Josh Grossman--AI & SAST: Is it a match?
Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better?
Listen to the episodeGuest
Josh Grossman has worked as a consultant in IT and Application Security and Risk for 15 years now, as well as a Software Developer. This has given him an in-depth understanding of how to manage the balance between business needs, developer needs and security needs which goes into a successful software security programme. Josh is currently CTO for Bounce Security where he helps clients improve and get better value from their application security processes and provides specialist application security advice. His consultancy work has led him to work, speak and deliver training both locally and worldwide including privately for ISACA and Manicode and publicly for OWASP's Global AppSec conferences, NDC Security and Black Hat. In his spare time, he co-leads the OWASP Application Security Verification Standard project and is on the OWASP Israel chapter board and the OWASP Events Committee. In 2025, OWASP recognised his contributions with a Distinguished Lifetime Membership award.
Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better?
Listen to the episodeJosh Grossman has over 15 years of experience in IT Risk and Application Security consulting, and he has also worked as a software developer.
Listen to the episodeWhat can the wider AppSec community learn from Israel’s unusually dense security ecosystem?
Listen to the episode