Nick Mitropoulos
Certified InstructorCEO at Scarlet Dragonfly
Specialities
Cyber Defense, Cybersecurity and IT Essentials

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsCyber Defense, Cybersecurity and IT Essentials

Nick Mitropoulos teaches defenders the same detection strategies he used while leading global SOCs and incident response teams, distilling these lessons into SANS SEC555TM: Detection Engineering and SIEM AnalyticsTM, the course he authored and primarily teaches at the SANS Institute, alongside SEC301 and SEC401. As lead instructor, he helps students design resilient pipelines, craft high-fidelity analytics, and validate defenses against real adversary behavior. In addition to his teaching, Nick serves as CEO of Scarlet Dragonfly, where he advises organizations worldwide on security operations, SIEM optimization, and adversary resilience.
Nick’s career reads like a blueprint for modern cyber defense. At BlueVoyant, he directed SOC operations serving clients across multiple continents. At Alvarez & Marsal, he led global SOC and security engineering teams, strengthening detection pipelines for enterprise-scale environments. As Senior Director of Incident Response at Ankura, he guided enterprises through high-stakes breaches. Earlier in his career, he advanced threat detection and intelligence at S-RM, ASOS, Deloitte, KPMG, JPMorgan Chase, AT&T, and F5. Each of these chapters informs the labs in SEC555, where students recreate adversary log chains, tune detections, and practice workflows tested in real-world conditions.
Nick earned a Master of Science, with distinction, in Advanced Security and Digital Forensics from Edinburgh Napier University, and a Bachelor of Science, with distinction and top departmental honors, in Computer Science and Telecommunications from the University of Thessaly. His credentials include advanced GIAC certifications, as well as CISSP, CISM, and CCSP, alongside additional certifications spanning cloud, penetration testing, and forensics. He is a member of the GIAC Advisory Board, contributes to the SANS CISO Network, and has been recognized in the United Nations Hall of Fame. Nick is also a faculty member of the SANS Technology Institute, an NSA Center of Academic Excellence in Cyber Defense and multi-year winner of the National Cyber League competition.
In the classroom, Nick is praised for his energy, clarity, and ability to turn complex detection concepts into practical skills. Students describe him as “approachable, engaging, and highly practical,” also noting, “he kept a ton of energy and engagement throughout the week.” By the end of SEC555, learners leave able to craft detections that catch adversary behaviors early, to automate workflows to reduce analyst fatigue, and to validate analytics against simulated attack chains. Beyond the classroom, Nick shares insights through conference talks and SANS webcasts, extending his mentorship to the broader security community. He often likens adversary detection to chess: success comes not from reacting, but from anticipating moves, recognizing subtle patterns, and shaping the game itself.
[Nick] kept a ton of energy and engagement throughout the week. I really enjoyed Nick's teaching style that included a lot of examples and analogies.
Nick knows his stuff. [He] is very knowledgeable and happily answers all questions. Keeps the class interesting.
[Nick] is very good at giving practical examples with the content. I loved the examples he gave during the day.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
In this session, we explore how attackers are leveraging generative AI, voice cloning, deepfakes, and conversational bots to exploit human trust with unprecedented precision.

This webinar explores the design and deployment of a robust detection engineering lab—built both on-prem and in the cloud—that enables engineers to simulate real world attacks, validate hypotheses, and rapidly iterate on detection logic.

現在のセキュリティチームにとっての大きな課題は、実際の運用に耐えうる精度と、回避的な脅威にも対応可能な堅牢な検知コンテンツをいかに設計・開発するかです。

Join us for SANS Secure Your Fortress: Building Robust and Resilient Defenses for 2025, where cutting-edge techniques meet hands-on practicality. Designed for cybersecurity professionals at all levels, this event equips you with the tools, strategies, and insights needed to overcome today’s toughest challenges and prepare for tomorrow’s emerging threats.

Hear the stories from top SANS faculty of how they became the cybersecurity experts they are today and how their stories can be applied to your career journey. Learn how they build their skills to become one of the top practitioners within cybersecurity.

Join us at the forefront of cybersecurity at "SANS Secure Your Fortress: 2024's Top Defense Strategies and Trends!"

Step into a world where cutting-edge defense meets practicality in cybersecurity! "SANS Secure Your Fortress" will teach you how to master the latest and most effective defense techniques. Whether you're a seasoned expert or just beginning your cyber journey, this event is for you.

This presentation explores the dynamic landscape of securing Microsoft Azure by addressing the relationship between reconnaissance and password guessing.

SANS Community Nights are a great way to stay in touch with your local InfoSec community and to hear the latest in technical wizardry, industry intelligence, and thought leadership from our amazing instructors.

Review relevant educational resources made with contribution from this instructor.