Management is asking, so....
As in the title, what is the most effective (and formal) way to get a web app developer with no security experience become a decent web application penetration tester?
Attend training?
Get a fully featured app scanning software that does everything?
My current preference is 
eWPT training and a copy of Kali VMware image.
Looking through the 
WAPTv2 outline, I like the fact that they start from basics, covers OWASP and the major web vulnerabilities, has hands-on labs and even include a section on report writing.
We do not need full penetration testing capabilities so OSCP and GPEN are out for now. Also looked at 
GWAPT and 
OSWE. Understand that GWAPT is more theoretical whereas OSWE training is only available at Black Hat 2015. Not keen on CEH either. 

Thoughts?