Revision as of 13:16, 25 February 2014 by Wichers (talk | contribs) (OWASP Contributions)

Jump to: navigation, search



Dave Wichers is a cofounder and the Chief Operating Officer (COO) of Aspect Security, a consulting company that specializes in application security services. He is also a long time contributor to OWASP, helping to establish the OWASP Foundation in 2004, serving on the OWASP Board since it was formed from 2004 through 2013, served as OWASP Conferences Chair from 2005 through 2008, is a coauthor of the OWASP Top 10 and has led the project since 2007, and has contributed to numerous other important OWASP projects including WebGoat, ESAPI, ASVS, and the OWASP Cheat Sheet Series.

Dave is also involved in developing a new type of application vulnerability analysis technology that uses instrumentation to detect vulnerabilities inside of a running web application. This new technology, called Contrast, is available from a partner company of Aspect Security called Contrast Security.

Dave has over 25 years of experience in the information security field, and has focused exclusively on application security since 1998. At Aspect, in addition to his COO duties, he is Aspect's application security courseware lead, one of their chief instructors, and provides a wide variety of application security consulting services to Aspect's clients. Prior to starting Aspect, he ran the Application Security Services Group at Exodus Communications. Dave has a Bachelors and Masters degree in Computer Science and is a CISSP.

OWASP Contributions

I have been contributing to OWASP since 2002. In 2004, along with Jeff Williams, we established the 501c3 organization that is now the OWASP Foundation. Since establishing the OWASP Foundation, I served as the de facto Chief Financial Officer of OWASP, until the OWASP Board established an Executive Director in mid 2013. During that time I negotiated and signed for virtually all contracts OWASP entered into with other parties. I also established all the financial accounts for the OWASP Foundation including bank accounts, credit cards, tax IDs, and helped hire most of the employees of the OWASP Foundation. I also helped determine the employee benefits these employees would receive, and established the procedures for how they would receive those benefits including health insurance, payroll, etc. In late 2004, I volunteered to become the OWASP Conferences Chair where I launched the OWASP Conferences Series, personally organized all the U.S. and European AppSec conferences from 2005 through 2008, and helped launch the Global Conferences Committee in 2009, which organized the conferences from 2009 through 2012. The OWASP Conferences have grown to serve as a primary fundraising resource for OWASP. I have also spent countless hours helping to initially establish the OWASP wiki, and then continuing to improve it, proofreading articles, encouraging others to contribute, etc.

As a volunteer to OWASP, Dave is or has been:

For more details than this short bio on what I've done at OWASP, listen to my OWASP podcast.

Wiki Contributions

I've also done lots of OWASP conference presentations. Here are some of them:

Dave can be reached at: dave.wichers (at) or dave.wichers (at)