Grant Ongers
Grant Ongers (@rewtd) is co-founder of the bearded trio called Secure Delivery focused on optimal delivery and security in one dynamic package. Grant's experience spans Development: building platforms for telcos, MSPs, and financial services firms for more than 10 years. He also has over 20 years of experience in Operations, running operational teams in global NOCs to managing mainframe and database systems. On the Security side of the business, Grant has over 30 years pushing the limits—mostly white hat. He’s done time on both sides of the TPSA table, working for and with regulated organizations to ensure compliance and match “appetite for” with “acceptance of” risk. Grant is involved in numerous organizations: staff at BSides, Goon at DEF CON, DC2721 cofounder, staff at BlackHat, and OWASP global board member.
Subscribe Now- Thought Leaders
- Application Security
- Contrast News
- DevOps
- AppSec
- vulnerabilities
- Hacked
- Threat
- Runtime Security
- cyberattacks
- API security
- DevSecOps
- ADR
- cybersecurity
- Product
- Contrast Protect
- RASP
- Contrast Assess
- AI
- Application Detection and Response (ADR)
- Security
- CodeSec
- MFA
- incident response
- APIs
- Metrics
- cybersecurity awareness month
- CISA
- CVE
- OSS
- data breach
- ransomware
- 2FA
- IAST
- threat detection
- vulnerability
- CISO
- SCA
- passwords
- runtime protection
- SOC
- WAF
- application attacks
- regulation
- transparency
- AWS
- CISOs
- Contrast Scan
- JavaScript
- Log4j
- MTTR
- SAST
- SQL injection
- Vulnerability Management:
- application layer
- backlog
- threat modeling
- .Net
- Application Layer Security
- Cloud security
- GitHub
- Log4Shell
- OpenSource
- SIEM
- Security Observability
- Threat Detection and Response
- Threat Intelligence
- XSS
- attack
- breach
- critical infrastructure
- cyberespionage
- cybersecurity incident reporting
- observability
- path traversal
- risk management
- scan
- software development
- unsafe deserialization
- zero-day
- AST
- Awards
- CISO Insights
- ChatGPT
- Community Edition
- Contrast ADR
- Contrast SCA
- Cybersecurity Risk Management
- DBIR
- DHS
- EDR
- Gen AI
- KVE
- Log4Shell attacks
- Log4Shell exploit
- Log4j vulnerability
- NIST CVE Backlog
- OpenAI
- RSA
- React
- Runtime Application Security
- Security Operations Center (SOC)
- Security Vulnerability Management
- Splunk
- Web Application Firewall (WAF)
- alert fatigue
- artificial intelligence
- awareness
- chat apps
- cybercrime
- cybersecurity culture
- data privacy week
- detection
- detection response
- extended detection response
- financial institutions
- financial sector
- jQuery
- malware
- method tampering
- okta
- python
- remediation
- sbom
- secure by design
- security culture
- security monitoring
- shift smart
- supply chain
- training
- vulnerability detection
- vulnerability disclosure
- workplace
- zero days
- .NET application
- .Net
- ADR (Application Detection and Response)
- AI Act
- AI Assistants (Attack Tools)
- AI censorship
- AI-powered security remediation
- Angular
- Application Security (AppSec)
- Architecture design
- Article 25
- Attack Detection and Response (ADR)
- Attack Trends
- Attacks
- Below the Waterline
- CFO
- CISA Log4Shell
- CISA Vulnrichment
- CNAPP
- CSRF
- CVE Enrichment
- CVE-2021-44228
- CVSS Scores
- Chris Hughes
- Cloud Native Security
- Cloud platform protection
- Console
- Contrast AI remediation
- Contrast One
- Crisis simulations
- Cross-site scripting
- Cyber Bank Heists
- Cybersecurity Collaboration
- Cybersecurity Funding
- Cybersecurity ROI
- Cybersecurity tools
- DAST
- DORA
- Data protection
- DeepSeek AI
- Dependabot
- Developers
- Digital Operational Resilience Act
- Drupal
- EL injection
- EU Product Liability Directive (PLD)
- Encryption
- European Commission Amendments
- European Union
- False Positives
- Gartner Peer Insights
- Genie
- Git
- GitHub Action
- GitLab
- Go
- Government surveillance
- HIPAA
- HIPAA Amendments
- Healthcare Cybersecurity
- How to comply with SEC cybersecurity rules
- Incident Response challenges with CVE backlog
- Intelligent remediation guidance
- Intrusion Detection Systems
- IoT
- KEV catalog
- Known Exploited Vulnerabilities
- LLMs
- Log4Shell remediation
- Log4Shell vulnerability
- Log4j remediation
- MITRE ATT&CK
- MLflow
- MOVEit
- Managed Security Services
- Managed security service providers
- Microsoft
- Multifactor Authentication
- Namasday
- National security
- Netflix
- Node.js
- Open source security risks
- OpenSourceSoftware
- PATs
- Perimeter defenses
- Protect data
- RCA
- RCE
- Real-Time Threat Detection
- Red teaming
- Regulation (EU) 2022/2554
- Risk assessment
- Ruby
- Runtime Application Security Protection (RASP)
- SEC
- SEC compliance
- SEC cybersecurity compliance
- SEC disclosure rules
- SOAR
- SOC (Security Operations Center)
- SOC incident response
- SecOps
- Secure from within
- Security controls
- Security engineering
- Serialized Data
- Software Compliance EU
- Software Composition Analysis (SCA)
- Software Defects and Compensation
- Software Security Liability
- Software supply chain security
- Third-party software vulnerabilities
- TypeScript
- WAF (Web Application Firewall)
Loving our content? Subscribe now!
Get the latest application security news, trends, tips and insights content from Contrast directly to your inbox. By subscribing, you will stay up to date with all the latest and greatest from Contrast Security.