Group Purchasing
Group Purchasing

Serge Borso

Principal InstructorCEO at SpyderSec

Specialities

Cloud Security, Offensive Operations

Connect with Serge

Serge Borso

About Serge Borso

Serge Borso is a SANS Principal Instructor, CEO of SpyderSec, and longtime cybersecurity practitioner with more than a decade of experience teaching at SANS. He teaches SEC502: Cloud Security Tactical Defense and SEC541: Cloud Security Threat Detection, bringing a practitioner-focused approach shaped by years of offensive security work, enterprise security leadership, and hands-on consulting experience.

Serge’s background spans penetration testing, red teaming, OSINT, web application security, cloud security, incident response, security architecture, and virtual CISO leadership. Rather than teaching security as theory or compliance language, he focuses on how security decisions hold up in real operational environments against modern attacker techniques, business constraints, and implementation mistakes.

Serge founded SpyderSec in 2015 after years working in enterprise security engineering and leadership roles. His experience includes authorized physical security testing, web application assessments, OSINT research, 0-day discovery, and building measurable security programs for billion-dollar organizations. He brings those experiences directly into the classroom, helping students translate complex security concepts into practical defensive capabilities they can immediately apply in production environments.

In addition to leading security consulting engagements, Serge has worked extensively with identity and access management, detection engineering, secure cloud architecture, CI/CD security, threat modeling, vulnerability management, and enterprise-scale security operations. His instruction blends offensive and defensive perspectives to help practitioners better understand attacker behavior, strengthen security strategy, and improve real-world resilience.

Serge holds a master’s degree in computer science from Colorado Technical University, maintains the CISSP certification, and holds multiple GIAC certifications, including GCLD, GWEB, GWAPT, GCFA, and GPEN. He is also the author of The Penetration Tester’s Guide to Web Applications, creator of the Espial OSINT tool, a former Denver OWASP chapter leader, and a frequent speaker at industry conferences including RSA Conference and RMISC.

Serge teaches with a direct, experience-driven approach that emphasizes practical application over theory alone. Drawing from years of penetration testing, consulting, cloud security, and security leadership experience, he helps students understand how security decisions perform in real environments against real attackers. His focus is on building practitioners who can think critically, adapt quickly, and apply security concepts effectively in production environments.

Qualifications Summary
  • Master’s degree in computer science, Colorado Technical University
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Certifications: GIAC Cloud Security Essentials (GCLD); GIAC Web Application Defender (GWEB); GIAC Web Application Penetration Tester (GWAPT); GIAC Certified Forensic Analyst (GCFA); GIAC Penetration Tester (GPEN)
  • Key Achievements: CEO and founder of SpyderSec; experienced penetration tester and security consultant; discovered multiple 0-days; created OSINT tools for the community; built an enterprise-wide measurable security program for a billion-dollar company
  • Courses: Instructor for SEC502: Cloud Security Tactical Defense, and SEC541 Cloud Security Threat Detection; author of SEC480: AWS Secure Builder
  • Community Contributions: Frequent national conference speaker on cloud security, offensive security, OSINT, and detection engineering including at RSA Conference, Denver OWASP chapter leader; organizer of SnowFROC

Press & Media