#028 · Security ProfessionalsEpicLocked in

Jeff Williams

Author of the First OWASP Top Ten

The list every compliance regime ended up pointing at

Rating

86Impact score
Technical depth88
Defensive craft92
Research82
Influence90
FromUSA
Era2002–present

Domains

Application securityRuntime protectionStandards

Scouting report

Wrote the first OWASP Top Ten and served as the volunteer chair of OWASP from 2003 to 2011, the years in which it went from a mailing list to the reference that PCI DSS and a long line of other standards cite by name. Co-founded Aspect Security and then Contrast Security, arguing for instrumentation inside the running application rather than scanning it from outside.

Curator’s note

One list, and suddenly every auditor knew what SQL injection was.

Sources