The Operator’s Perspective
Matt Toussain
Founder & Chief Information Officer
Offensive security operator, SANS instructor, and the founder behind Sirius — turning real attack experience into the methodology and tools other operators use.
- Offensive security
- Vulnerability operations
- Cybersecurity training

Introduction
Matt Toussain is the founder and CIO of Open Security, a SANS instructor, and IANS Faculty. He is known for building tools operators actually want to use — from Subterfuge at DEF CON 20 to Sirius, the open-source scanner behind Open Security’s vulnerability practice — and for teaching threat and vulnerability assessment to practitioners worldwide. Invite him when the audience needs someone who has run the missions, written the course, and shipped the software.
“Vulnerabilities should form a map to making risk actual. Too often the tools in this space get in the operator’s way.”
Expertise
Where Matt leads.
Offensive security
Hands-on exploitation, threat emulation, and adversary tactics — from Air Force cyber operations to commercial red-team and pen-test work.
Former USAF senior cyber tactics development lead; BHIS and CounterHack analyst
Penetration testingVulnerability operations
Treats vulnerability intelligence as an operator’s map, not a scanner dump. Built Sirius so practitioners can move from finding to proof.
Creator of the Sirius vulnerability scanning engine
Explore SiriusCybersecurity training
Designs and delivers practitioner education at industry scale — courseware, live instruction, and conference talks that become curriculum.
Author of SANS SEC460; certified SANS instructor; IANS Faculty
Open Security trainingProduct innovation
Ships tools the people doing the work will actually run — Subterfuge, Sirius, and the operator workflows behind Open Security’s platform.
Founder of Open Security; lead developer, Subterfuge (DEF CON 20)
Experience & background
How the authority was earned.
As founder and CIO, Matt sets the technical direction of Open Security: the methodology behind every engagement, the engineering behind Sirius, and the standard that findings must be defensible.
He came up through Air Force cyber training and tactics development — including curriculum work at Undergraduate Cyber Training and leading tactics teams in San Antonio — then took that tradecraft into commercial assessment work and into the company he founded in 2014.
Teaching is not a side project. He authored SANS SEC460, instructs for SANS, sits on IANS Faculty, and has guest-lectured and keynoted at the conferences where operators actually show up.
Credentials
- GIAC Security Expert (GSE #130)
- GPEN, GXPN, GSEC, GCIA, GCIH, GMOB, GCPM, GCCC
- Security+, CEH
- M.S., Information Security Engineering — SANS Technology Institute
- B.S., Computer Science — U.S. Air Force Academy
- 2014 SANS NetWars Tournament of Champions — Grand Champion
- GIAC Security Expert
- GSE #130
- SANS course author
- SEC460
GIAC Security Expert
SANS course author
2014–present
Founder & CIO
Open Security
Founded the firm; leads offensive research and the engineering direction behind Sirius.
2023–present
Faculty
IANS
Advises security leaders on threat and vulnerability assessment, red/purple teaming, and IAM.
2017–2019
Senior information security analyst
Black Hills Information Security & CounterHack
Commercial assessment and challenge-design work alongside Open Security.
2011–2017
Cyber tactics & training
United States Air Force
Senior tactics development team lead; curriculum developer; commander of Cyber 256 at the Air Force Academy.
2012
Subterfuge released
DEF CON 20
Launched the automated man-in-the-middle exploitation framework to the public.
Featured media
Watch, listen, or read first.
Video
A Pentester’s Warning: AI Broke Cybersecurity (Here’s the Fix)
Matt joins The Phillip Wylie Show to talk career path, Sirius, open-source contribution, and what AI is actually changing in offensive security and vulnerability management.
The Phillip Wylie Show · June 2025 · Video
Watch (opens in a new tab, The Phillip Wylie Show)Captions are available in the YouTube player.
Content library
Talks, writing, and teaching.

Video
A Pentester’s Warning: AI Broke Cybersecurity (Here’s the Fix)
Career path, Sirius, and how AI is changing offensive security — Matt as CIO of Open Security.
The Phillip Wylie Show · June 2025 · Video
Watch on The Phillip Wylie Show (opens in a new tab)Podcast
Matt Toussain: From JAG Aspirations to Cybersecurity
Episode write-up covering Matt’s path from Air Force legal aspirations into offensive security, open source, and vulnerability management.
The Phillip Wylie Show / The Hacker Maker · June 30, 2025
Read & listen on The Phillip Wylie Show / The Hacker Maker (opens in a new tab)Interview
Matthew Toussain, IANS Faculty
Faculty profile covering red/purple teaming, vulnerability management, modern web app security, and SEC460.
IANS Research · 2023
View profile on IANS Research (opens in a new tab)Article
Matthew Toussain — SC Media contributor
Contributor biography and industry commentary from Open Security’s founder and CIO.
SC Media · 2024
View contributor on SC Media (opens in a new tab)Event
Vulnerability-centric pentesting
How Sirius Scan lets operators treat vulnerabilities as a map to real risk — Wild West Hackin’ Fest Deadwood.
Wild West Hackin’ Fest · October 11, 2024 · 50 min
View session on Wild West Hackin’ Fest (opens in a new tab)Event
Be Evil | A toolset for Tier 1 threat emulation
Threat-emulation tooling talk at Wild West Hackin’ Fest 2019.
Wild West Hackin’ Fest · October 25, 2019
View listing on Wild West Hackin’ Fest (opens in a new tab)Event
Gryffindor | Pure JavaScript, covert exploitation
Covert browser-side exploitation research at DerbyCon 8.0.
DerbyCon 8.0 · October 5, 2018
View listing on DerbyCon 8.0 (opens in a new tab)Event
Subterfuge: The automated man-in-the-middle attack framework
Public release of Subterfuge at DEF CON 20 — 150,000+ unique downloads since.
DEF CON 20 · July 29, 2012
View listing on DEF CON 20 (opens in a new tab)Research
Sirius Scan — open-source vulnerability scanner
Operator-first scanner with automated discovery, CVE detection, remote agents, and a modern UI. Built by Matt and the Open Security team.
GitHub / SiriusScan · Ongoing
View repository on GitHub / SiriusScan (opens in a new tab)Training
SANS SEC460: Enterprise and Cloud | Threat and Vulnerability Assessment
Course Matt authored for SANS — enterprise and cloud threat and vulnerability assessment for working practitioners.
SANS Institute · Ongoing
View credentials on SANS Institute (opens in a new tab)Training & appearances
Rooms Matt has been in.
Previous
June 2025
WatchThe Phillip Wylie Show
Guest · AI, Sirius, and a career in offensive security · Podcast / YouTube
October 11, 2024
SiteWild West Hackin’ Fest — Deadwood
Speaker · Vulnerability-centric pentesting · Deadwood, SD
October 25, 2019
SiteWild West Hackin’ Fest
Speaker · Be Evil | A toolset for Tier 1 threat emulation · Deadwood, SD
October 5, 2018
SiteDerbyCon 8.0
Speaker · Gryffindor | Pure JavaScript, covert exploitation · Louisville, KY
July 29, 2012
SiteDEF CON 20
Speaker · Subterfuge: The automated man-in-the-middle attack framework · Las Vegas, NV
Ongoing
SANS Institute
Instructor · SEC460 and practitioner seminars worldwide · Global
Media kit
Use the approved facts.
For event organizers, podcast hosts, journalists, and partners. Copy or download — do not invent a bio.
Short biography
Matt Toussain is the founder and CIO of Open Security, a SANS instructor, and IANS Faculty. A former U.S. Air Force cyber tactics lead, he created the Sirius vulnerability scanner and authored SANS SEC460.
Extended biography
Matt Toussain is the founder and Chief Information Officer of Open Security, an information security firm specializing in adversarial testing and operator-built tooling. He served as senior cyber tactics development lead for the U.S. Air Force and later as a security analyst with Black Hills Information Security and CounterHack Challenges. A certified SANS instructor and IANS Faculty member, he authored SANS SEC460: Enterprise and Cloud | Threat and Vulnerability Assessment and created Sirius, an open-source vulnerability scanning engine designed for operators. Matt is a GIAC Security Expert (GSE #130) and a graduate of the U.S. Air Force Academy (B.S., computer science) and the SANS Technology Institute (M.S., information security engineering). He has spoken at DEF CON, RSA, DerbyCon, and Wild West Hackin’ Fest. In 2014 he was Grand Champion of the SANS NetWars Tournament of Champions. Contact: matt@opensecurity.io or via Open Security media.
Title
Founder & Chief Information Officer
Pronunciation
too-SAYN
Approved headshot
Download portraitMedia contact
contact@opensecurity.ioBook a conversationSuggested interview topics
- Vulnerability-centric penetration testing
- Why operators need different scanners than compliance programs
- Building Sirius as open-source infrastructure
- Teaching offensive security without theater
- AI’s real impact on vulnerability management
- From Air Force cyber operations to a commercial practice
Suggested speaking topics
- Vulnerability-centric pentesting and Sirius Scan
- Threat and vulnerability assessment for the enterprise and cloud
- Open-source contribution as a path into offensive security
- Threat emulation tooling and operator workflows
Open Security
Open Security is a veteran-owned, operator-led cybersecurity firm. We run adversarial testing that uncovers exploitable risk, then hand clients the decision intelligence to act — backed by the platform our operators built.
Related experts
Keep reading the practice.

Josh Christman
Chief Operating Officer
COO who runs security engineering and the applied AI behind Aludra. Tests stay scoped to business risk. Findings stay ones an engineer will stand behind.
View profile →
Bryce Zuccaro
Principal Security Engineer
Principal Security Engineer who plans engagements, mentors operators, and teaches the craft — SANS SEC460, Red Team Village, and the Las Vegas AI Security Forum.
View profile →
Michael Pleasant
Chief Executive Officer
Marine Corps veteran and co-founder who built Open Security to make operator-grade cybersecurity accessible to the businesses that actually need it.
View profile →Invite Matt to speak — or put Sirius in front of your team.
Book Matt for a conference, podcast, or private briefing. Or talk to Open Security about the vulnerability practice he built.
