Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Josh Grossman -- Building a High-Value AppSec Scanning Program

43 min19 april 2022

Om avsnittet

Josh Grossman has over 15 years of experience in IT Risk and Application Security consulting, and he has also worked as a software developer. He currently works as CTO for Bounce Security, where he focuses on helping organizations build secure products by providing value-driven Application Security support and guidance. In his spare time, he is very involved with OWASP. He is on the OWASP Israel chapter board, he is a co-leader of the OWASP Application Security Verification Standard project, and he has contributed to various other projects as well, including the Top 10 Risks, Top Ten Proactive Controls and JuiceShop projects. We hope you enjoy this conversation with...

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Josh Grossman has over 15 years experience in IT risk and application security consulting, and he's also worked as a software developer.
Learn more about Security Journey

Connect with Josh Grossman:
OWASP Application Security Verification Standard (ASVS)
OWASP Juice Shop

Mentioned in this episode:
OWASP Application Security Verification Standard (ASVS)
OWASP Juice Shop
Alyssa Miller
Avi Douglen on Twitter
SAST, DAST, IAST, and RASP: Pros, cons and how to choose

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Josh Grossman: Building a High-Value AppSec Scanning Program
02:10 So our guest today is Josh Grossman. Josh is, this is
04:02 Yeah, no, that's cool. Avi's a good friend of ours and
07:46 Josh, today's topic, we're going to be focusing on something you
10:26 So before we dive deeper into this, I think it would
13:08 Would you lump IAST then, interactive application security testing, into kind
14:44 We got to put together a solid AppSec scanning program. Where'd
19:34 Josh, we've talked about the importance of these tools, and none
25:51 Specific definition in the world of OWASP, right
32:26 Yeah, I was going to say the sunk cost analysis is
34:35 I mean, push the envelope. I mean, I wouldn't buy an
37:01 That's another problem. When I think about, and that's a whole

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.