Hi there! My name is Josh Grossman and my job/passion is helping organizations to build secure software!

🎉🎉I am teaching at Black Hat USA 2023! Click here more information! 🎉🎉

This is the site where I occasionally jot down my thoughts on related topics or problems I came across along the way.

I generally go by my real name but in some places I use my handles “tghosth” or “AppSec Ghost”, hence my avatar.

If you are looking for help building or getting higher value from your Application Security Programme, your best option is to contact me on my work address josh@bouncesecurity.com. For more information, see the Bounce Security website.


  • You can find more information on my experience on my “About” page.
  • If you are interested in me speaking at your event, see my “Talks” page.
  • You can find my blog on the “Posts” page.
  • You can find my contact details on the “Contact” page.