Measuring and evolving application security programs – metrics and insights that matter with Josh Grossman



We will discuss with Josh Grossman techniques to start and improve the precision of vulnerabilities scanning and discuss the vulnerability maturity model and framework

Audience recommendation:

  • Application Security and Product Security team leaders and members
  • Security Engineers with a software focus
  • Developers with an interest in security
  • CISOs interested in Secure SDLC and how to start a programme

In this webinar, we will discuss

  • Josh’s background and experience and what he has been working on recently
  • Trends that Josh sees in the application security industry
  • Key challenges which organizations face with application vulnerability scanning tools
  • Vulnerability management framework – from detection to measurement to actions 
  • A four step action plan to better address challenges with these tools:

  • Plan for where to start
  • Get buy-in from the business and the development organization.
  • Do and Measure – metrics that matter 
  • Improve – where do we go next

Metrics and measurements are also available and widely discussed in this whitepaper:

Data-driven approach on vulnerability management

We will refer to some of the framework models in the following articles:

See also the training that Josh is delivering on this topic at Black Hat USA:–a-high-value-appsec-scanning-programme-sca-sast-dast-and-more-30622

Watch live:

See also the training that Josh is delivering on this topic at Black Hat USA:–a-high-value-appsec-scanning-programme-sca-sast-dast-and-more-30622

Background about the speaker – Josh Grossman

Josh Grossman has worked as a consultant in IT and Application Security and Risk for 15 years now, as well as a Software Developer. This has given him an in-depth understanding of how to manage the balance between business needs, developer needs and security needs which goes into a successful software security programme.

Josh is currently CTO for Bounce Security where he helps clients improve and get better value from their application security processes and provides specialist application security advice. His consultancy work has led him to work, speak and deliver training both locally and worldwide including privately for ISACA and Manicode and publicly for OWASP’s Global AppSec conferences.

In his spare time, he co-leads the OWASP Application Security Verification Standard project and is on the OWASP Israel chapter board. 


Francesco Cipollone (host)

Francesco is a seasoned entrepreneur, CEO of the Contextual-based vulnerability management platform from code to cloud Phoenix Security, author of several books, host of multi-award Cyber Security & Cloud Podcast, speaker and known in the cybersecurity industry and recognized for his visionary views. He currently serves as Chapter Chair UK&I of the Cloud Security Alliance. Previously, Francesco headed HSBC’s application and cloud security and was Senior Security Consultant at AWS. Francesco has been keynoting at global conferences and has authored and co-authored several books. Outside of work, you can find me running marathons, snowboarding on the Italian slopes, and enjoying single malt whiskeys in one of my favourite London clubs.

Main information


Phoenix Security

From our Events

Join our Mailing list!

Get all the latest news, exclusive deals, and feature updates.

x Logo: ShieldPRO
This Site Is Protected By