Group Purchasing
Group Purchasing

Luke Pearson

Certified Instructor CandidateDirector of Cyber Security at CSIRT

Luke Pearson

About Luke Pearson

Luke wants everyone to get better at the thing he loves most: running down an intruder in someone else's network. He is drawn to incident response because, unlike most of security, there is a live human on the other side of the keyboard. "Most of what we do in security is building walls and setting traps for things that might never come," he says. "Response is the one place you're up against an actual person who is trying to beat you, right now, in the moment. That's where the real fun is." His goal in the classroom is to turn skilled responders into people who can lead that fight — calm, methodical, and a step ahead of the adversary.

Luke's teaching focus is the discipline of the investigation itself: how to form a hypothesis, test it against the evidence, and keep a complex response coordinated when the pressure is on and the facts are still moving. He wants students to think clearly about what they are actually seeing before they act on it, to resist the pull of the obvious answer, and to understand that leading an intrusion response is as much about running the team and the timeline as it is about reading the artifacts. That same curiosity drives his research: Luke actively studies how to improve the practice of intrusion investigation and response, and feeds what he learns straight back into how he teaches it. At SANS he is the lead author of the upcoming FOR538, a course on taking ownership of the technical investigation and leading sophisticated intrusions from first detection through full eradication.

That focus comes from more than a decade of doing the work across government, consulting, and global enterprise. Luke led cyber security operations for Queensland's emergency services agencies, built a Security Operations Centre from the ground up in Australia, and spent nearly three years as a Senior Consultant with Mandiant, where he ran the most complex incident response engagements for APAC clients and became the person colleagues turned to for any problem that didn't fit an existing process. He is now Director of Cyber Security for the Computer Security Incident Response Team (CSIRT) at a major global SaaS provider, leading APAC and global incident response for one of the world's largest enterprise platforms. There he rebuilt the CSIRT hiring pipeline, cutting time-to-autonomy for new hires from three months to three weeks, and designed a triage process that brought median time-to-contain in the highest-risk environments down from twelve days to under forty minutes.

Luke holds the GIAC Security Expert (GSE #358), one of the most demanding credentials in the field, along with more than twenty GIAC certifications spanning incident response, forensics, intrusion analysis, penetration testing, and security leadership, including the GEIR, GX-FA, GX-IH, GX-IA, GCFA, GNFA, GCFR, GCIL, and GSTRT. He holds a Master's in Cyber Security from Charles Sturt University and the CISSP, and serves on GIAC advisory boards. He is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. Luke writes about incident response, foundational skills, and the place of AI in security work at his blog, This Insecure World, and has presented at Black Hat Asia, BSides Brisbane, ChCon, and AvengerCon, and in SANS webcasts.

Away from the keyboard, Luke reads widely (with a heavy emphasis on fantasy), plays video games, and spends his time with family.

Qualifications Summary
  • Certified Instructor Candidate; Director of Cyber Security, CSIRT at a major global SaaS provider
  • GIAC Security Expert (GSE #358)
  • 20+ GIAC certifications across DFIR, intrusion analysis, penetration testing, and security leadership
  • CISSP; Master's in Cyber Security, Charles Sturt University
  • Author of the upcoming FOR538
  • Faculty member, SANS Technology Institute
  • Former Senior Consultant (Incident Response), Mandiant
  • Writes at This Insecure World;
  • Speaker at multiple conferences including Black Hat Asia, BSides Brisbane, ChCon, and AvengerCon