Josh Grossman (tghosth👻) :verified:

Your friendly AppSec Ghost 👻 | Personal account, content does not represent my employer. | Board member at twitter.com/OWASP_IL
| Project leader at twitter.com/OWASP_ASVS

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-06-12
Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-06-12

So you have a great training course with super-cool interactivity, now you have to get it accepted.

In my next blogpost, I talk about writing a proposal which appeals to both the review board and also your potential attendees.

Check it out here:
bouncesecurity.com/blog/2025/0

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-06-11

Last week, I was honoured to received a Distinguished Lifetime Member award from OWASP at Global AppSec EU Barcelona 2025.

I wrote more about it here:
linkedin.com/posts/joshcgrossm

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-05-13

@raesene thanks :)

I'm sorry but I have no specific recommendations on the cloud side, most of my focus as been on the group style exercises.

Iximiuz does look interesting

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-05-13

Link to the new post is here and don't forget to check out my other posts in this series "So you want to train at Black Hat (or other conferences)?"

bouncesecurity.com/blog/2025/0

#BlackHat #Training #OWASP #AppSec

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-05-13

Want to make your security training course memorable? 🎯

My latest post dives into creative ways to get students' hands dirty, from cloud-hosted labs to simulated stakeholder exercises. Learn how to make practical exercises the highlight of your course, not just an afterthought.

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-04-21

My blog series on developing training courses continues with a post about how to find the topic you are passionate about and that will also attract attendees:

bouncesecurity.com/blog/2025/0

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-04-02

@raesene yeah that's what I get for releasing a blog post on 1st April, it's definitely available now :)

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-04-01

You can see the previous posts in this series here:
infosec.exchange/@JoshCGrossma

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-04-01

So, you've decided you want to deliver training courses at a conference?

In the next post in my series about my experiences, I want to talk about money. I don't think it should be your main motivation but you probably can't ignore it!

Check it out:
bouncesecurity.com/blog/2025/0

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-31

I will be publishing the next post in this series tomorrow so look out for it!
infosec.exchange/@JoshCGrossma

Josh Grossman (tghosth👻) :verified: boosted:
Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-27

This year should hopefully be the 3rd year that I train at @BlackHatEvents #BHUSA and also at @owasp #AppSecEU?

But how did I get to this stage?

The short answer is a lot of thought and hard work.

And the long answer?

Well I thought I'd write some thoughts down...

🧵 1/x

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-24

In the second post, I talk about my motivation behind getting to this stage. This wasn't an any easy process and it took a lot of work to get to the required level.

If this is something you are considering doing, you need to be ready to commit.

bouncesecurity.com/blog/2025/0

🧵4/x

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-24

In the first post I explain a little more about the rationale behind the series and the sorts of topics I will be covering.

Feel free to reach out to me if you have questions on specific topics or other ideas 😀

bouncesecurity.com/blog/2025/0

🧵3/x

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-24

"Some thoughts" turned into a multi-post blog series which I have been writing for a while and I am now determined to get it polished up and finalised over the next few months.

For now, I have published the first two parts.

🧵2/x

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-24

This year should hopefully be the 3rd year that I train at @BlackHatEvents #BHUSA and also at @owasp #AppSecEU?

But how did I get to this stage?

The short answer is a lot of thought and hard work.

And the long answer?

Well I thought I'd write some thoughts down...

🧵 1/x

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-18
Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-18

At @BlackHatEvents #BHUSA on 4-5 Aug in Las Vegas, you can attend "Accelerated AppSec: Hacking your Product Security Programme for Velocity and Value".

This course helps you build a successful programme to bridge the gap between developers and security, without losing speed.
4/5

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-18

You can register for that course here:
owasp2025globalappseceu.sched.

Alternatively, you can see much more info on the course including explanatory videos here:
bouncesecurity.com/training/va
3/5

Josh Grossman (tghosth👻) :verified:JoshCGrossman@infosec.exchange
2025-03-18

At #GlobalAppSec EU on 26-27 May at the CCIB in Barcelona, you can attend "Building a High-Value AppSec Scanning Programme", with big updates for 2025.

If you want to build effective and valuable processes around tools like SAST, DAST and SCA, this is the course for you.
2/5

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst