Jeff Williams

Co-Founder & Chief Technology Officer · Contrast Security

Application security (DevSecOps) — instrumentation-based security software

Co-founder and chief technology officer of Contrast Security, which he started in 2014 with Arshan Dabirsiaghi to apply runtime instrumentation to application security. One of the most influential figures in the field, he chaired the OWASP Foundation for most of a decade and authored or led several of its defining projects, including the OWASP Top Ten, ESAPI and the Application Security Verification Standard.

Last reviewed: Sep 19, 2026

Jeff Williams

Co-Founder & Chief Technology Officer Contrast Security

Last Reviewed: September 19, 2026

Executive Summary

Jeff Williams is co-founder and chief technology officer of Contrast Security, and one of the more consequential figures in the history of application security. His central technical argument, pursued across two companies and two decades, is that you cannot find out whether an application is secure by looking at it from the outside or by reading its source in isolation — you have to instrument it and watch it run. Contrast, which he founded in 2014 with Arshan Dabirsiaghi, is built entirely on that premise: agents inside the running application observe data flow and behaviour continuously, which is what Interactive Application Security Testing and Runtime Application Self-Protection mean in practice. Before that he founded Aspect Security, among the first consultancies to do nothing but application security, later acquired by EY. And for eight years he chaired the OWASP Foundation, during the period in which it became the field’s standard-setting body.

Career Highlights

  • Served as volunteer Global Chairman of the OWASP Foundation from late 2003 until September 2011, the years in which it grew from a mailing-list project into an established international non-profit.
  • Created or led several of OWASP’s defining artefacts, including the OWASP Top Ten, the Enterprise Security API (ESAPI), the Application Security Verification Standard (ASVS), WebGoat and the XSS Prevention Cheat Sheet — all released free and openly.
  • Founded Aspect Security, one of the earliest firms dedicated exclusively to application security consulting, training, penetration testing and secure development; it was acquired by EY.
  • Co-founded Contrast Security in 2014 with Arshan Dabirsiaghi, now its Chief Scientist, and has served as chief technology officer since.
  • A pioneer of the instrumentation-based security categories — IAST and RASP — that displaced periodic external scanning as the mainstream approach to application security testing.
  • Named to Enterprise Security Tech’s Cyber Influencer Top 10 in 2022, and a prolific writer and speaker across Dark Reading, Security Magazine and the major security conferences.

Professional Journey

Williams’s background is unusual for a security technologist: a bachelor’s degree from Virginia, a master’s from George Mason and a law degree from Georgetown. That legal training is not incidental to how he has worked. Much of his OWASP output — the Top Ten, the Application Security Verification Standard — is essentially the drafting of standards: documents that must be precise enough to be testable, general enough to be adopted across an industry, and defensible when someone’s compliance obligation turns on them. Writing a verification standard is closer to legislative drafting than to engineering.

He founded Aspect Security in the early 2000s, when application security barely existed as a distinct commercial practice. Most security spending then went to network perimeter defences, on the assumption that the application behind the firewall was somebody else’s problem. Aspect was built on the opposite premise, doing consulting, training, penetration testing and secure development work exclusively at the application layer. It was eventually acquired by EY, which is itself a marker of how thoroughly that assumption reversed.

The OWASP chairmanship ran alongside. Mark Curphey had started the project in September 2001 as a mailing list and a collection of documents; Williams took the volunteer chair in late 2003 and held it until September 2011. Over those years OWASP became the reference point for the whole field — the Top Ten in particular moved from a useful list into contractual and regulatory language, cited in PCI DSS and procurement requirements worldwide. ESAPI attempted to give developers a secure-by-default library rather than a list of warnings; WebGoat taught the attacks by making people perform them; the ASVS gave organisations a graded standard to verify against. The consistent editorial choice across all of them was to give the work away.

Contrast Security, founded in 2014, is the commercial expression of what the consulting years taught. Aspect’s business was expert humans auditing applications periodically, which is accurate but does not scale and goes stale the moment code changes. Instrumentation solves both problems at once: an agent inside the running application sees actual data flow through actual code paths, reports vulnerabilities with the specificity of a debugger rather than the guesswork of an external scanner, and keeps doing it continuously as the application is deployed and redeployed. The same instrumentation that detects an attack can block it, which is the RASP half of the platform. With Dabirsiaghi as chief scientist, Williams has continued to develop that thesis and to argue it publicly — most recently extending it to the security of AI-generated code, where the volume of code produced makes periodic human review still less tenable than it already was.

Education

University of Virginia

Bachelor of Arts

George Mason University

Master of Arts

Georgetown University

Juris Doctor

Fields of study and graduation years are not stated in any public source.