Now reading●OWASP co-founder●Contrast Security CTO●Runtime over guesswork●Baltimore, Maryland Now reading●OWASP co-founder●Contrast Security CTO●Runtime over guesswork●Baltimore, Maryland

People / Application Security

Jeff Williams Put a Stethoscope Inside the Software

The co-founder of OWASP and Contrast Security has spent three decades arguing that software cannot be secured from a distance. His answer is simple enough to sound obvious: watch the code while it lives.

There is a small heresy at the center of Jeff Williams’s career: perhaps the software knows more about its own security than the security tools circling it. The usual apparatus stands outside the application, inspecting source code, sending test traffic, filing findings and producing the modern office equivalent of autumn leaves. Williams would rather put sensors inside the thing and watch what happens. A vulnerability that exists on paper may never be reached. A dangerous path may be busy right now. The running system can tell the difference.

This sounds like a technical preference, and it is. It is also the culmination of an education in how people make decisions when the machinery becomes complicated. Williams studied psychology and computer science at the University of Virginia, then human factors at George Mason University. Before application security had settled into a recognizable profession, he worked on human-factors problems at MITRE and TRW. Later came a Georgetown law degree focused on intellectual property and cyberlaw, earned while his engineering career was already underway.

Psychology, systems, law: an untidy assortment for a future chief technology officer, but a useful kit for anyone trying to make invisible risk intelligible. Software failures live in code. The response lives among people, incentives, evidence and rules. Williams’s work has repeatedly occupied the seam.

3degrees spanning computing, human factors and law
8+years as OWASP’s volunteer global chair
3masters basketball titles, 2021 through 2023

A list for a field without a language

In 1999, at Exodus Communications, Williams helped create an internal application-security consulting team. He has called it the “stone age of appsec,” a phrase that carries both archaeological distance and a programmer’s impatience. The web was becoming the world’s commercial plumbing, yet the expertise needed to secure it remained scarce and unevenly distributed.

OWASP emerged in 2001 as an open effort to change that. Williams helped create the project and then served for roughly eight years as its volunteer global chair. The work was aggressively practical: free guidance, test applications, standards and code that developers could actually use. He created or helped lead the OWASP Top 10, the Enterprise Security API, the Application Security Verification Standard and the XSS Prevention Cheat Sheet. Some projects became fixtures; others became arguments the field needed to have.

The Top 10 was especially effective because it performed an act of compression. A sprawling technical problem became a short, teachable vocabulary. Executives could ask about it. Developers could recognize it. Auditors could point to it. Lists always lose detail, but a young field first needs a shared set of nouns. OWASP supplied them without asking anyone to buy a license.

“Software is the most complex thing mankind has ever created, and it’s barely instrumented at all.”Jeff Williams

Volunteer institutions are held together by tact as much as code. A public recommendation from OWASP colleague Andrew van der Stock describes Williams as diplomatic, unfailingly polite and helpful. Those are not decorative qualities when contributors are scattered around the world and paid chiefly in the satisfaction of disagreeing on a mailing list. Williams helped give the organization enough structure to grow without sanding away its open character.

Builds an early AppSec consulting team inside Exodus Communications.
Helps create OWASP and the shared vocabulary that follows.
Co-founds Aspect Security, turning specialist knowledge into a consultancy.
Co-founds Contrast Security around sensors inside running applications.
Extends the runtime thesis to CVE observation and temporary protection.

The expert bottleneck

In 2002, Williams co-founded Aspect Security and became its chief executive. The firm focused on application-security consulting: penetration testing, threat modeling, architecture and the hard business of showing organizations where their assumptions were wrong. Aspect was eventually acquired by Ernst & Young in 2017. By then, Williams had already moved from the consultancy model toward a different wager.

Consulting reveals an awkward economic truth. An expert can discover a great deal, but there are never enough experts to sit beside every developer or examine every release. Traditional testing also arrives in episodes. A team assesses a system, produces a report, and departs while the software keeps changing. The snapshot begins aging before the meeting about the snapshot has ended.

Contrast Security, co-founded in 2014, was Williams’s attempt to turn some of that expert judgment into continuously available evidence. Its agents hook into applications and observe code as it loads and runs. Sensors can follow data flow, see which libraries execute, identify controls and distinguish a suspicious input from an exploit that reaches a dangerous operation. The premise resembles application-performance monitoring, except the vital signs concern trust.

Williams explains the idea with machines people already understand. Cars, aircraft and spacecraft are instrumented because complexity defeats intuition. Warning lights are not an admission that engineers failed. They are how responsible engineers operate consequential systems. Software, he argues, has acquired enormous consequence while remaining peculiarly shy about its internal state.

There is wit in the contradiction. The software industry measures build duration, page latency, conversion, clicks and nearly every twitch of a customer’s thumb. Ask whether untrusted data just altered a database query, however, and the answer may arrive in a quarterly test report. Williams’s complaint is not that teams lack data. It is that the data often describes the wrong moment.

Press graphic showing Jeff Williams beside his name and role at Contrast Security
A 2025 interview framed the question Williams keeps returning to: which risks are real in the running system?

Context, the scarce commodity

The arrival of generative AI has sharpened the argument. AI can help write more code and search more code. It can also multiply plausible findings faster than teams can investigate them. Williams does not dismiss its value. He objects to treating fluency as context. A model that sees a repository may still not know which component reached production, which route is exposed, which control fires or whether an attacker is exercising the path at this minute.

“Ultimately, it comes down to what data do you have that’s real?”Jeff Williams

His proposed answer is a digital twin of the application layer: a current model of applications, APIs, libraries, routes and security controls built from runtime telemetry. Humans can reason over it; AI agents may eventually do so too. The ambition is not to produce a grander alarm panel. It is to connect an alert to enough evidence that someone can decide.

Recent Contrast work carries that logic into the interval between discovery and repair. CVE Shield, announced in 2026, is designed to show whether vulnerable code is executing, observe attempts to exploit it and, for supported vulnerabilities, block the dangerous capability while a team prepares its patch. The careful phrase is “while a team prepares.” Williams is not proposing that runtime protection abolish maintenance. He is addressing the calendar problem: a public flaw can acquire an exploit faster than a large organization can test and deploy a permanent fix. Security often happens in that awkward gap, where the ideal answer is known but not yet installed. A useful system must help people survive the meantime without pretending the meantime is forever.

That distinction leads Williams to resist the easy slogans of his trade. “Shift left,” the instruction to move security earlier in development, helped correct a genuine problem. He now prefers “shift smart”: apply each kind of testing where it has the right context. Source analysis belongs where source is available. Runtime questions belong at runtime. Production defense belongs in production. A conveyor belt is not improved by moving every worker to its first inch.

The same pragmatism appears in his writing about software attestation and transparency. Buyers are routinely asked to trust consequential software with little credible evidence about how it was built or how it behaves. Williams wants a market in which producers can make verifiable claims and customers can compare them. The law graduate has not vanished inside the CTO. He is still interested in what counts as proof, who bears responsibility and how institutions reward candor.

Reading the floor

One of the more charming entries on Williams’s public record has nothing to do with semicolons. He lists three masters basketball titles from 2021 through 2023, including MVP and points-leader honors in 2022. It would be too neat to turn sport into a master key for a life, but basketball does offer an apt image for his work. The useful player does not merely know the playbook. He sees spacing, pressure, motion and the route that is actually open.

Application security has spent years accumulating playbooks. Williams helped write important ones. His later career has been devoted to seeing the floor.

The result is a professional arc with a pleasing reversal. The young field needed abstraction, so OWASP made lists and standards that could travel. Growing companies needed scarce judgment, so Aspect supplied experts. Software then became too fast and abundant for episodic inspection, so Contrast put observation inside the application. Each answer created the conditions for the next question.

Williams’s stated aspiration is broad: software worthy of the important activities people entrust to it. The route is stubbornly concrete. Measure behavior. Preserve context. Make claims testable. Give the person fixing the problem something better than a red icon and a ticket number. There will still be vulnerabilities, politics and meetings whose only measurable output is another meeting. But the application, at least, may finally be permitted to speak.