Megan Roddie-Fonseca
Certified InstructorSenior Security Engineer at Datadog
Specialities
Cloud Security, Digital Forensics and Incident Response

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCloud Security, Digital Forensics and Incident Response

Megan Roddie-Fonseca is a cybersecurity professional and SANS Certified Instructor recognized for her expertise in digital forensics, threat hunting, cloud investigations, and detection engineering. She currently serves as a Senior Security Engineer at Datadog, where she advances cloud-forensics practices and develops practical detection systems. With a reputation for blending technical depth with accessibility, Megan is both a practitioner and an educator dedicated to strengthening the cybersecurity community.
Megan’s academic journey began early, enrolling in college at 14 while completing high school. By 21, she had earned a bachelor's degree in mathematics and a master’s degree in digital forensics from Sam Houston State University. Her passion for security was sparked through an internship at the Texas Department of Public Safety, which led to SOC, IR, and threat-intelligence roles at Recon InfoSec and IBM Security X-Force. She later advanced into senior engineering positions at IBM and Datadog. Megan went on to complete a second master’s degree in Information Security Engineering at the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multi-year winner of the National Cyber League competition, where she now serves as a faculty member.
As co-author of SANS FOR509: Enterprise Cloud Forensics and Incident Response, Megan draws on her experience at Datadog and IBM X-Force to shape the course’s hands-on labs and investigative scenarios. Her background in cloud forensics and detection engineering informs modules on AWS, Azure, and Google Workspace investigations, while her incident-response work against nation-state and cybercrime activity ensures students practice techniques that reflect challenges they will face in real-world enterprise environments. She is also the author of Practical Threat Detection Engineering. Beyond her professional and academic roles, Megan serves as CFO of Mental Health Hackers, where she advocates for mental wellness and inclusivity in cybersecurity.
Outside of work, Megan applies the same discipline to Muay Thai and Brazilian Jiu-Jitsu. Students consistently describe her as approachable, clear, and motivating, praising her ability to translate complex technical concepts into practical applications (feedback via SANS course evaluations). Her teaching philosophy emphasizes inclusivity and accessibility, with a focus on equipping the next generation of analysts with the skills and confidence needed to defend against evolving threats.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
The SANS Fall Cyber Solutions Fest 2026 Threat Intelligence Track explores how organizations can transform raw data into operational insight that drives faster, more precise decision-making across the enterprise.

SANS 2026 DFIR Summit Solutions Track delivers a deep technical exploration of the tools, methodologies, and operational models driving next-generation digital forensics and incident response.

The Detection & Response Track at SANS Spring Cyber Solutions Fest 2026 brings together frontline experts, innovative practitioners, and cutting-edge solution providers to explore how modern security teams are adapting to an evolving threat landscape.

Secure the Future: Practical Solutions for Tomorrow’s Cyber ThreatsJoin us for the Emerging Threats Summit Solutions Track for a unique, forward-looking virtual event focused not just on identifying emerging cybersecurity threats—but on tackling them head-on.Rather than speculating, we’ve invited leading experts who are actively shaping the future of cybersecurity to share real-world insights and actionable strategies. From AI and ICS/OT vulnerabilities to the implications of quantum computing, this event is designed to equip you with proactive, solution-driven approaches to stay ahead of the evolving threat landscape.You’ll gain access to:Expert-Led Sessions exploring high-impact threat areas and what they mean for your organization.Interactive Discussions focused on building practical frameworks, advancing workforce education, and shaping policy and regulation.Collaborative Insights that connect research with real-world application so you can act, not react.If you're responsible for securing systems, developing strategies, or building resilience into your organization, this summit is your opportunity to future-proof your defenses—before tomorrow’s threats become today’s realities.Reserve your spot and help shape the response to cybersecurity’s next big challenges.

The ability to swiftly detect, investigate, and respond to cyber threats is crucial for minimizing damage. The Detection & Response track focuses on best practices, tools, and techniques for building robust threat detection and incident response capabilities.

In this webinar, we will demonstrate how with the right tooling, analysts of all backgrounds can effectively handle incidents, reducing the response time by removing the need for frequent escalation.

This hands-on workshop will support content from FOR509: Enterprise Cloud Forensics and Incident Response

Part 1: Building a Cloud Security Strategy: A Step-by-Step GuideIn this session, SANS Institute experts will guide you through the key steps in developing a robust cloud security strategy. Whether you're just starting or looking to strengthen your approach, this webcast covers everything from understanding your cloud environment to building a threat detection program and preparing for incident response.

In today's rapidly evolving cyber landscape, attacks are becoming more sophisticated and frequent, making robust detection and response capabilities critical for every organization. Join us for the Detection & Response Track at the Fall Cyber Solutions Fest, where you'll discover the strategies, tools, and insights that will empower your organization to stay ahead.Whether you're looking to fine-tune your current operations or completely overhaul your approach, this session will equip you with actionable insights from top top industry experts. What to Expect:Building Detection Engineering Into Security OperationsReducing Detection and Response TimesHow EDR and XDR Solutions Can Help Organizations with Detection and ResponseAutomating Incident Response Leveraging Lessons from Response to Inform Detection

As cloud migration and modernization gain momentum in 2023, organizations are increasingly leveraging cloud technologies to enhance operational efficiency and improve application performance. However, many encounter a discrepancy between their anticipated cloud outcomes and the reality they face. A significant barrier preventing organizations from realizing the full benefits of the cloud is the absence of DevSecOps practices.

Today, detection engineers and blue teamers are focused on cloud threat detection. However, are we thinking about these threats holistically?There are many pathways that threat actors utilize to gain access to cloud resources. Among these are endpoints that contain various cloud credential material.This cloud credential material - in the form of various files, tokens and cookies is often overlooked, with little visibility and telemetry generated.

As more and more organizations begin moving their resources to the cloud, analysts and responders must be prepared to operate in this new landscape. One aspect of traditional forensics that we must learn to implement in the cloud is memory forensics.

Review relevant educational resources made with contribution from this instructor.