Timothy McKenzie
Principal InstructorOwner at 3L337 Consulting, LLC
Specialities
Offensive Operations, Cloud Security

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsOffensive Operations, Cloud Security

Timothy McKenzie is a SANS Principal Instructor, founder and principal consultant of 3L337 Consulting, and a co-author of SEC542: Web Application Penetration Testing and Ethical Hacking. He also teaches SEC588: Cloud Penetration Testing. With more than 30 years of experience spanning enterprise infrastructure, information security, penetration testing, and Red Team operations, Timothy brings a practitioner's perspective to every course. His teaching reflects the realities of offensive security consulting, where web applications, cloud environments, and enterprise networks must be assessed methodically, findings must withstand scrutiny, and recommendations must translate into meaningful security improvements.
Timothy began his career building and securing enterprise systems before transitioning into offensive security full time. He previously served as a penetration tester and Red Team consultant at SecureWorks, Trustwave, and United American Insurance Company, where he led penetration tests, adversary emulation engagements, and Purple Team exercises across financial services, healthcare, government, and other regulated industries. Rather than focusing only on individual exploits, Timothy emphasizes attack paths, operational tradecraft, and how skilled testers combine technical knowledge with persistence and creativity to uncover weaknesses that automated tools often miss. His work also informs the cloud-focused assessments students perform, helping them understand how modern cloud services, identity, and web technologies intersect during offensive engagements.
Timothy holds the Offensive Security Certified Professional (OSCP), GIAC Web Application Penetration Tester (GWAPT), and GIAC Penetration Tester (GPEN) certifications, along with GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Certified Web Application Defender (GWEB), GIAC Python Coder (GPYC), GIAC Assessing and Auditing Wireless Networks (GAWN), CompTIA Security+, Project+, Network+, and A+ certifications. He serves on the GIAC Advisory Board and regularly contributes to the security community through conference presentations, technical research, GitHub projects, and the 3L337 Consulting research blog, where he writes about topics including GraphQL security, cloud attack techniques, artificial intelligence in penetration testing, and modern application security. Timothy is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition.
Outside the classroom, Timothy is committed to mentoring the next generation of offensive security professionals. He has volunteered his time teaching penetration testing to high school students and regularly speaks at professional security organizations, including ISSA chapters and community events. Students describe him as approachable, engaging, and generous with real-world examples drawn directly from his everyday work engagements. He believes knowledge only has value when it is shared, a philosophy that shapes every lecture, demonstration, and lab. By the end of the week, students leave with practical techniques they can immediately apply to web applications, cloud environments, and Red Team operations, along with a stronger understanding of how experienced practitioners approach offensive security in the real world.
Timothy McKenzie provides in-depth detail in SEC542, as well as his own experiences and anecdotes, and the labs present great examples of the topics covered and what to do when tools fail.
[Tim] continues to keep me engaged and teaches at a great pace with great explanations. I also benefit from hearing his real life "war stories" about where he has found examples of vulnerabilities and the impact they could have for a company/victim.
Very clear, funny, professional... 10/10
Here are upcoming opportunities to train with this expert instructor.
Explore content featuring this instructor’s insights and expertise.
This session walks through a modern web app pentest workflow using OWASP tools, Burp MCP, DefectDojo, and AI-assisted reporting to accelerate recon, scanning, and triage.

The demo will move through reconnaissance, vulnerability scanning, Burp Suite integration, data import into DefectDojo, and AI-assisted report writing—providing a complete, modern pentesting workflow.

Large Language Models (LLMs) such as ChatGPT, Claude, and Grok have become very powerful. This talk is full of live demonstrations of the kinds of things information security professionals can do with the LLMs. Examples include analyzing and manipulating shell code, writing exfiltration code, analyzing logs, and more.

Defenders must be constantly vigilant in their efforts to protect their organization's environment. Through practice, the defenders can be sharpened by red and purple team exercises. This presentation will explore some cassstudies where exercise improved the organization's security posture.

Review relevant educational resources made with contribution from this instructor.