Talk With an Expert

SANS Instructors

SANS Institute Instructors are rock stars of the cybersecurity field, with a broad base of expertise in government and industry working as red team leaders, CISOs, technical directors, and research fellows. Use the search bar below to search for an instructor by name, or use the filter to narrow the instructors down by focus area.

Filter by:
Mark Baggett
Mark Baggett

Mark Baggett

Fellow

SANS Faculty Fellow Mark Baggett authored SEC573, SEC673, and SEC406, leads as CTO of the SANS Internet Storm Center, and empowers defenders to automate security through practical, real-world application.

Read more about Mark Baggett
Heather Barnhart
Heather Barnhart

Heather Barnhart

Fellow

Heather has 20+ years of experience working with government agencies, defense contractors, law enforcement, and Fortune 500 companies. Her case experience ranges from fraud, crimes against children, counter-terrorism, and homicide investigations.

Read more about Heather Barnhart
Eric Conrad
Eric Conrad

Eric Conrad

Fellow

Eric Conrad, a SANS Faculty Fellow and course author, has 28 years of information security experience. Eric is the CTO of Backshore Communications and his specialties include Intrusion Detection, Threat Hunting, and Penetration Testing.

Read more about Eric Conrad
Tim Conway
Tim Conway

Tim Conway

Fellow

SANS Fellow Tim Conway, co-author of ICS456, ICS310, and ICS612, blends decades of hands-on ICS/OT security and compliance expertise with ongoing frontline consulting, helping students turn complex industrial challenges into practical skills.

Read more about Tim Conway
Phil Hagen
Phil Hagen

Phil Hagen

Fellow

Phil Hagen shaped network forensics with SOF-ELK® and SANS FOR572, setting standards in large-scale log analysis and response. His role in exposing a global fraud ring behind hundreds of millions in losses defines his lasting impact on cybersecurity.

Read more about Phil Hagen
David Hoelzer
David Hoelzer

David Hoelzer

Fellow

David Hoelzer has fundamentally advanced cybersecurity by pioneering the GIAC Security Expert (GSE) certification, leading AI-driven threat detection initiatives, and developing MAVIS, an open-source ML tool enhancing code review processes.

Read more about David Hoelzer
Eric Johnson
Eric Johnson

Eric Johnson

Fellow

Eric is a co-founder and principal security engineer at Puma Security, focusing on cloud security, Kubernetes, and DevSecOps automation. A SANS Fellow, he is co-author and instructor for three SANS Cloud Security courses.

Read more about Eric Johnson
Frank Kim
Frank Kim

Frank Kim

Fellow

Frank Kim is the Founder of ThinkSec, a security consulting and CISO advisory firm. He leads the Cybersecurity Leadership and Cloud Security curricula at SANS, as well as authors and instructs multiple SANS courses.

Read more about Frank Kim
Rob Lee
Rob Lee

Rob T. Lee

Fellow

Rob T. Lee is Chief AI Officer and Chief of Research at SANS Institute, where he leads research, mentors faculty, and helps cybersecurity teams and executive leaders prepare for AI and emerging threats.

Read more about Rob T. Lee
Robert M. Lee
Robert M. Lee

Robert M. Lee

Fellow

SANS Fellow and Dragos CEO Robert M. Lee, author of ICS515 and FOR578 and co-author of ICS310, teaches from landmark industrial cyber investigations, turning real adversary tradecraft into visibility, detection, and response skills in OT.

Read more about Robert M. Lee
Seth Misenar
Seth Misenar

Seth Misenar

Fellow

Seth, SANS Faculty Fellow and author of SEC411, LDR414, and SEC511, combines cutting-edge consulting and education to equip defenders worldwide. Founder of Context Security and GSE #28, he brings clarity, humor, and purpose to cybersecurity training.

Read more about Seth Misenar
Stephen Sims
Stephen Sims

Stephen Sims

Fellow

Stephen Sims, an esteemed vulnerability researcher and exploit developer, has significantly advanced cybersecurity by authoring SANS's most advanced courses and co-authoring the "Gray Hat Hacking" series.

Read more about Stephen Sims