About Open Security

Built by the people who do the work.

Open Security was not assembled in a boardroom. It was built by operators, practitioners performing security operations every day, with military cyber backgrounds and years of real-world engagements behind every methodology, every report, and every line of Sirius. We are headquartered in Dallas and work with clients across the United States and remotely worldwide.

Meet the team
Map of Open Security client engagements and trainings worldwide
  • Client Engagements
  • Training
  • Training and Client Engagements

What we believe

Three convictions behind every engagement.

Outcomes over deliverables

You are not buying a test — you are buying what happens after. Every engagement is measured by the decisions it enables and the exposure it closes, not the page count it produces.

We build the tools we use

The same operators who run your engagement build the platform behind it — Sirius, Aludra, Portal, RTable. Building the tooling is why the work goes deeper than a firm running someone else’s scanner.

Judgment stays human

Automation and AI expand what our experts can cover; they never make the calls. Every finding that reaches you has been reviewed by an operator who stands behind it.

The Operator's Perspective

Security Minds.

The operators behind the engagements — the people who still run the work, teach the craft, and stand behind the findings.

Matt Toussain, Founder & Chief Information Officer at Open Security

The Operator’s Perspective

Matt Toussain

Founder & Chief Information Officer

Offensive security operator, SANS instructor, and the founder behind Sirius — turning real attack experience into the methodology and tools other operators use.

  • Offensive security
  • Vulnerability operations
  • Cybersecurity training
View profile
Josh Christman, Chief Operating Officer at Open Security

The Operator’s Perspective

Josh Christman

Chief Operating Officer

COO who runs security engineering and the applied AI behind Aludra. Tests stay scoped to business risk. Findings stay ones an engineer will stand behind.

  • Applied AI
  • Aludra
  • Security engineering
  • Penetration testing
View profile
Bryce Zuccaro, Principal Security Engineer at Open Security

The Operator’s Perspective

Bryce Zuccaro

Principal Security Engineer

Principal Security Engineer who plans engagements, mentors operators, and teaches the craft — SANS SEC460, Red Team Village, and the Las Vegas AI Security Forum.

  • Penetration testing
  • Adversary simulation
  • Cybersecurity training
View profile
Jacob Krut, Security Engineer at Open Security

The Operator’s Perspective

Jacob Krut

Security Engineer

A self-taught security engineer who started in bug bounty by turning a blind SSRF in Yahoo Mail into remote code execution. The same instinct later found a high-severity SSRF in ChatGPT.

  • Bug bounty
  • Application security
  • AI security
  • Cloud exposure
View profile
Michael Pleasant, Chief Executive Officer at Open Security

The Operator’s Perspective

Michael Pleasant

Chief Executive Officer

Marine Corps veteran and co-founder who built Open Security to make operator-grade cybersecurity accessible to the businesses that actually need it.

  • Security leadership
  • Veteran enterprise
  • Client partnerships
View profile

Recognition

Veteran-owned, nationally recognized.

Open Security’s veteran roots are not a footnote — they are the operating model. National recognition for veteran enterprise and hiring reflects the discipline behind the work.

SBA Small Business Champion (Veteran Enterprise) of the Year2019

SBA Small Business Champion (Veteran Enterprise) of the Year

Future Texas Legend Veteran Award — Texas Business Hall of Fame2023

Future Texas Legend Veteran Award — Texas Business Hall of Fame

DOL HIRE Veterans Platinum Medallion2022

DOL HIRE Veterans Platinum Medallion

Work with the operators.

Talk through your risk with the people who will actually run your engagement — and get a clear, tailored plan.