Lessons Learned: AppSec Role Based Training 5 Years Ups, Downs, Futures @OWASPGLOBAL
Lessons Learned: AppSec Role Based Training 5 Years Ups, Downs, Futures  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 1 week ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/e2/owaspglobalappsecusa2025rolebasedtraining20251106rgrupe-251107131008-999ad18d.pdf

This presentation tells a tale of the design, successes, and challenges of establishing an application security awareness training program for software engineering teams and security compliance advisors: developers, testers, project managers, and management.

Audience: Those who are interested in developing, or enhancing, an application development security program.

Robert Grupe
Cigna--Evernorth
Senior Security Architect & AppSec Evangelist
linkedin.com/in/rgrupe
rgrupeappsecnewsbits.beehiiv.com (blog)

Robert Grupe is a senior Security Architect and AppSec Evangelist at Cigna-Evernorth.

Focused on hardened web, mobile, and service applications against malicious security attacks and vulnerabilities,
Robert initiated and has led AppSec practices comprised of:

• Secure Software Development Lifecycle (S-SDLC) and DevSecOps processes for high security quality development
• Security Coding and Design Standards that harden applications from attacks, and
• Role-Based Education and Awareness Training.

With over 20 years of cyber security experience in internal companies, Robert is a Certified Security Professional and Project Manager, with 4 US security patents, and contributor to the US National Institute of Standards and Technology (NIST 800-812) Secure Software Development Framework.

Managed by the OWASP® Foundation
owasp.org
Lessons Learned: AppSec Role Based Training 5 Years Ups, Downs, FuturesAutomated Security Testing with OWASP NettackerOWASP Finance SummaryOWASP Board of Directors - January 2026OWASP DefectDojo - Matt TesauroFrom Soft Skills to Hard Data: Measuring the Impact of Culture and Security ChampionsBusinesses Run On Risk And Debt: Why Communicating Security Risk Is Hard - Dwayne McDanielOpening Remarks and KeynoteLearning to build an effective security design review program - Felix Matenaar, Ari FayOWASP Foundation - December 2025 Financials
OWASP Foundation |

Lessons Learned: AppSec Role Based Training 5 Years Ups, Downs, Futures

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER