The Operator’s Perspective
Josh Christman
Chief Operating Officer
COO who runs security engineering and the applied AI behind Aludra. Tests stay scoped to business risk. Findings stay ones an engineer will stand behind.
- Applied AI
- Aludra
- Security engineering
- Penetration testing

Introduction
Josh Christman is Open Security’s Chief Operating Officer. He runs security engineering and the product work behind Aludra, the continuous penetration testing environment operators use to prove what is exploitable. His AFIT master’s research on interactive evolutionary computation, presented at IEEE ICMLA in 2015, is the same idea at work: search at machine scale, keep judgment with the operator. Invite him when you want to talk about how a technical practice uses AI without handing the calls to a model.
“We don’t look for checkboxes. We look for what’s possible — the same curiosity we train into every assessment.”
Expertise
Where Josh leads.
Applied AI and Aludra
Leads the engineering behind Aludra, Open Security’s continuous penetration testing environment. Operators own the methodology. Aludra scales discovery, exploitation, and validation so they spend time on judgment and complex paths. Findings still go through human review before a client sees them.
IEEE ICMLA 2015. Interactive evolutionary computation, human in the loop.
AludraSecurity engineering leadership
Runs the practice: who is on the engagement, how quality is held, and how findings move from operator judgment to a client-ready report. Mentors, staffs, and trains the engineering team.
COO; leads all engineering at Open Security
Penetration testing
Still a technical operator’s eye on scoping, methodology, and the difference between a finding that scores high and one that is exploitable. Network, application, and cloud tests.
OSCP, OSCE
Penetration testing servicesRed teaming
Built a red team from the ground up in fintech: hiring, training path, and how the function ran. Tests CVEs against the stack and sits in on incident response.
Threat simulationApplication security
Directed an AppSec program, put SAST into the development workflow, and tested more than 20 applications a year against a regulated standard.
Application testingExperience & background
How the authority was earned.
As COO, Josh owns engagement delivery and the engineering organization behind it. That includes Aludra: the continuous penetration testing environment built on Open Security’s methodology. If a test is mis-scoped or a finding is not ready, it stops with him.
His applied-AI work started at the Air Force Institute of Technology. The 2015 IEEE ICMLA paper and conference presentation, Augmenting Interactive Evolution with Multi-objective Optimization, treated the operator as part of the search, not a reviewer after the fact. That human-in-the-loop stance is the same one Aludra takes: automation does the groundwork, operators make the calls.
He was a founding member of the Air Force Academy cyber competition team, with a dual B.S. in computer engineering and computer science. Undergraduate Cyber Training named him top overall graduate.
Air Force service ran through certified exploitation operations for NSA/CSS and, as a captain, rapid capability development for the Cyber National Mission Force: 35-plus joint developers and 100-plus capabilities across three organizations.
After the service he built Finance of America’s red team from scratch and ran AppSec to a regulated testing cadence. He returned to Open Security as COO.
His published writing on the ChatGPT SSRF discovery is a window into the standard he sets: curiosity first, then disciplined confirmation, then a finding someone will sign.
Credentials
- Offensive Security Certified Expert (OSCE), Oct 2018
- Offensive Security Certified Professional (OSCP), Mar 2018
- IEEE ICMLA 2015, paper and conference presentation
- M.S., Computer Engineering, Air Force Institute of Technology
- B.S., Computer Engineering and Computer Science, U.S. Air Force Academy
- U.S. Air Force veteran, cyberwarfare officer
- Undergraduate Cyber Training, top overall graduate
- IEEE 2015 paper and conference presentation
- ICMLA
- Offensive Security Certified Expert
- OSCE
IEEE 2015 paper and conference presentation
Offensive Security Certified Expert
2023–present
Chief Operating Officer
Open Security
Leads all engineering, including Aludra. Continuous penetration testing that operators review before a finding ships.
2021–2023
Director of Offensive Security
Finance of America
Directed AppSec and built the red team from scratch: hiring, training path, and how the function ran. Tested CVEs against the stack and more than 20 applications a year.
2020–2021
Senior security engineer
PLEX Solutions
Android reverse engineering, vulnerability research, and corporate pentests. Designed a cloud endpoint-security product through internal beta.
2018–2020
Rapid development manager
Cyber National Mission Force
Officer-in-charge, captain, USAF. Led 35-plus joint developers building high-priority capabilities. Production, testing, and deployment of 100-plus tools across three development organizations.
2015–2018
Exploitation operator
NSA/CSS
Certified exploitation operator. Computer network exploitation for foreign intelligence collection, tactical malware forensics, and post-operation briefs to senior leadership.
Featured media
Watch, listen, or read first.

Research
Augmenting Interactive Evolution with Multi-objective Optimization
Josh’s AFIT graduate paper, presented at IEEE ICMLA 2015. Interactive evolutionary computation with the operator in the search, the same human-in-the-loop stance Aludra takes today.
IEEE ICMLA · December 2015
Read the IEEE paper (opens in a new tab, IEEE ICMLA)Featured insights
Selected work and coverage.
Training & appearances
Rooms Josh has been in.
Previous
December 2015
SiteIEEE International Conference on Machine Learning and Applications
Speaker · Full paper and conference presentation of Augmenting Interactive Evolution with Multi-objective Optimization.
November 2025
SiteOpen Security engineering essay
Host · What the ChatGPT SSRF finding says about how the team tests
Media kit
Use the approved facts.
For event organizers, podcast hosts, journalists, and partners. Copy or download — do not invent a bio.
Short biography
Josh Christman is Chief Operating Officer at Open Security, where he runs security engineering and the applied AI behind Aludra. An OSCP and OSCE, he presented interactive-evolution research at IEEE ICMLA in 2015 and oversees engagement delivery and the operator-built platform behind the work.
Extended biography
Josh Christman is the Chief Operating Officer of Open Security. He leads security engineering across penetration testing, red teaming, application security, and Aludra, the continuous penetration testing environment operators use to prove what is exploitable. He holds OSCP and OSCE certifications, a B.S. in computer engineering and computer science from the U.S. Air Force Academy, and an M.S. in computer engineering from the Air Force Institute of Technology. In 2015 he presented Augmenting Interactive Evolution with Multi-objective Optimization at IEEE ICMLA: human-in-the-loop evolutionary search, the same stance Aludra takes with operators in the loop. His Air Force career included certified exploitation operations for NSA/CSS and rapid capability development for the Cyber National Mission Force. After leaving the service he directed offensive security at Finance of America, then returned to Open Security as COO. He is the executive who keeps every test scoped to the client’s business risk and every published finding tied to a decision leadership can act on.
Title
Chief Operating Officer
Pronunciation
KRIST-man
Approved headshot
Download portraitMedia contact
contact@opensecurity.ioBook a conversationSuggested interview topics
- Human-in-the-loop AI for offensive security
- How Aludra scales operator methodology without replacing judgment
- Interactive evolutionary computation, from ICMLA 2015 to production
- How a technical practice holds quality at growing volume
- What the ChatGPT SSRF finding taught the industry about AI features
Suggested speaking topics
- Applied AI in a practitioner pentest practice
- Keeping operators in the loop when testing is continuous
- Running a modern offensive-security practice
- Assume-breach testing as defense in depth
Open Security
Open Security is a veteran-owned, operator-led cybersecurity firm. We run adversarial testing that uncovers exploitable risk, then hand clients the decision intelligence to act — backed by the platform our operators built.
Related experts
Keep reading the practice.

Matt Toussain
Founder & Chief Information Officer
Offensive security operator, SANS instructor, and the founder behind Sirius — turning real attack experience into the methodology and tools other operators use.
View profile →
Bryce Zuccaro
Principal Security Engineer
Principal Security Engineer who plans engagements, mentors operators, and teaches the craft — SANS SEC460, Red Team Village, and the Las Vegas AI Security Forum.
View profile →
Michael Pleasant
Chief Executive Officer
Marine Corps veteran and co-founder who built Open Security to make operator-grade cybersecurity accessible to the businesses that actually need it.
View profile →Talk through a security challenge with the people who run the work.
Josh’s organization scopes, executes, and reviews every engagement. Start with a conversation about what you actually need tested. To invite him to speak, book a short conversation first.
