
Greg Anderson
Founder & CEO of DefectDojo; open-source AppSec leader
Austin, Texas
Summary
Open-source founder and advocate who built DefectDojo from an individual project into a community-driven platform and a commercial Pro offering. github+2
Product and engineering leader focused on scaling application security through automation and machine learning to reduce manual triage, deduplicate findings, and prioritize risk. defectdojo+2
Experienced security practitioner with hands-on background in penetration testing, CI/CD security research, and applied AppSec across enterprises and services companies. sans+2
Community and industry leader who engages publicly—speaking at conferences, participating in OWASP governance, and contributing to the broader AppSec ecosystem. owasp+2
Work
Education
Projects
Writing
DefectDojo Outcomes - A Scalable Security Program & A Happier Security Team
May 1, 2024An article describing DefectDojo's mission, the platform's automation and ML capabilities, and how the project reduces manual workload to scale security programs.
Is This Your Pipe? Hijacking the Build Pipeline
January 1, 2014DEF CON presentation/paper on techniques for compromising CI/CD pipelines and supply-chain related attack vectors (presentation co-authored and delivered at DEF CON).