The Operator’s Perspective

Josh Christman

Chief Operating Officer

COO who runs security engineering and the applied AI behind Aludra. Tests stay scoped to business risk. Findings stay ones an engineer will stand behind.

  • Applied AI
  • Aludra
  • Security engineering
  • Penetration testing
Discuss a security challenge
Josh Christman, Chief Operating Officer at Open Security

Introduction

Josh Christman is Open Security’s Chief Operating Officer. He runs security engineering and the product work behind Aludra, the continuous penetration testing environment operators use to prove what is exploitable. His AFIT master’s research on interactive evolutionary computation, presented at IEEE ICMLA in 2015, is the same idea at work: search at machine scale, keep judgment with the operator. Invite him when you want to talk about how a technical practice uses AI without handing the calls to a model.

“We don’t look for checkboxes. We look for what’s possible — the same curiosity we train into every assessment.”

Expertise

Where Josh leads.

Applied AI and Aludra

Leads the engineering behind Aludra, Open Security’s continuous penetration testing environment. Operators own the methodology. Aludra scales discovery, exploitation, and validation so they spend time on judgment and complex paths. Findings still go through human review before a client sees them.

IEEE ICMLA 2015. Interactive evolutionary computation, human in the loop.

Aludra

Security engineering leadership

Runs the practice: who is on the engagement, how quality is held, and how findings move from operator judgment to a client-ready report. Mentors, staffs, and trains the engineering team.

COO; leads all engineering at Open Security

Penetration testing

Still a technical operator’s eye on scoping, methodology, and the difference between a finding that scores high and one that is exploitable. Network, application, and cloud tests.

OSCP, OSCE

Penetration testing services

Red teaming

Built a red team from the ground up in fintech: hiring, training path, and how the function ran. Tests CVEs against the stack and sits in on incident response.

Threat simulation

Application security

Directed an AppSec program, put SAST into the development workflow, and tested more than 20 applications a year against a regulated standard.

Application testing

Experience & background

How the authority was earned.

As COO, Josh owns engagement delivery and the engineering organization behind it. That includes Aludra: the continuous penetration testing environment built on Open Security’s methodology. If a test is mis-scoped or a finding is not ready, it stops with him.

His applied-AI work started at the Air Force Institute of Technology. The 2015 IEEE ICMLA paper and conference presentation, Augmenting Interactive Evolution with Multi-objective Optimization, treated the operator as part of the search, not a reviewer after the fact. That human-in-the-loop stance is the same one Aludra takes: automation does the groundwork, operators make the calls.

He was a founding member of the Air Force Academy cyber competition team, with a dual B.S. in computer engineering and computer science. Undergraduate Cyber Training named him top overall graduate.

Air Force service ran through certified exploitation operations for NSA/CSS and, as a captain, rapid capability development for the Cyber National Mission Force: 35-plus joint developers and 100-plus capabilities across three organizations.

After the service he built Finance of America’s red team from scratch and ran AppSec to a regulated testing cadence. He returned to Open Security as COO.

His published writing on the ChatGPT SSRF discovery is a window into the standard he sets: curiosity first, then disciplined confirmation, then a finding someone will sign.

Credentials

  • Offensive Security Certified Expert (OSCE), Oct 2018
  • Offensive Security Certified Professional (OSCP), Mar 2018
  • IEEE ICMLA 2015, paper and conference presentation
  • M.S., Computer Engineering, Air Force Institute of Technology
  • B.S., Computer Engineering and Computer Science, U.S. Air Force Academy
  • U.S. Air Force veteran, cyberwarfare officer
  • Undergraduate Cyber Training, top overall graduate
IEEE 2015 paper and conference presentation
ICMLA

IEEE 2015 paper and conference presentation

Offensive Security Certified Expert
OSCE

Offensive Security Certified Expert

  1. 2023–present

    Chief Operating Officer

    Open Security

    Leads all engineering, including Aludra. Continuous penetration testing that operators review before a finding ships.

  2. 2021–2023

    Director of Offensive Security

    Finance of America

    Directed AppSec and built the red team from scratch: hiring, training path, and how the function ran. Tested CVEs against the stack and more than 20 applications a year.

  3. 2020–2021

    Senior security engineer

    PLEX Solutions

    Android reverse engineering, vulnerability research, and corporate pentests. Designed a cloud endpoint-security product through internal beta.

  4. 2018–2020

    Rapid development manager

    Cyber National Mission Force

    Officer-in-charge, captain, USAF. Led 35-plus joint developers building high-priority capabilities. Production, testing, and deployment of 100-plus tools across three development organizations.

  5. 2015–2018

    Exploitation operator

    NSA/CSS

    Certified exploitation operator. Computer network exploitation for foreign intelligence collection, tactical malware forensics, and post-operation briefs to senior leadership.

Featured media

Watch, listen, or read first.

Research

Augmenting Interactive Evolution with Multi-objective Optimization

Josh’s AFIT graduate paper, presented at IEEE ICMLA 2015. Interactive evolutionary computation with the operator in the search, the same human-in-the-loop stance Aludra takes today.

IEEE ICMLA · December 2015

Read the IEEE paper (opens in a new tab, IEEE ICMLA)

Training & appearances

Rooms Josh has been in.

Previous

  • December 2015

    IEEE International Conference on Machine Learning and Applications

    Speaker · Full paper and conference presentation of Augmenting Interactive Evolution with Multi-objective Optimization.

    Site
  • November 2025

    Open Security engineering essay

    Host · What the ChatGPT SSRF finding says about how the team tests

    Site

Social presence

Follow Josh.

Media kit

Use the approved facts.

For event organizers, podcast hosts, journalists, and partners. Copy or download — do not invent a bio.

Short biography

Josh Christman is Chief Operating Officer at Open Security, where he runs security engineering and the applied AI behind Aludra. An OSCP and OSCE, he presented interactive-evolution research at IEEE ICMLA in 2015 and oversees engagement delivery and the operator-built platform behind the work.

Extended biography

Josh Christman is the Chief Operating Officer of Open Security. He leads security engineering across penetration testing, red teaming, application security, and Aludra, the continuous penetration testing environment operators use to prove what is exploitable. He holds OSCP and OSCE certifications, a B.S. in computer engineering and computer science from the U.S. Air Force Academy, and an M.S. in computer engineering from the Air Force Institute of Technology. In 2015 he presented Augmenting Interactive Evolution with Multi-objective Optimization at IEEE ICMLA: human-in-the-loop evolutionary search, the same stance Aludra takes with operators in the loop. His Air Force career included certified exploitation operations for NSA/CSS and rapid capability development for the Cyber National Mission Force. After leaving the service he directed offensive security at Finance of America, then returned to Open Security as COO. He is the executive who keeps every test scoped to the client’s business risk and every published finding tied to a decision leadership can act on.

Title

Chief Operating Officer

Pronunciation

KRIST-man

Approved headshot

Download portrait

Media contact

contact@opensecurity.ioBook a conversation

Suggested interview topics

  • Human-in-the-loop AI for offensive security
  • How Aludra scales operator methodology without replacing judgment
  • Interactive evolutionary computation, from ICMLA 2015 to production
  • How a technical practice holds quality at growing volume
  • What the ChatGPT SSRF finding taught the industry about AI features

Suggested speaking topics

  • Applied AI in a practitioner pentest practice
  • Keeping operators in the loop when testing is continuous
  • Running a modern offensive-security practice
  • Assume-breach testing as defense in depth

Open Security

Open Security is a veteran-owned, operator-led cybersecurity firm. We run adversarial testing that uncovers exploitable risk, then hand clients the decision intelligence to act — backed by the platform our operators built.

Talk through a security challenge with the people who run the work.

Josh’s organization scopes, executes, and reviews every engagement. Start with a conversation about what you actually need tested. To invite him to speak, book a short conversation first.