Christian Villapando
Instructor
Security Consultant at Red Rock IT Security Inc
Specialities
Offensive Operations
Connect with Christian

About Christian
Christian Villapando is a cybersecurity consultant at Red Rock IT Security Inc. and a SANS Certified Instructor Candidate who teaches SEC560: Enterprise Penetration Testing. With hands-on expertise in penetration testing, red teaming, and purple teaming, he brings real-world adversary tactics directly into the course, helping students understand how modern attacks are executed and how to defend enterprise environments against them.
Christian began his career supporting national cybersecurity efforts with the Philippines’ National Computer Emergency Response Team (CERT-PH), where he conducted vulnerability assessments and penetration testing on government systems. He later moved into consulting roles, including his time at Verizon, where he worked closely with enterprise clients to identify exploitable weaknesses and strengthen their security posture. Now at Red Rock IT Security, he leads and delivers offensive security engagements across industries such as finance, healthcare, and e-commerce. These real-world experiences directly inform the course labs, where students practice enterprise penetration testing techniques, simulate adversary behavior, and develop actionable remediation strategies.
Press & Media
Recognitions
- ROOTCON 18 / Conference Talk / 2024 How Attackers Are Compromising Your Networks and What You Can Do About It
- ROOTCON 18 Red Teaming Village / Conference Talk / 2024 Active Directory Attacks and Operational Security Considerations
- Webcast / Tech Academy / 2024 The Red Team Side of Cybersecurity
- ROOTCON 17 / Conference Talk / 2023 Introduction to Mobile Penetration Testing
- Wild West Hackin’ Festival (WWHF) / Conference Talk / 2023 Zero to Hero: Hacking Your Way to Your First Pentest Gig
- De La Salle University Repository / Academic Publication / 2022 Improving Security Posture by Mitigating Common Active Directory Security Misconfigurations in Active Directory Environments
