<img height="1" width="1" style="display:none;" alt="" src="https://dc.ads.linkedin.com/collect/?pid=113894&amp;fmt=gif">

Thought Leadership


Product Videos

60 Minute Product Demo
60-Minute Product Demo

Contrast Demo & Overview

Watch a demonstration of Contrast, presented by Jeff Williams, Contrast CTO & Co-founder in conversation with Ed Amoroso, former CISO of AT&T and Founder of TAG Cyber.
(1 hour)

Contrast Demo Video
9-Minute Product Demo

Contrast Product Highlights

Watch a short high-level overview and see for yourself how Contrast Security makes software self-protecting so it can defend itself from vulnerabilities & attacks. (09:08)

Product Video

Next Generation Application Security

Watch this short video and see how Contrast works with Agile and Devops processes to accomplish maximum security at maximum speed for all application deployments. (01:06)

Product Video

DevOps Ready Security

Watch this short overview video and learn how Contrast Security enables DevOps teams to deliver security-as-code. (01:15)

60-Second Overview

Contrast High-level Overveiw

Watch this short overview video to see how Contrast uses instrumentation to deploy and more accurately identify application vulnerabilities in minutes, without experts or legacy SAST and DAST testing tools. (01:11)

Product Overview

Introduction to Contrast Protect

Watch this short overview video to see how Contrast Protect leverages Runtime Application Self-Protection (RASP) and patented deep security instrumentation to protect applications against cyber-attacks in real-time and make it the most accurate, fastest and scalable application security solution. (01:39)

Product Video

Contrast Security Advantages Over WAF – SQL Query Example

Watch this short video and see how Contrast Security protects applications and blocks SQL injection attacks better than WAF's. (01:17)

Product Video

Contrast Protect Advantages Over WAF

Watch first hand how Contrast Protect avoids the need for WAF's by working from the inside of a running application to provide better visibility and accuracy of finding and blocking attacks. (02:32)

Product Overview

The Contrast Advantage

Watch a short video of Jeff Williams, Co-Founder & CTO of Contrast Security, explaining what it means to have "self-protecting" software. (03:27)

Product Overview

Contrast Assess as Part of the SDLC

Contrast Assess (IAST solution) deploys an intelligent agent that instruments the application with smart sensors to analyze code in real time from within the application, without disrupting your process. (01:20)

Product Overview

Introduction to Contrast Assess

Watch this short overview video to learn how instrumentation works to find vulnerabilities, insecure libraries, and how it compares to other security testing methodologies. (01:27)

Short Interviews with Security Experts

Security Experts Insight

Cyber Security and Digital Transformation

Contrast Security CEO, Alan Naumann chats with former CISO of AT&T Ed Amoroso on the importance of software security, DevOps initiatives, and the future of digital transformation. (10:06)

Security Experts Insight

Realistic Approaches to AppSec & the Future of Cyber Security

Hear a conversation with Contrast Security CTO, Jeff Williams and former CISO of AT&T, Ed Amoroso, as they discuss how to approach application security and what the future of cyber security looks like. (10:18)

On the Street Interview

Instrumenting Application Security

In this video, hear Scott Parson, Senior Enterprise Security Architect of a Fortune 500 Financial Company, discuss the importance of continuous application security and how automation and cloud infrastructure has impacted his organizations approach to application security. (02:25)

On the Street Interview

Continuous Application Security with Tim Chase from Nielsen

In this brief video, hear Tim Chase, Director of Application Security and Architecture at Nielson, discuss the importance of continuous application security and what he thinks the future will hold for security testing, including DevSecOps. (02:15)

On the Street Interview

Investing in the AppSec Market

In this video, Jeff Williams, CTO of Contrast Security, talks with John Monagle of General Catalyst, in regards to investing in application security, how the DevOps movement is changing the market, and Contrast's role in this transformation. (03:15)

Thought Leadership

Dark Reading Interview with Jeff Williams

Hear Brian Gillooly, VP of Events Content & Strategy, Dark Reading in an in-depth conversation with Jeff Williams, CTO, Contrast Security. Topics included revolutionary changes taking place in both application security and DevOps as well as Jeff’s prestigious nomination as one of the three finalists in the "Most Innovative Thought Leader" category for his work as a cyber security innovator. (12:57)

On the Street Interview

What does IAST mean to you?

Watch this short video and hear from Director of Test, John Scarborough on how he defines Interactive Application Security Testing (IAST). (00:39)

On the Street Interview

DevOps teams and AppSec?

Establishing a DevOps-ready security program is possible. In this video, hear from 3 folks who have successfully built and scaled the DevOps functions within their organizations. (01:31)

On the Street Interview

What does RASP mean to you?

Watch this short video and hear how Steve Herrod, Managing Director of General Catalyst Partners, defines and uses RASP technology as a decision-making tool. (00:35)

OWASP Benchmark

How it Works

Hear Jeff Williams, as he discusses the OWASP Benchmark Project in this short video. (05:38)

On-Demand Webinars & Conference Presentations

Resource Whitepaper
On-Demand Webinar

Under the Hood with Static Analysis - Fact vs Fiction

Tune into this webinar to walk through the basics that support the static analysis field, such as semantic analysis and how data flow works between source and sink. We will also walk through the model structure that is built, how it is queried, and how it is impacted by different development techniques to give you a better understanding of how static analysis falls short of providing your security needs. (40:00)

On-Demand Webinar

Securing Java Web Applications and APIs...in minutes...for FREE...Seriously!

Security tools have always been difficult, inaccurate, and frustrating...but what if there were a security tool that was as easy and powerful to use as AppDynamics? A security tool anyone can use to secure their own code, lock down open source libraries, identify attackers, and prevent exploits. In this webinar, Contrast's CTO and Co-founder, Jeff Williams, will get you up and running with Contrast's Community Edition - FREE and full-strength application security solution for anyone to use. (44:00)

Resource Whitepaper
On-Demand Webinar

The DevSecOps Journey: Why It Starts with Agile, DevOps, & App Security

Traditionally, security has been an afterthought, or at the very least introduced late into the release process. Hence, security has been viewed as an impediment to high velocity Agile DevOps processes and becoming a primary bottleneck in the software delivery pipeline. This can cause major contention and distrust between development and security teams–but that doesn’t need to be the case. This webinar will highlight how modern, automated application security tools can help weave security into the code continuously and accurately throughout the SDLC. (45:00)

On-Demand Webinar

Embedding Security in a Modern DevOps Pipeline – A Customer Perspective

Hear directly from a customer's perspective on how Beeline, the world leader in contingent workforce solutions, aligned Development, Operations, and Security practitioners to set up a fully automated CI/CD pipeline and incorporated application security early in the process. (1 hour)

On-Demand Webinar

Targeted Defense: The Future of Defending Applications in Production

Development teams have struggled with massive security backlog with the inability to fix everything in code. Protecting your legacy applications is critical to your business and therefore necessary for your organization to have better production controls and faster zero-day response. Listen to this webinar to learn Contrast's new Targeted Defense Platform and its new capabilities using RASP technology. (1 hour)

On-Demand Webinar
On-Demand Webinar

Application Security Testing for an Agile & DevOps World

Security teams have a hard time keeping pace with software development in Agile / DevOps environments. With the majority of cybersecurity attacks focused on applications, automatically detecting vulnerabilities and protecting your applications from attack is critical. Listen to this webinar to learn the best practices in securing your software code and how to start developing a winning application security strategy. (43:00)

Equifax, Struts and You
On Demand Webinar

Equifax, Struts and You

The Equifax breach was a watershed moment for software application security. The root cause is confirmed to be a web application security issue tied to a widely used software framework called Apache Struts 2. To gain a better understanding of these events, listen to this webinar to learn how to shield yourself against Struts 2 attacks and how the team at Contrast Labs saw these issues and continues to see exploit attempts. (35:00)

On Demand Webinar

Scaling Rugged DevOps to Thousands of Applications

In 40-minutes you'll hear how Tim Chase, Director of Application Security and Architecture at Nielsen, is scaling Rugged DevOps and achieving continuous protection during development and operations by instrumenting the software application portfolio, assessing and protecting applications in parallel, and deploying integrations that provide instant notification. (42:00)

On Demand Webinar

Secure Government Web Applications

Hear Jeff Williams, Contrast Security Co-founder & CTO, discuss how government agencies can scale their DevOps functions by instrumenting their application portfolio, assessing and protecting applications in parallel, and deploying integrations that provide instant notifications. (1 hour)

Security Experts Insight

OWASP London DevSecOps Presentation

Jeff Williams, Contrast Security CTO, presents the “Three Ways of Security”, an interpretation of the DevOps classic, “The Phoenix Project”. In this video, you’ll learn how to get your security work flowing, create continuous security feedback, and create a culture of security experimentation and learning. (72:00)

On Demand Webinar

Massive Java "Zero Day": What is It and How to Fix It

Learn why the widespread flaw makes Heartbleed look tame. Also, learn how RASP technology is perfectly suited to protect applications vulnerable to Java deserialization exploits and many other types of attacks. (43:04)

On Demand Webinar

Demystifying Runtime Application Self-Protection – RASP

Gartner has recognized a new category of application security calling it Runtime Application Self-Protection (RASP). RASP is “transformational” because it enables new ways of securing business. But, how can applications protect themselves against attacks, especially if those protections weren’t built in by the app developers?
(1 hour)

On Demand Video

What's Killing SAST?

See how a unique technology let’s you build applications that accurately self-diagnose vulnerabilities and self-protect against attacks, without changing a line of code. (54:00)

On Demand Video

OWASP AppSec Benchmarking Project: Astonishing Results

See how Contrast stacks up against the OWASP Benchmark in this on-demand video. The results are illuminating. (55:00)

On Demand Video

IAST: AppSec at Agile Speed & Portfolio Scale

It is time to learn about interactive application security testing (IAST), a technology that is transforming the way businesses approach finding and remediating vulnerabilities. (1 hour)

On-Demand Webinar

Cybersecurity Webinar with Gene Kim and Jeff Williams

Listen to Jeff Williams, CTO of Contrast Security and co-founder of OWASP, in a lively conversation with Gene Kim, researcher, author, Tripwire founder. Jeff and Gene will discuss DevOps and continuous app security. (45:00)

Chief Information Security Officer.png
On-Demand Recording

Rich Licato, CISO, Airlines Reporting Corporation (ARC)

Listen to Jeff Williams, CTO of Contrast Security and co-founder of OWASP, discuss topics regarding risk and compliance in an overall security program. (21:12)


Security Influencers Channel

Episode 31

In this episode, we discuss Jacob's views on the top security challenges facing companies today.

Security Influencers Channel

Episode 30

In this episode, we discuss why this past year is being referred to as the year of the breach.

Security Influencers Channel

Episode 29

We will discuss the notion of a public/private partnership to deal with cyber-attacks.

Security Influencers Channel

Episode 28

In this episode we discuss what exactly is the "Dark Net" and why it is important.

Security Influencers Channel

Episode 27

In this episode we discuss what Cylance does and what led Stuart to create the company after seeing the frustration of so many breeches.

Security Influencers Channel

Episode 26

In this episode, we discuss the games that Adam has created what these games do to help improve security for everyone.

Security Influencers Channel

Episode 25

In this episode, we discuss what Josh thinks about security's place in the "Internet of Things."

Security Influencers Channel

Episode 24

In this episode Nancy gives a brief history of security and illustrates what is not working.

Security Influencers Channel

Episode 23

On this episode of The Security Influencers Channel, we're joined by Bill Brenner. He's the Senior Program Manager for Editorial in the Information Security Group at Akamai.

Security Influencers Channel

Episode 22

In the podcast, we discuss how Agari reached the point where it is protecting 85% of all email boxes in the world and what its plans are from there.

Security Influencers Channel

Episode 21

In the podcast, we discuss John's background as a nuclear physicist turned security professional and why nhe believes in an "evidence-based" approach to security.

Security Influencers Channel

Episode 20

In the podcast, we discuss a predictions blog post that Andrew wrote in December of 2013 where he predicted five security "happenings" for 2014.

Security Influencers Channel

Episode 19

In this episode, Michele explains the meaning of a term she coined, "Security Stoogecraft," and why she feels it is the best way to describe today's security landscape.

Security Influencers Channel

Episode 18

Kevin and I discuss his thoughts on what he calls "Leading design of the human oriented information security experience."

Security Influencers Channel

Episode 17

In this episode, we talk about how we get developers to do their own security and why he views security as one of the "hardest careers out there."

Security Influencers Channel

Episode 16

Jeff explains the challenges of bringing network security to a stack that was not designed to be defended.

Security Influencers Channel

Episode 15

Troy and I discuss all of the recent high profile security breaches of Target, Home Depot and Apple and what that means for the state of security in today's landscape.

Security Influencers Channel

Episode 14

Today, we're talking with my good friend, Samy Kamkar. Samy is a security and privacy researcher, computer hacker, whistleblower, entrepreneur.

Security Influencers Channel

Episode 13

Neil and I discuss his philosophy on automating applications security and doing continuous delivery - DevOps style.

Security Influencers Channel

Episode 12

In this episode we discuss the mission of the Cloud Security Alliance and what the organization seeks to accomplish.

Security Influencers Channel

Episode 11

In this episode, Brian and I discuss how we enstill the wrong security mindest in children from a young age.

Security Influencers Channel

Episode 10

In this episode, John and I discuss the evolution of application security and how the trend in faster development cycles plays into the security life cycle.

Security Influencers Channel

Episode 9

In this episode, Nick and I discuss DevOps, continuous security and how companies should handle high rates of deployment.

Security Influencers Channel

Episode 8

In this episode, Gene and I discuss DevOps, continuous security, and how a company develops a great security culture.

Security Influencers Channel

Episode 7

In this episode, we're talking with Bradley Schaufenbuel. Brad is currently the Director of Information Security at Midland States Bank and held security leadership positions at many leading financial institutions.

Security Influencers Channel

Episode 6

In this episode, Jeff Williams interviews Alex Hutton, the director of information security at Too Big to Fail Bank. Alex was previously employed by Verizon, where he worked on modeling risk and contributing to the Verizon data breach report.

Security Influencers Channel

Episode 4

In this episode, Jeff Williams interviews Wayne Jackson of Sonatype. They discuss the results from The 2014 Open Source Development Survey, where developers gave their honest opinions on everything from third-party code to internal policies and procedures.

Security Influencers Channel

Episode 3

In this episode, Jeff Williams interviews Andrew Hay of Open DNS. They discuss bad credential management and the recent eBay breach, thinking with the mind of an attacker, firewalls and security in the cloud.

Security Influencers Channel

Episode 2

In this episode, Jeff Williams interviews Bruce Brody of Cubic Cyber Solutions, a leading provider of specialized systems and services in the rapidly changing world of technology.

Security Influencers Channel

Episode 1

In this episode, Jeff Williams interviews Jonathan Chow and Neeta Maniar of Live Nation Entertainment: The world's leading producer and promoter of live entertainment, and the parent company of Ticket Master and The House of Blues.