Karim Lalji
Certified Instructor
Specialities
Offensive Operations, Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations, Cloud Security

Karim Lalji is a SANS Certified Instructor and co-author of SEC665: Advanced Red Team Operations, as well as an instructor for SEC565: Red Team Operations and Adversary Emulation and SEC588: Cloud Penetration Testing. He currently serves as a Principal Adversarial Engineer at Okta, where he leads adversary simulation campaigns and offensive security research to strengthen detection and response capabilities. With more than 15 years of experience, Karim brings real-world expertise from leading red, purple, and adversary simulation teams across complex enterprise environments.
He previously served in leadership roles at Accenture and TELUS, where he led large-scale offensive security consulting practices across North America, overseeing penetration testing, red team, and adversary simulation engagements across the globe. His work has supported organizations across federal governments, financial services, law enforcement, and Fortune 500 sectors, shaping the practical, real-world scenarios reflected in the courses he teaches.
He holds multiple industry-leading certifications, including the GIAC Security Expert (GSE), and has earned ten GIAC certifications spanning penetration testing, cloud security, intrusion analysis, and management. Karim is also a graduate of the Master of Science in Information Security Engineering (MSISE) program at the SANS Technology Institute. He is also a faculty member of the SANS Technology Institute—an NSA Center of Academic Excellence in Cyber Defense, and a multi-year winner of the National Cyber League competition.
In the classroom, Karim is known for his practical, experience-driven teaching style, translating complex offensive security concepts into actionable skills. Drawing from years of real-world engagements, he equips students to think like adversaries and apply techniques immediately.
Karim is an exceptional instructor, blending deep technical insights with engaging delivery. His mastery in Cloud Pen Testing is unparalleled, making complex topics accessible and intriguing. Highly recommended!
One of the best I had! very nice way to present and knows his stuff.
Karim is very knowledgable and has stacks of practical experience. He has all the time in the world for questions, paces the course well and made a long hard course very digestible. A great assest to SANS.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
Get deeper with WinDbg in this advanced session for offensive researchers. Explore dx, variables, custom functions, memory editing, extensions, and live user- and kernel-mode debugging to build confidence for SEC665-level red team work.

Many organizations have progressed to increasingly cloud heavy infrastructures, changing the game for security professionals of all stripes. While identity attacks have existed for a long time, it was primarily used as the first step in the path to initial access into a secured network.
