Description
Josh has worked as a consultant in IT and Application Security and Risk for 15 years now, as well as a Software Developer. In that time he has seen the good, the bad and the stuff which is sadly/luckily still covered by an NDA. This has given him an in-depth understanding of how to manage the balance between business needs, developer needs and security needs which goes into a successful software security programme.
As CTO for Bounce Security, he helps clients improve and get better value from their application security processes and provides specialist application security advice. His consultancy work has led him to work, speak and deliver training both locally and worldwide including privately for ISACA and Manicode and publicly for OWASP’s Global AppSec conferences, NDC Security and Black Hat.
In his spare time, he co-leads the OWASP Application Security Verification Standard project and is on the OWASP Israel chapter board and the OWASP Events Committee. In 2025, OWASP recognised his contributions with a Distinguished Lifetime Membership award.
Back to Our Team
Josh Grossman's upcoming events:
Training at OWASP Global AppSec Vienna 2026
Repeatable, Scalable, and Valuable Code Security Scanning
(Read more about this course)
Training at BlackHat USA 2026
Achieving Scalable Code Security Scanning through AI Acceleration
(Read more about this course)
Josh Grossman's previous appearances:
Podcast with ICodeWith.ai
Pre-Launch Security Essentials for Vibe Coded Apps
DEF CON 2025 - OWASP Community
Vibe Coding: Security Crisis or Opportunity
DEF CON 2025 - OWASP Community
Whitehats Secret Weapon: OWASP
Training at BlackHat USA 2025
Accelerated AppSec – Hacking your Product Security Programme for Velocity and Value
(Read more about this course)
Video Interview with ITSPmagazine
Introducing the OWASP ASVS 5.0 release
Training at OWASP Global AppSec Barcelona 2025
Building a High-Value AppSec Scanning Programme
(Read more about this course)
Training at BlackHat USA 2024
Accelerated AppSec – Hacking your Product Security Programme for Velocity and Value (Virtual)
(Read more about this course)
Training at OWASP Global AppSec Lisbon 2024
Building a High-Value AppSec Scanning Programme
(Read more about this course)
BrakeSec Education Podcast
Building AppSec programs and bridging security and developer gaps
Cyber Security Virtual Meetups
Talk title: The Real AppSec Issues
NDC Security 2024 (Conference)
Tune your Toolbox for Velocity and Value
NDC Security 2024 (Conference)
Discover your inner security engineer with this one weird trick (hackers hate it!)
NDC Security 2024 (Workshops)
Building a High-Value AppSec Scanning Programme
(Read more about this course)
DeveloperWeek Enterprise 2023
Discover Your Inner Security Engineer with This One Weird Trick (Hackers Hate It!)
Training at BlackHat USA 2023
Building a High-Value AppSec Scanning Programme (SCA, SAST, DAST and More)
(Read more about this course)
PyCon Israel 2023
Omniscient AppSec- Custom, Continuous Security Verification of Python Code
DevTalks Romania
Building a Sustainable Security Requirements Process With the ASVS
OWASP 2023 Virtual June Training
Application Security Awareness and Security Requirements with the OWASP ASVS
OWASP Netherlands
The Rise of the Security Verification Standard
QCon London 2023
Sustainable Security Requirements with the ASVS
Security Weekly
The OWASP ASVS and Sustainable Software Security Practices
OWASP Global AppSec Dublin 2023
Building a High-Value AppSec Scanning Programme - (Training)
(Read more about this course)
(ISC)2 Meetup February 2023
Talk title: The Real AppSec Issues
NDC Security 2023 (Conference)
Building a sustainable security requirements process with the ASVS
Down the Security Rabbithole Podcast (DtSR)
Episode 534 - The AppSec is Still a Mess
OWASP Global AppSec San Francisco 2022
The Rise of the Security Verification Standard
OWASP Global AppSec San Francisco 2022
Building a High-Value AppSec Scanning Programme (Training)
(Read more about this course)
Application Security podcast
Building a High-Value AppSec Scanning Program
DevSec For Scale Podcast
Proactively Building Secure Software
Open Security Summit
Tune Your Toolbox for Velocity and Value (SCA)
DevSecCon Lightning
Count Up From Zero Day - when a critical vulnerability takes you by surprise
MyDevSecOps Livestream
Panel - The State of Open-Source Security
OWASP AppSec USA 2018
How to get the best AppSec test of your life
OWASP AppSec Israel 2017
How to get the best AppSec test of your life

