The Operator’s Perspective

Matt Toussain

Founder & Chief Information Officer

Offensive security operator, SANS instructor, and the founder behind Sirius — turning real attack experience into the methodology and tools other operators use.

  • Offensive security
  • Vulnerability operations
  • Cybersecurity training
Book for an event
Matt Toussain, Founder & Chief Information Officer at Open Security

Introduction

Matt Toussain is the founder and CIO of Open Security, a SANS instructor, and IANS Faculty. He is known for building tools operators actually want to use — from Subterfuge at DEF CON 20 to Sirius, the open-source scanner behind Open Security’s vulnerability practice — and for teaching threat and vulnerability assessment to practitioners worldwide. Invite him when the audience needs someone who has run the missions, written the course, and shipped the software.

“Vulnerabilities should form a map to making risk actual. Too often the tools in this space get in the operator’s way.”

Expertise

Where Matt leads.

Offensive security

Hands-on exploitation, threat emulation, and adversary tactics — from Air Force cyber operations to commercial red-team and pen-test work.

Former USAF senior cyber tactics development lead; BHIS and CounterHack analyst

Penetration testing

Vulnerability operations

Treats vulnerability intelligence as an operator’s map, not a scanner dump. Built Sirius so practitioners can move from finding to proof.

Creator of the Sirius vulnerability scanning engine

Explore Sirius

Cybersecurity training

Designs and delivers practitioner education at industry scale — courseware, live instruction, and conference talks that become curriculum.

Author of SANS SEC460; certified SANS instructor; IANS Faculty

Open Security training

Product innovation

Ships tools the people doing the work will actually run — Subterfuge, Sirius, and the operator workflows behind Open Security’s platform.

Founder of Open Security; lead developer, Subterfuge (DEF CON 20)

Experience & background

How the authority was earned.

As founder and CIO, Matt sets the technical direction of Open Security: the methodology behind every engagement, the engineering behind Sirius, and the standard that findings must be defensible.

He came up through Air Force cyber training and tactics development — including curriculum work at Undergraduate Cyber Training and leading tactics teams in San Antonio — then took that tradecraft into commercial assessment work and into the company he founded in 2014.

Teaching is not a side project. He authored SANS SEC460, instructs for SANS, sits on IANS Faculty, and has guest-lectured and keynoted at the conferences where operators actually show up.

Credentials

  • GIAC Security Expert (GSE #130)
  • GPEN, GXPN, GSEC, GCIA, GCIH, GMOB, GCPM, GCCC
  • Security+, CEH
  • M.S., Information Security Engineering — SANS Technology Institute
  • B.S., Computer Science — U.S. Air Force Academy
  • 2014 SANS NetWars Tournament of Champions — Grand Champion
GIAC Security Expert
GSE #130

GIAC Security Expert

SANS course author
SEC460

SANS course author

  1. 2014–present

    Founder & CIO

    Open Security

    Founded the firm; leads offensive research and the engineering direction behind Sirius.

  2. 2023–present

    Faculty

    IANS

    Advises security leaders on threat and vulnerability assessment, red/purple teaming, and IAM.

  3. 2017–2019

    Senior information security analyst

    Black Hills Information Security & CounterHack

    Commercial assessment and challenge-design work alongside Open Security.

  4. 2011–2017

    Cyber tactics & training

    United States Air Force

    Senior tactics development team lead; curriculum developer; commander of Cyber 256 at the Air Force Academy.

  5. 2012

    Subterfuge released

    DEF CON 20

    Launched the automated man-in-the-middle exploitation framework to the public.

Featured media

Watch, listen, or read first.

Video

A Pentester’s Warning: AI Broke Cybersecurity (Here’s the Fix)

Matt joins The Phillip Wylie Show to talk career path, Sirius, open-source contribution, and what AI is actually changing in offensive security and vulnerability management.

The Phillip Wylie Show · June 2025 · Video

Watch (opens in a new tab, The Phillip Wylie Show)

Captions are available in the YouTube player.

Content library

Talks, writing, and teaching.

Video

A Pentester’s Warning: AI Broke Cybersecurity (Here’s the Fix)

Career path, Sirius, and how AI is changing offensive security — Matt as CIO of Open Security.

The Phillip Wylie Show · June 2025 · Video

Watch on The Phillip Wylie Show (opens in a new tab)

Podcast

Matt Toussain: From JAG Aspirations to Cybersecurity

Episode write-up covering Matt’s path from Air Force legal aspirations into offensive security, open source, and vulnerability management.

The Phillip Wylie Show / The Hacker Maker · June 30, 2025

Read & listen on The Phillip Wylie Show / The Hacker Maker (opens in a new tab)

Interview

Matthew Toussain, IANS Faculty

Faculty profile covering red/purple teaming, vulnerability management, modern web app security, and SEC460.

IANS Research · 2023

View profile on IANS Research (opens in a new tab)

Article

Matthew Toussain — SC Media contributor

Contributor biography and industry commentary from Open Security’s founder and CIO.

SC Media · 2024

View contributor on SC Media (opens in a new tab)

Event

Vulnerability-centric pentesting

How Sirius Scan lets operators treat vulnerabilities as a map to real risk — Wild West Hackin’ Fest Deadwood.

Wild West Hackin’ Fest · October 11, 2024 · 50 min

View session on Wild West Hackin’ Fest (opens in a new tab)

Event

Be Evil | A toolset for Tier 1 threat emulation

Threat-emulation tooling talk at Wild West Hackin’ Fest 2019.

Wild West Hackin’ Fest · October 25, 2019

View listing on Wild West Hackin’ Fest (opens in a new tab)

Event

Gryffindor | Pure JavaScript, covert exploitation

Covert browser-side exploitation research at DerbyCon 8.0.

DerbyCon 8.0 · October 5, 2018

View listing on DerbyCon 8.0 (opens in a new tab)

Event

Subterfuge: The automated man-in-the-middle attack framework

Public release of Subterfuge at DEF CON 20 — 150,000+ unique downloads since.

DEF CON 20 · July 29, 2012

View listing on DEF CON 20 (opens in a new tab)

Research

Sirius Scan — open-source vulnerability scanner

Operator-first scanner with automated discovery, CVE detection, remote agents, and a modern UI. Built by Matt and the Open Security team.

GitHub / SiriusScan · Ongoing

View repository on GitHub / SiriusScan (opens in a new tab)

Training

SANS SEC460: Enterprise and Cloud | Threat and Vulnerability Assessment

Course Matt authored for SANS — enterprise and cloud threat and vulnerability assessment for working practitioners.

SANS Institute · Ongoing

View credentials on SANS Institute (opens in a new tab)

Training & appearances

Rooms Matt has been in.

Previous

  • June 2025

    The Phillip Wylie Show

    Guest · AI, Sirius, and a career in offensive security · Podcast / YouTube

    Watch
  • October 11, 2024

    Wild West Hackin’ Fest — Deadwood

    Speaker · Vulnerability-centric pentesting · Deadwood, SD

    Site
  • October 25, 2019

    Wild West Hackin’ Fest

    Speaker · Be Evil | A toolset for Tier 1 threat emulation · Deadwood, SD

    Site
  • October 5, 2018

    DerbyCon 8.0

    Speaker · Gryffindor | Pure JavaScript, covert exploitation · Louisville, KY

    Site
  • July 29, 2012

    DEF CON 20

    Speaker · Subterfuge: The automated man-in-the-middle attack framework · Las Vegas, NV

    Site
  • Ongoing

    SANS Institute

    Instructor · SEC460 and practitioner seminars worldwide · Global

Media kit

Use the approved facts.

For event organizers, podcast hosts, journalists, and partners. Copy or download — do not invent a bio.

Short biography

Matt Toussain is the founder and CIO of Open Security, a SANS instructor, and IANS Faculty. A former U.S. Air Force cyber tactics lead, he created the Sirius vulnerability scanner and authored SANS SEC460.

Extended biography

Matt Toussain is the founder and Chief Information Officer of Open Security, an information security firm specializing in adversarial testing and operator-built tooling. He served as senior cyber tactics development lead for the U.S. Air Force and later as a security analyst with Black Hills Information Security and CounterHack Challenges. A certified SANS instructor and IANS Faculty member, he authored SANS SEC460: Enterprise and Cloud | Threat and Vulnerability Assessment and created Sirius, an open-source vulnerability scanning engine designed for operators. Matt is a GIAC Security Expert (GSE #130) and a graduate of the U.S. Air Force Academy (B.S., computer science) and the SANS Technology Institute (M.S., information security engineering). He has spoken at DEF CON, RSA, DerbyCon, and Wild West Hackin’ Fest. In 2014 he was Grand Champion of the SANS NetWars Tournament of Champions. Contact: matt@opensecurity.io or via Open Security media.

Title

Founder & Chief Information Officer

Pronunciation

too-SAYN

Approved headshot

Download portrait

Media contact

contact@opensecurity.ioBook a conversation

Suggested interview topics

  • Vulnerability-centric penetration testing
  • Why operators need different scanners than compliance programs
  • Building Sirius as open-source infrastructure
  • Teaching offensive security without theater
  • AI’s real impact on vulnerability management
  • From Air Force cyber operations to a commercial practice

Suggested speaking topics

  • Vulnerability-centric pentesting and Sirius Scan
  • Threat and vulnerability assessment for the enterprise and cloud
  • Open-source contribution as a path into offensive security
  • Threat emulation tooling and operator workflows

Open Security

Open Security is a veteran-owned, operator-led cybersecurity firm. We run adversarial testing that uncovers exploitable risk, then hand clients the decision intelligence to act — backed by the platform our operators built.

Invite Matt to speak — or put Sirius in front of your team.

Book Matt for a conference, podcast, or private briefing. Or talk to Open Security about the vulnerability practice he built.