Group Purchasing
Group Purchasing

Jon Gorenflo

Principal InstructorInformation Security Consultant at Fundamental Security

Specialities

Offensive Operations

Connect with Jon

Jon Gorenflo

About Jon Gorenflo

Jon Gorenflo is the CEO of ATTACKD, a SANS Principal Instructor, and co-author of SEC560: Enterprise Penetration Testing. He also teaches SEC504: Hacker Tools, Techniques, and Incident Handling, bringing enterprise penetration testing, incident response, security architecture, and military information management experience into the classroom. His teaching is grounded in the work practitioners are expected to do after class: understand the target environment, test carefully, explain findings clearly, and connect offensive techniques to practical remediation.

Jon’s path into security started in a network administration role where security was supposed to be a small part of the job. It quickly became most of the work. Without a deep bench of internal security mentors, he learned by collaborating with teammates, taking SANS courses, and reading a lot of practitioner research. His later roles included penetration testing and application security testing at PNC, security architecture at L Brands, information management leadership in the U.S. Army Reserve, and consulting roles focused on enterprise security. Those experiences show up in the labs, where students work through reconnaissance, credential attacks, Active Directory, Azure and Entra ID, lateral movement, and post-exploitation using tools such as Nmap, Metasploit, Sliver, BloodHound, Impacket, and Mimikatz

Jon holds the GIAC Certified Incident Handler (GCIH), GIAC Penetration Tester(GPEN), GIAC Assessing and Auditing Wireless Networks (GAWN), GIAC Mobile Device Security Analyst (GMOB), GIAC Python Coder (GPYC), Certified Information Systems Security Professional (CISSP), and CompTIA Security+ certifications. He earned a Bachelor of Science in Network and Communications Management from DeVry University and an Associate of Science in Network Administration from Marion Technical College. Jon is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. Beyond SANS, he contributes to the community as Executive Director of Hackers Teaching Hackers, a hacker conference in Columbus, Ohio built around hands-on learning, villages, CTFs, talks, and knowledge-sharing.

Students describe Jon as an instructor who makes complex material easier to understand, reinforces concepts through labs, and brings professional experience into the room. That style fits his public motto: cybersecurity can feel overwhelming, so he “peddles hope.” By the end of the week, students should be able to plan and execute a structured penetration test, explain real risk in business terms, and connect technical findings to practical remediation. Outside cybersecurity, Jon enjoys 3D printing, investing, and breaking things (on purpose).

Qualifications Summary
  • Founder and CEO, ATTACKD
  • SANS Principal Instructor; Co-author of SEC560: Enterprise Penetration Testing
  • Certifications: GCIH, GPEN, GAWN, GMOB, CISSP, and Security+
  • Former penetration tester and application security testing manager at PNC
  • Former security architect at L Brands with experience across security architecture, penetration testing, and incident response
  • Executive Director, Hackers Teaching Hackers

Press & Media

More From Jon