Management is asking, so....
As in the title, what is the most effective (and formal) way to get a web app developer with no security experience become a decent web application penetration tester?
Attend training?
Get a fully featured app scanning software that does everything?
My current preference is
eWPT training and a copy of Kali VMware image.
Looking through the
WAPTv2 outline, I like the fact that they start from basics, covers OWASP and the major web vulnerabilities, has hands-on labs and even include a section on report writing.
We do not need full penetration testing capabilities so OSCP and GPEN are out for now. Also looked at
GWAPT and
OSWE. Understand that GWAPT is more theoretical whereas OSWE training is only available at Black Hat 2015. Not keen on CEH either.

Thoughts?