NTO was founded a few years back by some of the guys from Foundstone to deal directly with web app security. Check out their short training sessions on:
- Understanding SQL Injection
- Inventorying Your Site
- Coming soon - What to Fix First
I didn't do them myself, but the guys running this company are sharp.
Don