Group Purchasing
Group Purchasing

Timothy McKenzie

Principal InstructorOwner at 3L337 Consulting, LLC

Specialities

Offensive Operations, Cloud Security

Connect with Timothy

Timothy McKenzie

About Timothy McKenzie

Timothy McKenzie is a SANS Principal Instructor, founder and principal consultant of 3L337 Consulting, and a co-author of SEC542: Web Application Penetration Testing and Ethical Hacking. He also teaches SEC588: Cloud Penetration Testing. With more than 30 years of experience spanning enterprise infrastructure, information security, penetration testing, and Red Team operations, Timothy brings a practitioner's perspective to every course. His teaching reflects the realities of offensive security consulting, where web applications, cloud environments, and enterprise networks must be assessed methodically, findings must withstand scrutiny, and recommendations must translate into meaningful security improvements.

Timothy began his career building and securing enterprise systems before transitioning into offensive security full time. He previously served as a penetration tester and Red Team consultant at SecureWorks, Trustwave, and United American Insurance Company, where he led penetration tests, adversary emulation engagements, and Purple Team exercises across financial services, healthcare, government, and other regulated industries. Rather than focusing only on individual exploits, Timothy emphasizes attack paths, operational tradecraft, and how skilled testers combine technical knowledge with persistence and creativity to uncover weaknesses that automated tools often miss. His work also informs the cloud-focused assessments students perform, helping them understand how modern cloud services, identity, and web technologies intersect during offensive engagements.

Timothy holds the Offensive Security Certified Professional (OSCP), GIAC Web Application Penetration Tester (GWAPT), and GIAC Penetration Tester (GPEN) certifications, along with GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), GIAC Certified Web Application Defender (GWEB), GIAC Python Coder (GPYC), GIAC Assessing and Auditing Wireless Networks (GAWN), CompTIA Security+, Project+, Network+, and A+ certifications. He serves on the GIAC Advisory Board and regularly contributes to the security community through conference presentations, technical research, GitHub projects, and the 3L337 Consulting research blog, where he writes about topics including GraphQL security, cloud attack techniques, artificial intelligence in penetration testing, and modern application security. Timothy is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition.

Outside the classroom, Timothy is committed to mentoring the next generation of offensive security professionals. He has volunteered his time teaching penetration testing to high school students and regularly speaks at professional security organizations, including ISSA chapters and community events. Students describe him as approachable, engaging, and generous with real-world examples drawn directly from his everyday work engagements. He believes knowledge only has value when it is shared, a philosophy that shapes every lecture, demonstration, and lab. By the end of the week, students leave with practical techniques they can immediately apply to web applications, cloud environments, and Red Team operations, along with a stronger understanding of how experienced practitioners approach offensive security in the real world.

Qualifications Summary
  • Founder and Principal Consultant, 3L337 Consulting
  • SANS Principal Instructor; Co-author of SEC542: Web Application Penetration Testing and Ethical Hacking
  • Certifications: OSCP, GWAPT, GPEN, GXPN, GWEB, GPYC, GAWN, CompTIA Security+, Project+, Network+, A+; GIAC Advisory Board member
  • Previously served as a penetration tester and Red Team consultant at SecureWorks, Trustwave, and United American Insurance Company
  • Community contributor through technical research, GitHub projects, conference presentations, ISSA speaking engagements, and the 3L337 Consulting security research blog

Press & Media

More From Timothy