Group Purchasing
Group Purchasing

Jorge Orchilles

Principal InstructorSenior Director, Readiness and Proactive Security at Verizon

Specialities

Offensive Operations

Jorge Orchilles

About Jorge Orchilles

Jorge Orchilles is a SANS Principal Instructor, course author, and cybersecurity executive who leads Readiness and Proactive Security at Verizon, overseeing Exposure and Vulnerability Management, Penetration Testing, Red Team, Purple Team, and AI Red Team functions. He co-authored, in the past, SEC565: Red Team Operations and Adversary Emulation and teaches courses spanning adversary emulation, purple teaming, penetration testing, and incident response across the SANS curriculum. His ability to connect enterprise-scale security operations with hands-on adversary emulation gives students a practical understanding of how offensive security programs operate in mature organizations and how red team activities translate into measurable defensive improvements. 

Jorge's career began in systems administration and enterprise IT before progressing into vulnerability management, penetration testing, and offensive security leadership. He holds a Bachelor of Business Administration and a Master of Science in Management Information Systems from Florida International University, as well as advanced computer security studies from Stanford University, combining technical expertise with the business and leadership perspective required to build and mature large-scale security programs. Previously, Orchilles led Citi's offensive security organization for more than a decade, building and managing advanced penetration testing and vulnerability assessment programs across a global financial institution. He later served as Chief Technology Officer at SCYTHE, helping organizations operationalize adversary emulation and purple team programs. These experiences directly shape the course labs and methodologies he teaches, where students learn not only technical tradecraft but also how offensive operations fit within larger security programs and risk-management objectives.

Jorge holds numerous industry certifications, including the GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Defending Advanced Threats (GDAT), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Penetration Tester (GPEN), GIAC Certified Forensic Analyst (GCFA), and GIAC Certified Incident Handler (GCIH), among other credentials. He is the creator of the C2 Matrix, a widely used community resource for evaluating command-and-control frameworks, and the author of the Purple Team Exercise Framework, an open-source methodology used by organizations to structure adversary emulation and collaborative security exercises. He has contributed to MITRE ATT&CK, MITRE ATLAS, Atomic Red Team, CVSS v3.1, and the MITRE Engenuity Center for Threat-Informed Defense. Jorge is also the author of Microsoft Windows 7 Administrator's Reference and a Fellow of both the Information Systems Security Association (ISSA) and the National Security Institute. Orchilles is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition.

In the classroom, Jorge is known for translating complex offensive security concepts into repeatable processes that students can immediately apply. Learners consistently highlight his willingness to answer questions, provide real-world context, and ensure students understand both the technical details and operational purpose behind the exercises. By week's end, students are better prepared to emulate adversaries, validate detections, assess security controls, and communicate findings in a way that helps organizations improve resilience. Outside of cybersecurity, Jorge enjoys watching and playing soccer and remains deeply involved in the security community through open-source projects, conference presentations, and industry collaboration.

Qualifications Summary
  • Senior Director, Verizon; Readiness and Proactive Security
  • SANS Principal Instructor; previous co-author of SEC565: Red Team Operations and Adversary Emulation, and Instructor for SEC699, SEC565, SEC560, SEC504, and other advanced SANS courses
  • Certifications: GXPN, GDAT, CISSP, CISM, GPEN, GCFA, GCIH, GICSP, GSEC, CEH, CICP, Security+, CCDA, CSSDS, MCTS (70-620, 70-282, 70-284, and 70-228)
  • Former Chief Technology Officer at SCYTHE and former leader of Citi's offensive security program
  • Creator of the C2 Matrix and author of the Purple Team Exercise Framework
  • Contributor to MITRE ATT&CK, Atomic Red Team, CVSS v3.1, and founding member of the MITRE Engenuity Center for Threat-Informed Defense
  • Fellow of the Information Systems Security Association (ISSA) and National Security Institute

Press & Media

More From Jorge