Jeroen Vandeleur
Certified Instructor CandidateTechnical Innovation Lead at NVISO
Specialities
Cloud Security, Offensive Operations, Artificial Intelligence

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCloud Security, Offensive Operations, Artificial Intelligence

Jeroen Vandeleur is a SANS Certified Instructor and co-author of SEC598: AI and Security Automation for Red, Blue, and Purple Teams, and serves as the Technical Innovation Lead at NVISO. In this role, he works alongside a team of domain experts to drive innovation across professional and managed security services, with a strong focus on operationalizing AI workflows within enterprises and building Agentic AI solutions to deliver enhanced Security Operations. His work centers on bridging strategy and execution, translating emerging AI capabilities into scalable, production-ready solutions for security operations. By designing and evolving managed detection and response (MDR), adversary emulation, and automation-driven services, Jeroen brings a unique, field-tested perspective to both his customers and his students. Every concept he teaches is grounded in real-world deployments, lessons learned, and the practical constraints of enterprise environments.
Jeroen’s career began in infrastructure and network-focused roles, where he developed a strong operational foundation. Over time, he expanded into application security, cloud security, incident response, and security monitoring across diverse enterprise environments. This evolution shaped his belief that security innovation must be both technically sound and operationally scalable, especially when integrating AI into detection, response, and decision-making workflows. Through his work, Jeroen actively explores how AI can enhance—not replace—security operations by enabling structured automation, improving reasoning within defined boundaries, and supporting analysts at scale. This philosophy is deeply embedded in SEC598, where students learn how to build resilient, AI-assisted workflows that align with real enterprise needs rather than experimental or isolated use cases.
Holding a bachelor’s degree in Information Management Systems, Jeroen has built broad expertise across security operations, cloud security, and security architecture. Jeroen Vandeleur is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. Beyond his role in industry and education, Jeroen contributes to the cybersecurity community through public speaking, technical content, and open-source initiatives such as PurpleCrew, an agentic AI framework focused on offensive and defensive security automation. His work consistently reflects a forward-looking vision: security teams that are augmented by AI, driven by automation, and designed for continuous adaptation.
In the classroom, Jeroen is known for his energetic and highly practical teaching style. He focuses on actionable techniques, real-world architectures, and repeatable workflows, enabling students to move beyond theory and immediately apply AI-driven security automation in their own environments. His combination of hands-on experience, strategic insight, and passion for innovation makes his courses both relevant and impactful for modern security practitioners.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
In this exclusive webcast, course authors Jeroen Vandeleur and Jason Ostrom unveil the groundbreaking updates to SEC598: AI and Security Automation for Red, Blue, and Purple Teams.

Adversary emulation stands as an indispensable cornerstone in the cybersecurity domain, empowering organizations to proactively evaluate and bolster their defensive capabilities against real-world threats. In this presentation, we delve into the practical application of adversary emulation, leveraging the robust Caldera open-source platform. This demonstration serves as a preview of one of the engaging labs featured in our cutting-edge course, SEC598: Security Automation for Offense, Defense, and Cloud.

Review relevant educational resources made with contribution from this instructor.