Group Purchasing
Group Purchasing

Josh Johnson

Certified InstructorInformation Security Professional

Specialities

Cyber Defense

Connect with Josh

Josh Johnson

About Josh Johnson

Every defender has faced the moment when an alert feels like a mystery and the stakes are high. Josh Johnson helps turn that uncertainty into action—driven by a belief that great defense isn’t about chasing alerts, but about empowering people to think critically under pressure. A SANS Certified Instructor, Josh teaches SEC530: Defensible Security Architecture and Engineering: Implementing Zero Trust for the Hybrid Enterprise, where he equips students to design resilient, layered defenses that thrive in complex environments.

His path from enterprise defender to architect taught him a simple truth: the best security designs come from those who’ve seen both sides of the fight. Over eight years in enterprise security, Josh advanced from Information Security Analyst to Architect, leading initiatives in detection engineering, incident response, and adversary simulation. That mix of offensive insight and defensive precision now shapes every lab, discussion, and design challenge in his SANS courses. Since 2016, as an independent information security professional, he has helped organizations operationalize automation, strengthen detection capabilities, and engineer defenses that stand up to real adversaries. Josh teaches defenders to see architecture not as static infrastructure, but as a living system—one they can shape, protect, and continuously improve. Students leave his class not just knowing how to design secure systems—they leave thinking differently about how to anticipate, disrupt, and outpace adversaries.

His technical depth is matched by his belief in lifelong learning. Josh holds a Master of Science in Information Security Engineering from the SANS Technology Institute and a Bachelor of Science in Computer Science (with a Business Management minor) from St. John Fisher University. He is a Certified Information Systems Security Professional (CISSP) and holds multiple GIAC credentials, including GIAC Security Expert (GSE), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), GIAC Web Application Penetration Tester (GWAPT), GIAC Certified Project Manager (GCPM), GIAC Certified Forensic Analyst (GCFA), GIAC Reverse Engineering Malware (GREM), and GIAC Defensible Security Architecture (GDSA). He is also the author of Finding Evil in the Whitelist, Implementing Active Defense Systems on Private Networks, and One Detect to Win: Tactical Network Detection.

He says his favorite moments in class aren’t when the slides advance—they’re when the lightbulb goes on, and a student leans back, smiles, and says, “I finally get it.” Known for his clarity, curiosity, and calm, Josh helps students connect knowledge with confidence through practice. One student described his class as “a blueprint for building smarter defenses.” Outside SANS, Josh contributes to open-source projects like Update-VMs, presents at conferences including DerbyCon, and shares practical insights through articles, community talks, and appearances such as the Blueprint Podcast episode “PowerShell for the Blue Team.” Whether leading a blue team or a classroom, his focus never changes: building defenders who think critically, act decisively, and lift each other up. He reminds every student that cybersecurity isn’t a solo sport—it’s a community built on curiosity, resilience, and trust—and his greatest satisfaction comes from seeing his students carry that mission forward.

Qualifications Summary

Press & Media