Jason Lam
Senior InstructorConsulting Practice Director at World Wide Technology
Specialities
Cloud Security, Cybersecurity Leadership

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCloud Security, Cybersecurity Leadership

Jason Lam is a Senior Instructor at the SANS Institute and seasoned global cybersecurity leader, currently applying his experience as a consulting practice director at World Wide Technology while teaching and authoring key courses. Previously Jason served as the regional CISO and cybersecurity head at MetLife and Head of Global Management at RBC. He is the author and instructor of LDR520: Emerging Trends for Cyber Leaders: AI and Cloud and SEC522: Application Security: Securing Web Apps, APIs, and Microservices, where he combines executive-level strategy with hands-on application security and cloud leadership.
Jason’s journey into cybersecurity began when, early in his career at an Internet service provider, he volunteered to assist after a major security incident, turning a moment of crisis into a lifelong dedication to defense. As he progressed into roles that spanned intrusion detection, penetration testing, incident response and global security programs, he previously served as manager of global threat operations in a regulated industry across 30+ countries. These experiences directly inform the labs in the course where students pivot from threat hunting to cloud-native architecture and business-aligned leadership decisions.
Jason Lam has taught sans courses I have attended in the past. He's always very informative and knowledgeable and presents material in a way that makes sense.
Jason was very informative and passionate about the material.
Jason is the best teacher I have ever had. Amazing that he could keep it interesting for 7 hours.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Enterprise AI is moving faster than security maturity. Learn how to identify AI-specific risks, secure models and data pipelines, and apply a lifecycle-driven MLSecOps approach to operationalize governance and resilience at scale.

This workshop is ideal for cloud security leaders, CISOs, and team managers who want to strengthen their leadership skills, align security strategies with business goals, and effectively manage cloud security programs.

This workshop supports content from SEC522: Application Security: Securing Web Applications, APIs, and Microservices

Cloud environments are attractive targets for hackers due to their complexity, which can make them difficult to defend. This presentation will cover three crucial strategy cloud security that can greatly impact your cloud's security posture.

In this session, we will guide you through the eight fundamental domains of cloud security in today's organizations. Our aim is to help you comprehend the key areas that need to be secured in the cloud.

Cloud environments are attractive targets for hackers due to their complexity, which can make them difficult to defend. This presentation will cover three crucial details of cloud setup that can greatly impact your cloud's security posture. We'll kick off by exposing common vulnerabilities that hackers exploit to compromise cloud environments. Then, we'll dive into effective mitigation strategies in three areas and show you how to implement them in a practical and hands-on manner. Our insights on mitigations will apply to typical enterprise cloud setups.

Review relevant educational resources made with contribution from this instructor.