Actively Considering Opportunities

Roles like… Technical Team Leader, Security Researcher, Security Architect

Targeting areas like… Security tool development, AI/ML security, Java Virtual Machine runtime monitoring/analysis, Java application observability, TLS protocol analysis, industry facing contributions/projects, open source development

Work locations like… Remote, Hybrid

You found my projects/contributions page.  Thanks for stopping by.


Java Security Researcher & Architect

About Milton Smith

Milton Smith

Black Hat USA 2013 — Executive Summit

I was invited by Black Hat leadership to present candidly on Java security at the Black Hat USA Executive Summit — one of three featured presenters, sharing the stage with the world’s foremost security leaders, under NDA, before an audience of top global technology executives.

Milton Smith · Oracle Java Security Alex Stamos · Yahoo / Facebook CSO Gen.  Keith Alexander · 16th Director, NSA

That same year, Milton founded and led the JavaOne Security Track — establishing the first full security track at a major software development conference, a role he held from 2013 through 2017.  As Java Platform security leader at Oracle, he shaped the security direction of one of the world’s most widely deployed software platforms and served as a public-facing representative during critical periods of Java’s security credibility.

His work and public statements have been covered by InfoWorld, The Register, ComputerWorld, PC Magazine, San Jose Mercury News, IT News, and others — most notably following a 2014 Java User Group Leaders Call that triggered widespread industry press at a pivotal moment in platform security.  It wasn’t all roses but Java emerged successful, stronger, and community trust was restored.

Active Projects

Active · Project Lead & Author

JVMXRay monitors Java applications in real-time via bytecode injection, detecting vulnerabilities and suspicious activity without code changes. 19 modular sensors track file access, network connections, SQL queries, cryptographic operations, authentication, process execution, and more — generating structured, machine-readable security events with automatic cross-sensor correlation.

JVMXRay addresses a gap that SAST and DAST tools cannot fill: runtime behavioral visibility into production Java systems.  As AI-accelerated development compresses the distance between code generation and deployment, runtime assurance becomes a critical layer.

Active · Project Lead & Author

A TLS/SSL analysis API for building Java-based security tools.  DeepViolet powers TLS analysis within ZAP, one of the largest open-source security scanners on the internet — selected by the ZAP project as the foundation for its TLS analysis capability.

~9.5 million ZAP runs / month
Active · Project Lead & Author

Companion tooling built on the DeepViolet API — a CLI for scripting and scheduling, and a TLS Workbench for desktop-based scanning.  Both serve as reference implementations and production-ready tools for security practitioners.

In Progress

Manning Publications — Currently serving as Technical Editor on an innovative book project.  More on that in the future.

Inactive Projects

Inactive · Co-Lead & Contributor

A software project extending popular SLF4J-compliant loggers like Log4j and Logback with security and auditing features.  Many of the ideas originated while helping Jim and August with their book, Iron-Clad Java.  The security logging team later presented the project at OWASP AppSec Rome 2016.

Publications & Media

2026
ZAP Updates – March 2026
Project Credit
ZAP web application security was run nearly 9.5 million times in March.  ZAP team credits the DeepViolet project: “DeepViolet: Strengthening TLS Analysis.”
2026
ZAP: Introducing DeepViolet
Author · ZAP Community Blog
Guest blog post covering the DeepViolet API integration — what the ZAP team chose to ship and the advanced capabilities not yet in the initial release.
2014
Iron-Clad Java: Building Secure Web Applications
Technical Editor & Foreword Author
Shaped the book’s security content, most notably the Logging chapter — which directly seeded the OWASP Security Logging Project.  An honor to contribute alongside Jim and August on a book that’s become a Java security reference.
~2005
Enterprise Component Patterns
Author · O’Reilly Media
A services patterns manuscript and precursor to modern SOA architecture, completed over two years under contract with O’Reilly.  O’Reilly elected not to publish for business reasons — but the project sharpened my technical writing considerably and the work with their team was genuinely excellent.
2015–17
OWASP Board Election Candidate
Candidate Interviews
Interviewed as a candidate for the OWASP Board: 2017, 2016 (parts 14), 2015.
2014
Oracle Podcast: Java Spotlight, Episode 142
Guest · Interviewed by Roger Brinkley
Interview on Java platform security improvements and the JavaOne security track.  I introduced the first full security track at a major software development conference.
2014
DEVOXX Interview
Guest · Interviewed by Yolande
Discussion on security improvements in Java.
2014
Java User Group Leaders Call
Presenter
The call triggered widespread press coverage at a pivotal moment in Java’s public security credibility.  Covered by InfoWorld, CSO Online, PC Magazine, The Register, San Jose Mercury News, and more.  Navigating incidents like these takes real security chops.
2014
JavaOne 2014 Security Track Early Acceptance Sessions
Security Track Chair · Oracle
As security track chair for JavaOne in San Francisco, I previewed featured sessions to build excitement for the security track.

Conferences & Presentations

Year Event Role
2013 Presenter
2013 OWASP AppSec USA, New York Presenter
2015 OWASP AppSec USA Committee / Organizer
2016 Presenter · DeepViolet
2016 OWASP AppSec EU, Rome Presenter · Security Logging
2018 Presenter · DeepViolet
2020 Presenter · JVMXRay

JavaOne Security Track Lead2013, 2014, 2015, 2017  ·  Founded and led the first full security track at a major software development conference.
OWASP AppSec EU, Hamburg — Presenter  ·  All Day DevOps — DevSecOps Track Leader  ·  ISC2 East Bay Chapter, 2017 — Presenter