Group Purchasing
Group Purchasing

Brandon Evans

Senior InstructorPartner at Cyverity

Specialities

Cloud Security

Connect with Brandon

Brandon Evans

About Brandon Evans

Brandon Evans serves as Senior Instructor at the SANS Institute and Partner at Cyverity, where he brings advanced cloud-security and DevSecOps expertise to global learners. He is the lead author of SEC510: Cloud Security Engineering and Controls and a key contributor to SEC540: Cloud Native Security and DevSecOps Automation, equipping practitioners to defend modern, multicloud environments with precision and hands-on mastery.

Brandon’s career began in software engineering, building core products at startups and large enterprises before pivoting toward security. He previously led the secure-development training program at Zoom Video Communications and now consults broadly on multicloud and hybrid security for large workloads. His engineering background and shift into application security underpin the labs in the course. In his class, students move from cloud architecture to secure code patterns, infrastructure as code, and DevSecOps automation under his guidance.

He holds prominent credentials including the GIAC Public Cloud Security (GPCS) certification (holder #1), GIAC Certified Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), GIAC Secure Software Programmer – Java (GSSP-JAVA), GIAC Security Essentials Certification (GSEC), GIAC Cloud Security Automation (GCSA), GIAC Cloud Penetration Tester (GCPN), and an AWS Certified Security – Specialty credential. Brandon is also a faculty member of the SANS Technology Institute, which has been designated an NSA Center of Academic Excellence in Cyber Defense and is a multi-year winner of the National Cyber League competition. In addition to his course work, Brandon contributes open-source projects and research, such as the “Serverless Prey” project, multicloud security cheat sheets, and he hosted the Cloud Ace podcast (Season 1).

In the classroom, Brandon emphasizes developer-friendly security: he believes that the most effective defenses come when security speaks the same language as engineering. His labs promote the mindset: “walk a mile in the developer’s shoes, then build the guardrails.” Student reviews highlight his energetic delivery, relevant war-stories, and practical frameworks for real work. Outside of the course, Brandon is an avid rock-climber, chess enthusiast and classic-video-game fan. Above all, he brings that sense of continuous climb and playful curiosity into every one of his classes.

Qualifications Summary
  • Partner at Cyverity; Senior Instructor/Author, SANS Institute.
  • Certifications and credentials: GIAC Public Cloud Security (GPCS) #1; GIAC Certified Penetration Tester (GPEN); GIAC Web Application Penetration Tester (GWAPT); GIAC Secure Software Programmer – Java (GSSP-JAVA); GIAC Security Essentials Certification (GSEC); GIAC Cloud Security Automation (GCSA); GIAC Cloud Penetration Tester (GCPN); AWS Certified Security – Specialty.
  • Key achievements: Transitioned from software engineer to lead secure-development programs at Zoom; lead author of SEC510 and contributor to SEC540; multicloud security consultant assessing large-scale workloads.
  • Publications and tools: Co-creator of the “Serverless Prey” project (serverless functions for attack simulation); host of Cloud Ace podcast; multicloud cheat sheets and labs.
  • Courses taught/authored: SEC510: Cloud Security Engineering and Controls; SEC540: Cloud Native Security and DevSecOps Automation.
  • Community/other roles: Co-leader, Nashville chapter of the OWASP; contributor to OWASP Serverless Top 10 project; frequent presenter at RSA Conference and serverlessDays.

Press & Media