Group Purchasing
Group Purchasing

Raymond DePalma

President at DePalma Research LLC

Connect with Raymond

Raymond DePalma

About Raymond DePalma

Raymond DePalma is President of DePalma Research LLC. Raymond brings 14 years of experience in digital forensics, SOC operations, SIEM engineering, incident response consulting, and solutions architecture. His work runs in both directions where AI and DFIR meet. The first is AI for DFIR: applying large language models and multi-agent systems to accelerate investigations. The second is DFIR of AI: investigating LLM applications, agentic pipelines, MCP servers, and RAG/vector stores when the AI system itself is the victim.

Raymond's career began at MIT Lincoln Laboratory. He completed three rotations there, moving from the Security Service Department to the Forensic Analysis Center to IT Security Threat Assessment while holding a Department of Defense Top Secret clearance. That work grounded him in digital forensic acquisition, open-source threat research, and compliance auditing against NISPOM and NIST standards.

After earning his B.S. from Northeastern University, he spent nearly four years at Liberty Mutual Insurance. He rose from IT Analyst to Lead Responder on the company's global LSERT, where he drove threat-hunting initiatives and built training and threat exercises for SOC analysts. He then served as Principal SIEM Security Engineer and tech lead of a five-person detection engineering team that scaled Splunk Enterprise Security across the organization. He later led Managed Security Services workstreams at IBM as a Security Delivery Project Executive. He then joined Rapid7 as a Senior Security Solutions Engineer, advising customers across SIEM, SOAR, and MDR.

Raymond then spent five years at Palo Alto Networks, advancing through four roles:

  • Cortex Systems Engineer and XDR Solutions Architect: led hands-on XSOAR workshops, developed XQL queries with Unit 42, and ran adversary emulation using MITRE Caldera and breach-and-attack simulation platforms.
  • Principal DFIR Consultant with Unit 42: led incident response and security posture assessments for Fortune 500 and Global 2000 organizations across finance, technology, healthcare, and aerospace. His Unit 42 work also included big data analysis and detection engineering for zero-day threats, as well as case leadership and forensics for edge-device zero-day incidents.
  • Principal DFIR Technical Architect on Unit 42's Engineering team: designed AI-integrated tooling that helped consultants and clients during critical incidents, including multi-agent architectures built on Google's Agent Development Kit.

Raymond created "AI for the Win," an open-source training program of 50+ hands-on labs and Capture the Flag challenges. It helps practitioners bring AI and machine learning into their detection and response work. He also maintains open-source projects including ai-dfir-toolkit and the AI-Powered Ransomware Intelligence Agent. He is a featured guest on the SANS Stay Ahead of Ransomware livestream series hosted by FOR528 author Ryan Chapman, and he writes for the SANS blog on AI-driven ransomware defense.

"A lot of talented responders are sitting on the sidelines of AI because nobody showed them the on-ramp," he says. "If you can write a detection rule, you can learn to work with an LLM. The gap is smaller than people think."

Off the clock, Raymond lives in New Hampshire with his red golden retriever, Cooper. He splits his time between snowboarding, hiking, and a home lab that keeps him as busy as his day job.

Speaker / Contributor: This individual participates in SANS events, presentations, written content, or other community resources as an external contributor. They are not a SANS employee, instructor, or affiliate.