Group Purchasing
Group Purchasing

David Hazar

Certified InstructorSecurity Consultant at HazarDSec LLC

Specialities

Cloud Security

Connect with David

David Hazar

About David Hazar

David Hazar is a Certified Instructor at the SANS Institute and Founder and Security Consultant at HazarDSec LLC. He works with organizations to improve and mature their security programs, focusing on the practical implementation, automation, and orchestration of existing technologies. As a co-author and instructor for SEC549: Cloud Security Architecture and SEC540: Cloud Native Security and DevSecOps Automation, he brings hands-on operational experience into the classroom.

David’s career trajectory is grounded in technical breadth: he began in municipal systems administration where he handled telephony, databases, domains and networks before moved into application security and vulnerability management. He previously served time with a top-tier security consulting firm, conducting enterprise assessments across startups to large enterprises, and helping embed DevOps and cloud-centric controls into development lifecycles. Those hands-on, messy real-world engagements directly shaped the labs and scenarios in the course, enabling students to simulate root-cause analysis, backlog reduction, and cloud-native architecture remediation in the labs.

He holds significant credentials including Certified Information Systems Security Professional (CISSP), Microsoft Certified Database Administrator (MCDBA), Microsoft Certified Professional (MCP) and 12 GIAC certifications. He is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. In addition to his course work, David has authored the SANS 2022 Vulnerability Management Survey whitepaper and frequently presents webinars and industry panels on vulnerability analytics and cloud risk.

In the classroom, David’s teaching philosophy is simple: vulnerability management may not be glamorous, but it is the foundation of all security. He emphasizes shifting focus from reactive patching to strategic problem-solving, helping students move beyond “identify and priorities” to ask, “what structural change prevents 90% of the backlog?” A consistent thread in student feedback is that his sessions “tie data to board-room stories” and “show real-world value from day one.” When he isn’t helping organizations reduce millions of open vulnerabilities, he’s skiing with his family, following his daughter’s high-school basketball games, or experimenting with a new recipe in the kitchen, bringing the same curiosity, discipline and human touch into every lab and lecture.

Qualifications Summary
  • Co-Founder and Chief Information Security Officer, Next Level3 Software; Certified Instructor, SANS Institute.
  • Certifications: Certified Information Systems Security Professional (CISSP); Microsoft Certified Database Administrator (MCDBA), Microsoft Certified Professional (MCP), ITIL v3 Foundation, and12 GIAC certifications including: GIAC Cloud Security Automation (GCSA), GIAC Cloud Threat Detection (GCTD), GIAC Cloud Security Architecture and Design (GCAD), GIAC Strategic Planning, Policy, and Leadership (GSTRT), GIAC Secure Software Programmer- .NET (GSSP-.NET), GIAC Certified Web Application Defender (GWEB), GIAC Certified Windows Security Administrator (GCWN), GIAC Certified UNIX Security Administrator (GCUX), GIAC Mobile Device Security Analyst (GMOB), GIAC Web Application Penetration Tester (GWAPT), GIAC Certified Incident Handler (GCIH), and GIAC Certified Intrusion Analyst (GCIA)
  • Key achievements: 20+ years of experience spanning developer, server/network admin, AppSec engineer, security consultant; helped one organization reduce its vulnerability backlog from 12 million to under 5 million.
  • Publications and tools: Author of the SANS 2022 Vulnerability Management Survey whitepaper; frequent industry presenter on root-cause VM analytics and cloud security automation.
  • Courses taught/authored: LDR516: Strategic Vulnerability and Threat Management; SEC549: Cloud Security Architecture; SEC540: Cloud Native Security and DevSecOps Automation.
  • Community/other roles: Faculty member, SANS Technology Institute; frequent speaker at UtahSec and other regional chapters; volunteer contributor to vulnerability management best-practice initiatives.

Press & Media