James Leyte-Vidal
Principal Instructor
Specialities
Offensive Operations

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations

James is a Principal Engineer and Principal Instructor at SANS, where he maintains the Slingshot Linux distribution used by tens of thousands of students in some of SANS's most popular courses. Before joining SANS full time, he spent nearly two decades in information security at The Walt Disney Company doing "a little bit of everything," and he brings that enterprise perspective to his classroom, helping students understand how big companies work and think. "Students need to understand how to convey information and important topics in a way big companies understand," he says. James is co-author of SEC617: Wireless Penetration Testing and Ethical Hacking and SEC556: IoT Penetration Testing, teaches SEC401: Security Essentials and SEC504: Hacker Tools, Techniques, and Incident Handling, and is the author of Ethical Password Cracking (Packt, 2024). He has 20+ years in the information security field and holds 25+ security certifications, including GSE #209, CISSP, and numerous GIAC certifications.
James had his first taste of information security back in 2001 as an IT systems admin, when he faced his first malware outbreak. Working with a new security team and putting in long hours to resolve the situation left a strong impression on him. "I left that situation knowing what I wanted to do with my life," he says. A few years later James officially started his career in information security and has since worked across penetration testing, security architecture, security assessments, remediation, vulnerability management, compliance and privacy, business continuity, security program development and management, and incident response. At Disney, he served as lead security architect for MyMagic+, a business-wide effort that required securing everything from back-end infrastructure to the wristbands guests wore, and he led the rollout of GDPR compliance programs across the company's IT organization.
Through his work in this field, James saw the need for talented IT professionals, and that led him to teach for SANS. "In our industry, we face a perilous shortage of talented professionals, as well as a crisis to maintain our overworked, existing seasoned professionals," he says. "The high-quality training SANS offers addresses both needs." As a course author, James focuses on keeping hands-on labs current with how attackers actually operate, from updated hardware kits and broader platform support to AI-assisted testing workflows and new Bluetooth Low Energy fuzzing labs. In the classroom, he enjoys inspiring his students. "I cherish the opportunity to see someone in my class lock in, their eyes get wide and they realize that no matter how much they know or how talented they are, there is always more to learn. We are all lifelong learners, especially in infosec." James is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition.
Students describe James as engaging, knowledgeable, practical, and able to relate course material to real-world situations. Outside of SANS, James consults independently for startups and established organizations in technology, education, and energy, working on penetration testing, security architecture, compliance, and new product security. His guiding belief is that security exists to help the business do its job as securely as possible, not to simply say no, and he brings that mindset to every engagement and every class. Additionally, he writes about security, technology, family, and life on Medium. He has shared that he enjoys video games, running, movies, home improvement, and thinking about how psychology and neurodivergence shape the way people learn and work.
[James] is very engaging and knowledgeable. He retains the attention of the class and relates the content to real-life scenarios. Very enthusiastic!
[James'] style is very engaging and keeps things interesting.
[James] is fantastic.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
See how SEC556 and SEC617 have evolved with AI-assisted workflows, updated labs, revised hardware kits, and broader platform support—and learn which course fits your IoT or wireless testing goals.

AirSnitch introduces new attacks against client isolation and multi-SSID access points. SEC617 authors explain AirSnitch, its impact on Wi-Fi isolation controls, and what security teams should do next.

Discover the covert world of wireless network exploitation in our webcast on the "Nearest Neighbor Attack," as recently detailed by Volexity.

Review relevant educational resources made with contribution from this instructor.