Don Murdoch
Certified InstructorCyber Defense Principal at Kaiser Permanente
Specialities
Cyber Defense

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCyber Defense

Don Murdoch helps defenders turn complex security principles into practical, repeatable architectures that hold up under real-world pressure. A Certified Instructor with the SANS Institute, he teaches SEC530: Defensible Security Architecture and Engineering – Implementing Zero Trust for the Hybrid Enterprise, guiding students to design resilient systems, strengthen detection, and communicate defense strategy with confidence. Students learn to think like architects and communicate like leaders—building defenses that are both technically sound and strategically aligned.
With more than two decades in cybersecurity, Don has led teams and built programs spanning education, healthcare, and global enterprise. He began in software development and network operations before serving as Information Systems Security Officer at Old Dominion University, where he implemented the institution’s first SIEM and internal honeynet for detection and active mitigation. He later directed strategy and planning for a Fortune 500 healthcare organization, led a managed SOC practice, and served as Director of Security and Risk for RSA Security’s NetWitness Division. Each chapter of his career reinforces his belief that defense is strongest when people, process, and technology work in harmony. Today, as Cyber Defense Principal and lead countermeasures expert at atop 10 hospital system, he drives architecture and detection programs that directly inform the course labs students experience.
Don holds the GIAC Security Expert (GSE #99) designation and multiple advanced certifications, including GIAC Python Coder (GPYC), GIAC Reverse Engineering Malware (GREM), GIAC Defending Advanced Threats (GDAT), GIAC Defensible Security Architecture (GDSA), GIAC Web Application Penetration Tester (GWAPT), GIAC Network Forensic Analyst (GNFA), and GIAC Continuous Monitoring (GMON). He earned both a Master’s Degree in Information Security Engineering and a Graduate Certificate in Cloud Security and Computer Systems Networking and Telecommunications from the SANS Technology Institute, and serves on the SANS Advisory Board. He is the author of the acclaimed Blue Team Handbook series—Incident Response Edition and SOC, SIEM, and Threat Hunting Use Cases—written to give defenders concise, field-tested guidance when clarity matters most. The practices he’s developed have influenced SOC and detection teams worldwide.
In class, Don is known for his direct style, humor, and ability to make complex architecture approachable by sharing real-world examples that amplify the course material. He encourages curiosity and hands-on experimentation, teaching defenders to analyze clearly, act decisively, and adapt faster than their adversaries. For Don, success in cybersecurity isn’t just technical—it’s the confidence to face complexity, simplify it, and teach others to do the same.
Don was exceptional! His expertise, clarity, and enthusiasm made the course engaging and enjoyable.
Don is very knowledgeable and continued to do a very good job of incorporating his own experiences in the course as appropriate. I found this approach to be very beneficial.
His real world experience is mind-blowing. To take part in all the things he's done and all the investigations and setups he's worked on is impressive and it helps me understand the content that much more.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Review relevant educational resources made with contribution from this instructor.