Christian Villapando
Certified Instructor CandidateSecurity Consultant at Red Rock IT Security Inc
Specialities
Offensive Operations

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations

Christian Villapando is a cybersecurity consultant at Red Rock IT Security Inc. and a SANS Certified Instructor Candidate who teaches SEC560: Enterprise Penetration Testing. With hands-on expertise in penetration testing, red teaming, and purple teaming, he brings real-world adversary tactics directly into the course, helping students understand how modern attacks are executed and how to defend enterprise environments against them.
Christian began his career supporting national cybersecurity efforts with the Philippines’ National Computer Emergency Response Team (CERT-PH), where he conducted vulnerability assessments and penetration testing on government systems. He later moved into consulting roles, including his time at Verizon, where he worked closely with enterprise clients to identify exploitable weaknesses and strengthen their security posture. Now at Red Rock IT Security, he leads and delivers offensive security engagements across industries such as finance, healthcare, and e-commerce. These real-world experiences directly inform the course labs, where students practice enterprise penetration testing techniques, simulate adversary behavior, and develop actionable remediation strategies.
He holds the Certified Information Systems Security Professional (CISSP) certification and multiple Global Information Assurance Certification (GIAC) credentials, including GIAC Penetration Tester (GPEN), GIAC Certified Incident Handler (GCIH), and GIAC Certified Intrusion Analyst (GCIA). He is also an Offensive Security Certified Professional (OSCP) and Offensive Security Experienced Penetration Tester (OSEP) and is recognized as a GIAC Security Expert (GSE #397). Christian earned a Master of Science in Information Security Engineering from the SANS Technology Institute and has contributed to cybersecurity education through university teaching roles and published research on improving Active Directory security posture.
In the classroom, Christian focuses on practical, hands-on learning, breaking down complex offensive techniques into clear, repeatable processes. His teaching philosophy emphasizes thinking like an attacker while acting as a defender, ensuring students leave with skills they can immediately apply in real-world environments. Outside of his consulting and teaching work, he remains active in academic instruction and mentorship, driven by a belief that education is one of the most effective ways to strengthen the global cybersecurity community. In his personal time, he maintains a regular CrossFit training routine, an intense discipline that demands technical execution, focus, and consistency, qualities he also applies in his cybersecurity work.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.