adversary-focused teaching style and his ability to translate complex attack techniques into effective defensive strategies. Students consistently value the realism of his lectures and the direct applicability of the skills they develop, and his meme game! Outside the classroom, Bryce is a full-time digital nomad with millions of miles logged working in and exploring nearly 50 countries.
The disciplines/skills taught in SEC501 were exactly what my career and team needed to mature our SOC. Bryce Galbraith was an amazing, extremely knowledgeable instructor who kept all of the material interesting and fun.
Bryce Galbraith's real-world examples in SEC599 have been excellent and will be extremely useful in convincing executive boards and security teams to spend the necessary resources on implementing some of these controls.
Bryce Galbraith is obviously very experienced, as his knowledge is extremely in-depth. His delivery of SEC599 is thorough and easy to follow, and he adds a lot of good real-world examples to make it even more interesting.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Attackers are constantly finding new ways to evade endpoint defenses. Join Bryce Galbraith on 8 July, 5–6 PM, to learn how these techniques work and how to defend against them.

This talk explores the emerging landscape of AI-driven cyber threats and argues that organizations must defend at the speed of AI to survive.

This talk explores the emerging landscape of AI-driven cyber threats and argues that organizations must defend at the speed of AI to survive.
