Terrence Williams
Certified InstructorSecurity Engineer, Investigations at Meta
Specialities
Digital Forensics and Incident Response, Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsDigital Forensics and Incident Response, Cloud Security

Terrence Williams is a SANS Certified Instructor and Security Engineer, Investigations at Meta, with deep expertise in cloud security, digital forensics, and incident response. He has built his career protecting some of the world’s most complex global infrastructures while mentoring the next generation of cybersecurity professionals.
Terrence’s career began in the U.S. Marine Corps and later with U.S. Special Operations Command (USSOCOM), where he served as a Cyber Network Operator supporting critical defense missions. After his military service, he transitioned to the private sector, holding security engineer roles as Amazon Web Services (AWS) and Google. At AWS, he focused on securing large-scale cloud environments and leading cyber threat hunting initiatives. At Google, he specialized in detection engineering, cloud incident response, and advanced threat analysis. Today at Meta, Terrence investigates sophisticated cyber threats and develops strategies to improve detection and response across billions of user accounts.
As a SANS Instructor, Terrence teaches FOR509: Enterprise Cloud Forensics and Incident Response, where his experience at AWS, Google Cloud, and Meta directly shapes hands-on labs covering cloud log acquisition, detection engineering, and multicloud incident response. He is also author of the 2025 SANS Detection Engineering Survey and co-author of the 2023 SANS Incident Response Survey, shaping industry-wide conversations around detection engineering and incident response practices. His teaching is recognized for balancing technical rigor with an approachable style that empowers students to confidently tackle cloud investigations.
Outside of work, Terrence enjoys traveling, exploring new restaurants and bourbon bars, and mentoring aspiring cybersecurity professionals. Students who train with him can expect encouragement, clarity, and real-world strategies that they an immediately apply in their careers.
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
This talk teaches the practitioner path from where most of us started: prompting an assistant for a faster answer.

Join SANS instructor Terrence Williams and Kevin Gonzalez for a deep dive into the data and actionable insights into detection engineering practices

The landscape of Detection Engineering is rapidly evolving, and staying ahead of the curve is crucial for cybersecurity professionals. To dive deep into understanding the current state and future trends of this critical field, SANS has partnered with Anvilogic to conduct a comprehensive survey of Detection Engineering professionals across various industries.

This hands-on workshop will support content from FOR509: Enterprise Cloud Forensics and Incident Response

Going from responding to incidents to actively hunting threats is a stance shift that requires maturity in your cybersecurity journey. It also requires having access to the right threat intelligence, the right visibility across your environment, as well as the right tools to do the job. Advances in data science and artificial intelligence can help organizations bridge the maturity gap, but we shouldn’t forget that it’s ultimately a human with financial or geopolitical interests who’s behind these attacks. Also the same technology is available to both sides, and just as quickly as new models become more effective at threat detection, malicious actors grow more capable at confusing those models.Likewise, organizations have now access to threat intelligence sources through various vendors and platforms. Yet many are not necessarily seeing all the value threat intelligence can bring because they don't understand how to operationalize it or they are not taking advance of the tools that can help them automate and accelerate their threat-hunting programs.At the same time many security practitioners still struggle with the basics, the three big “knows” that every organization should focus on: knowing your enemy, knowing your network, and knowing your tools. Why? In many cases they are too busy responding to alerts and false positives to do what's needed for a threat-hunting program to be successful.What should organizations do in 2023 to take a more proactive stance, operationalize threat intelligence and focus on maturing their threat hunting program?Join Ismael Valenzuela, SANS author and Senior instructor for the 2024 Cyber Solutions Fest - Threat Hunting and Intelligence Track, and hear talks on:Enriching alerts with threat intelligenceUtilizing XDR and MDR services to help accelerate your threat-hunting programOperationalizing threat intelligenceAutomating threat hunting tasks with XDR, NDR, and threat intelligence solutionsIdentifying the most actionable intelligence for the organization

Crypto miners are increasingly targeting cloud environments, leveraging the vast resources of organizations to mine cryptocurrency, which leads to inflated costs and resource depletion.

Review relevant educational resources made with contribution from this instructor.