Josh Grossman -- Building a High-Value AppSec Scanning Program episode artwork

EPISODE · Apr 19, 2022 · 43 MIN

Josh Grossman -- Building a High-Value AppSec Scanning Program

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Josh Grossman has over 15 years of experience in IT Risk and Application Security consulting, and he has also worked as a software developer. He currently works as CTO for Bounce Security, where he focuses on helping organizations build secure products by providing value-driven Application Security support and guidance. In his spare time, he is very involved with OWASP. He is on the OWASP Israel chapter board, he is a co-leader of the OWASP Application Security Verification Standard project, and he has contributed to various other projects as well, including the Top 10 Risks, Top Ten Proactive Controls and JuiceShop projects. We hope you enjoy this conversation with...The Application Security Podcast is brought to you by Security Journey.About Security JourneyJosh Grossman has over 15 years experience in IT risk and application security consulting, and he's also worked as a software developer.→ Learn more about Security JourneyConnect with Josh Grossman:→ OWASP Application Security Verification Standard (ASVS)→ OWASP Juice ShopMentioned in this episode:→ OWASP Application Security Verification Standard (ASVS)→ OWASP Juice Shop→ Alyssa Miller→ Avi Douglen on Twitter→ SAST, DAST, IAST, and RASP: Pros, cons and how to chooseFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Josh Grossman: Building a High-Value AppSec Scanning Program02:10 So our guest today is Josh Grossman. Josh is, this is04:02 Yeah, no, that's cool. Avi's a good friend of ours and07:46 Josh, today's topic, we're going to be focusing on something you10:26 So before we dive deeper into this, I think it would13:08 Would you lump IAST then, interactive application security testing, into kind14:44 We got to put together a solid AppSec scanning program. Where'd19:34 Josh, we've talked about the importance of these tools, and none25:51 Specific definition in the world of OWASP, right32:26 Yeah, I was going to say the sunk cost analysis is34:35 I mean, push the envelope. I mean, I wouldn't buy an37:01 That's another problem. When I think about, and that's a whole

Episode metadata supplied by the publisher feed · Published Apr 19, 2022

Embed this episode

Josh Grossman has over 15 years of experience in IT Risk and Application Security consulting, and he has also worked as a software developer. He currently works as CTO for Bounce Security, where he focuses on helping organizations build secure products by providing value-driven Application Security support and guidance. In his spare time, he is very involved with OWASP. He is on the OWASP Israel chapter board, he is a co-leader of the OWASP Application Security Verification Standard project, ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Josh Grossman -- Building a High-Value AppSec Scanning Program

0:00 43:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 43 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on April 19, 2022.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!