The Operator’s Perspective
Bryce Zuccaro
Principal Security Engineer
Principal Security Engineer who plans engagements, mentors operators, and teaches the craft — SANS SEC460, Red Team Village, and the Las Vegas AI Security Forum.
- Penetration testing
- Adversary simulation
- Cybersecurity training

Introduction
Bryce Zuccaro is a principal security engineer and penetration tester at Open Security. He plans and runs engagements, mentors other operators, and vets the product work that will eventually sit behind a finding. Before Open Security he spent years as an internal red/purple teamer in financial services, taught vulnerability management and operating-system fundamentals as an adjunct professor, and co-instructed SANS SEC460. He has served on the DEF CON Red Team Village for three years, helping bring premier red team content to thousands of attendees every year, and is an organizer of the Las Vegas AI Security Forum 2026. He also wrote AI Operations, a three-day course on running, tuning, and using LLMs and agents.
“AI has accelerated both the red and blue teams. As a trusted partner, we can ensure you’re well positioned for what comes next.”
Expertise
Where Bryce leads.
Penetration testing
Full-scope network and application testing with rules of engagement written to the business — not a scan with a cover sheet.
Principal Security Engineer; OSCP
Penetration testingAdversary simulation
Long-horizon red-team and purple-team work, including atomic testing mapped to ATT&CK and SOC-visibility improvement.
Certified Red Team Operator (CRTO); five years internal red/purple team in financial services
Threat simulationCybersecurity training
Course design and live instruction — community-college vulnerability management, SANS SEC460 labs, and public technical talks.
SANS SEC460 co-instructor; designed CNG256 at Red Rocks Community College
TrainingAI security
Practical operator view on local LLMs: what runs on real hardware, what does not, and how to do it on a budget. He also wrote AI Operations, a three-day course on running, tuning, and using LLMs and agents.
Red Team Village RTVCron — Local Large Language Models (2026); organizer, Las Vegas AI Security Forum 2026
Experience & background
How the authority was earned.
At Open Security, Bryce is on the engagement: scoping, testing, mentoring, and deciding whether a new capability is good enough to put behind a client finding.
His path runs through telecom and enterprise security operations (Level 3 / CenturyLink), then a five-year stretch as Nelnet’s internal pen tester and red/purple teamer, then into teaching — SANS and Colorado community colleges — before joining Open Security in 2024.
Since August 2023 he has been secretary and marketing for Red Team Village: DEF CON on-site video and photo, records, and year-round CRON teaching. He was a US Cyber Challenge virtual TA in 2021, CCDC Red Team for Rocky Mountain in 2020 and 2021, and helped organize DerpCon in Denver in March 2020.
Credentials
- CISSP ((ISC)2), valid through Mar 2029
- GIAC Experienced Penetration Tester (GXPT), Nov 2023
- GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), Apr 2022
- GIAC Web Application Penetration Tester (GWAPT), Mar 2022
- GIAC Battlefield Forensics and Acquisition (GBFA), Jan 2022
- GIAC Enterprise Vulnerability Assessor (GEVA), Nov 2021
- GIAC Python Coder (GPYC), Aug 2021
- GIAC Certified Incident Handler (GCIH), Jul 2021
- GIAC Security Essentials Certification (GSEC), Jul 2021
- GIAC Defending Advanced Threats (GDAT), Feb 2021
- Certified Red Team Operator (CRTO), Dec 2020
- Offensive Security Certified Professional (OSCP), Jun 2020
- GIAC Advisory Board, Aug 2018
- GIAC Penetration Tester (GPEN), Aug 2018
- B.B.A., Computer Information Systems, Colorado State University (2012–2013)
- Valid through Mar 2029
- CISSP
- Offensive and red-team credentials
- OSCP + CRTO
Valid through Mar 2029
Offensive and red-team credentials
Jul 2024–present
Principal Security Engineer
Open Security
Training and support for junior engineers, engagement planning and management, and new product development and vetting. San Antonio, TX / remote.
Jul 2019–Jul 2024
Information Security Architect / Penetration Tester
Nelnet
Denver hybrid. Internal pentest and red/purple team: PCI segmentation, long-horizon red team versus APTs, social engineering, application reverse engineering, atomic testing mapped to ATT&CK, SOC visibility, asset inventory, SIEM/EDR offensive research, and IR assist.
Jan 2022–Aug 2023
Certified Instructor Candidate
SANS Institute
Co-instructed SANS GEVA/SEC460 half-time at events and developed On Demand lab courseware for enterprise threat and vulnerability assessment.
Aug 2019–Jul 2023
Adjunct professor
Red Rocks Community College & Community College of Aurora
Designed and taught CNG256 Intro to Vulnerability Management at Red Rocks (Aug 2021–Jul 2023). At Community College of Aurora (Aug 2019–May 2021): CIS 128 OS, CNG 132 Network Security Fundamentals, CNG 142 Cloud, and CNG 223 Linux, including a 12-host ESXi/vCenter lab.
Mar 2018–Jul 2019
Sr. Information Security Engineer
CenturyLink
SaltStack automation, PCI vulnerability management, and ASV vendor procurement.
2014–2018
Security operations
Level 3 Communications
Security Operations Engineer (Feb 2017–Feb 2018), Security Technician II (Feb 2015–Feb 2017), and Technical Ops Associate (Jan 2014–Feb 2015).
Featured media
Watch, listen, or read first.
Video
RTVcron | Local Large Language Models
A practical walkthrough of running LLMs on your own hardware — constraints, budget, and what actually works. Red Team Village RTVCron.
Red Team Village · May 9, 2026 · Video
Watch (opens in a new tab, Red Team Village)Captions are available in the YouTube player.
Content library
Talks, writing, and teaching.

Video
RTVcron | Local Large Language Models
A practical walkthrough of running LLMs on your own hardware — constraints, budget, and what actually works.
Red Team Village · May 9, 2026 · Video
Watch on Red Team Village (opens in a new tab)
Video
DC34 - Red Team Village - Recap
Recap of Red Team Village at DEF CON 34.
Red Team Village · 2026 · Video
Watch on Red Team Village (opens in a new tab)Resource
Credly badge profile
Public GIAC, OSCP, and GIAC Advisory Board badges.
Credly · Ongoing
View badges on Credly (opens in a new tab)Training
AI Operations
A three-day course on running, tuning, and using LLMs and agents.
Course
Training
SANS SEC460 — co-instruction and lab courseware
As a SANS instructor candidate, Bryce taught half-time at multiple events and developed on-demand labs for enterprise threat and vulnerability assessment.
SANS Institute · 2022–2023
View credentials on SANS Institute (opens in a new tab)Training & appearances
Rooms Bryce has been in.
Previous
2026
EventSnowFroc 2026 - Red Teaming AI
Speaker · Red Teaming AI
August 6, 2026
EventLas Vegas AI Security Forum 2026
Host · Organizer · Las Vegas, NV
May 9, 2026
WatchRed Team Village — RTVCron
Speaker · Local Large Language Models · Online
2023–present
SiteRed Team Village
Volunteer · Secretary and Marketing — DEF CON on-site video/photo and year-round CRON teaching
2022–2023
SANS Institute
Instructor · SEC460 enterprise threat and vulnerability assessment · Multiple SANS events
2021–2023
Red Rocks Community College
Instructor · CNG256 — Introduction to Vulnerability Management (course designer) · Denver, CO
Media kit
Use the approved facts.
For event organizers, podcast hosts, journalists, and partners. Copy or download — do not invent a bio.
Short biography
Bryce Zuccaro is a principal security engineer and penetration tester at Open Security. He has served on the DEF CON Red Team Village for three years, co-instructed SANS SEC460, and wrote AI Operations, a three-day course on running, tuning, and using LLMs and agents.
Extended biography
Bryce Zuccaro is a principal security engineer and penetration tester at Open Security. He plans and runs engagements, mentors other operators, and vets the product work that will eventually sit behind a finding. Before Open Security he spent years as an internal red/purple teamer in financial services at Nelnet, taught vulnerability management and operating-system fundamentals as an adjunct professor, and co-instructed SANS SEC460. He has served on the DEF CON Red Team Village for three years, helping bring premier red team content to thousands of attendees every year, and is an organizer of the Las Vegas AI Security Forum 2026. He also wrote AI Operations, a three-day course on running, tuning, and using LLMs and agents. He holds CISSP, OSCP, CRTO, and multiple GIAC certifications.
Title
Principal Security Engineer
Pronunciation
zoo-CAR-oh
Approved headshot
Download portraitMedia contact
contact@opensecurity.ioBook a conversationSuggested interview topics
- What a serious internal red team looks like in a regulated enterprise
- Teaching vulnerability management from a terminal up
- Running local LLMs as an operator, not a demo
- Purple teaming that actually changes SOC visibility
Suggested speaking topics
- Local large language models for security practitioners
- From PCI pentest to adversary emulation
- Building junior operators without lowering the bar
Open Security
Open Security is a veteran-owned, operator-led cybersecurity firm. We run adversarial testing that uncovers exploitable risk, then hand clients the decision intelligence to act — backed by the platform our operators built.
Related experts
Keep reading the practice.

Matt Toussain
Founder & Chief Information Officer
Offensive security operator, SANS instructor, and the founder behind Sirius — turning real attack experience into the methodology and tools other operators use.
View profile →
Josh Christman
Chief Operating Officer
COO who runs security engineering and the applied AI behind Aludra. Tests stay scoped to business risk. Findings stay ones an engineer will stand behind.
View profile →
Jacob Krut
Security Engineer
A self-taught security engineer who started in bug bounty by turning a blind SSRF in Yahoo Mail into remote code execution. The same instinct later found a high-severity SSRF in ChatGPT.
View profile →Put Bryce in a room — or on an engagement.
Invite him to teach or speak, or talk to Open Security about the kind of testing he runs for clients.
