Lenny's PodcastHow Snyk built a product-led growth juggernaut | Ben Williams (VP of Product at Snyk)
CHAPTERS
- 0:00 – 0:37
Growth strategy through connected loops (teaser)
Ben opens with a key idea: high-performing growth teams don’t lack ideas—they lack a clear strategy for where to focus. He frames growth as a network of micro- and macro-loops that should be documented qualitatively and guided quantitatively quarter-to-quarter.
- •Map micro and macro growth loops and how they connect
- •Use a qualitative model to align the organization on “how we grow”
- •Add quantitative guidance to decide where to invest each quarter
- •Strategy’s job is prioritization amid a flood of ideas
- 0:37 – 5:37
Show setup: why Snyk is a PLG + community-led case study
Lenny introduces Snyk as a developer-first security company that scaled through product-led growth, community, and a developer-centric wedge. He previews topics including first users, monetization missteps, and how growth and product teams are structured.
- •Snyk’s story: PLG evolving into product-led sales (PLS)
- •Community-driven growth and deep focus on developers
- •Preview: early user acquisition, monetization lessons, team structure
- •Security as a market tailwind and strategic wedge
- 5:37 – 7:26
Ben Williams’ background: developer tooling to growth leadership
Ben shares his path from computer science to product, moving through developer tooling roles, IBM, and DevOps transformation work. He explains how those experiences led him to build and lead Snyk’s growth organization and developer experience initiatives.
- •Early career in developer/engineering tooling and solutions engineering
- •IBM Rational experience shaping product strategy and preferences
- •CloudBees: product design + growth in DevOps/open-core context
- •Joined Snyk to formalize and scale growth and developer experience
- 7:26 – 9:46
What Snyk does and the company’s scale today
Ben defines Snyk as developer security that finds and fixes vulnerabilities across code, open source, containers, IaC, and cloud configs. He shares metrics that reflect Snyk’s growth, valuation, and organizational footprint.
- •Developer-first security with strong in-workflow experiences
- •Covers code, dependencies, containers, infrastructure, and cloud
- •Scale: millions of developers, 2,000+ paying customers
- •Company size and org details (R&D and product scale)
- 9:46 – 14:46
Founders’ wedge: why developer-first AppSec was disruptive
Ben explains the historical AppSec landscape: centralized, top-down, and friction-heavy for developers. Snyk’s founding insight was that security had to shift left into developer workflows, enabled by low-friction tools and a freemium model.
- •Traditional security: audit/policing, long feedback loops, dev resistance
- •DevOps shifts created an opening for developer-first security
- •Initial narrow persona/use case: Node.js developers and OSS dependencies
- •Freemium from day one to maximize adoption and pervasiveness
- 14:46 – 17:15
Getting the first 100 users: community-first execution (Node.js)
The first users came from deep involvement in the Node.js community—talks, meetups, and early evangelism at developer conferences. The hook was simple and fear-inducing: “Do you have known vulnerabilities in your apps?” backed by a CLI tool that fit existing workflows.
- •Founder-led evangelism in a focused developer community
- •In-person conferences and meetups as early distribution
- •Hook messaging: making vulnerability awareness immediate and actionable
- •Early product form: CLI + CI/CD integration for fast feedback
- 17:15 – 19:45
Staying narrow to find PMF, then expanding deliberately
Ben describes why Snyk stayed deep in one ecosystem before broadening: developers care about excellence in their stack, not breadth across others. He shares concrete context about Node’s dependency explosion and how that made the wedge both focused and massive.
- •Depth-before-breadth to validate PMF and build momentum
- •Ecosystem-specific completeness matters more than cross-language support
- •Node/NPM scale and dependency graphs made risk pervasive
- •The temptation of TAM vs. the discipline of focus
- 19:45 – 27:08
Product-led growth loops: GitHub PR loop, Advisor SEO loop, education loop
Ben outlines Snyk’s most powerful growth loops, especially the GitHub “fix PR” loop that doubles as acquisition and engagement. He also explains programmatic SEO via Snyk Advisor and a public security education library that acts as a distribution engine.
- •GitHub loop: scan repos → create branded fix PRs → teammates discover and sign up
- •PR descriptions educate while driving traffic back to Snyk
- •Snyk Advisor: programmatic package pages with health + security metadata
- •Security education: democratized, public lessons as a content loop
- 27:08 – 31:23
Self-serve monetization failed early: enterprise governance and breadth gaps
Despite strong free growth and retention, early self-serve revenue only worked for individual devs—not enterprises. The missing pieces were enterprise governance features and broader language/ecosystem coverage, which also forced Snyk to build relationships with security leadership and add sales/marketing.
- •Early paid traction: individuals (~$100/month), not large orgs
- •Enterprise needs: reporting, user management, governance at scale
- •Broader tech stacks required broader product coverage
- •Shift to product-led sales: developers influence, but buying centers vary
- 31:23 – 35:28
How to win developers: stay in their flow and bring security to their tools
Ben explains that developers must care about the problem, but products also have to make secure behavior painless. The key is meeting developers in existing workflows—like GitHub—so teams benefit without being dragged into separate tools or contexts.
- •Developer motivation: security must feel integral, not a tax
- •Minimize friction by integrating into existing workflows
- •“Flow” is sacred: avoid pulling devs into separate environments
- •One user can secure repos for many collaborators via in-tool delivery
- 35:28 – 54:11
Building the growth org: cross-functional pods, decision science, embedded marketers
Ben describes Snyk’s formalized growth group (built later and larger than typical) and how it evolved into teams for acquisition, activation, monetization, plus a growth platform team. He emphasizes solving cross-functional tension by embedding growth marketers and aligning everyone to shared KPIs, supported by a “decision science” function.
- •From ad hoc growth to a formal developer growth group
- •Team structure: acquisition, activation, monetization + growth platform
- •Cross-functional pods to eliminate R&D vs. marketing incentive friction
- •Decision science: predictive models and deeper analysis for better decisions
- •Embedded growth marketers increase speed, idea diversity, and execution parallelism
- 54:11 – 1:10:12
Operating growth well: process for learnings, loop-based strategy, data trust
Ben shares a practical operating model: documented growth processes optimized for rapid learning and reuse. He covers loop-based strategy for identifying constraints, and the necessity of trustworthy behavioral data—down to schema conformance tested in CI—to power experimentation and product-led sales signals.
- •Growth process goal: rapid learning cadence and systematic reuse
- •Impact & Learnings Reviews (team weekly, group monthly) and open Slack visibility
- •Loop-based strategy to pinpoint constraints and guide quarterly planning
- •Data foundations: intentional event tracking, schema conformance, confidence in metrics
- •Growth as an enabler: powering PLS signals and “paved road” experimentation for all R&D
- 1:10:12 – 1:23:00
Org structure, packaging, and activation: how Snyk measures real value
Ben explains how Snyk’s broader product org is mostly domain/ownership-based, while growth is outcome-based and often experiments on surfaces it doesn’t own (requiring tight coordination). He then covers how Snyk thinks about free vs. paid, trials, and defines activation as teams forming a habit of fixing vulnerabilities within 30 days—strongly correlated with 3-month retention.
- •Product org: functional/domain ownership; growth org: outcome ownership
- •Coordination mechanisms: experiment plan reviews with stakeholder co-design
- •Free vs. paid: growth-enabling features in free; governance drives paid
- •Trials: continually revisited; evaluation time varies by customer complexity
- •Activation: team-based habit of fixing vulnerabilities within 30 days predicts retention
- 1:23:00 – 1:31:34
Tools, lightning round, and closing
Ben lists the most valuable tools in Snyk’s growth stack (analytics, session replay, research, surveys) and adds Airtable as a core system for experiments and knowledge. He closes with quick book/podcast recommendations, interview questions, and where to find him online.
- •Growth tooling: Amplitude, Segment, Fullstory, userinterviews.com, Sprig
- •Airtable as the hub for experiment plans and research knowledge
- •Book recs: How to Measure Anything, Make Time, This Is How They Tell Me the World Ends
- •Favorite podcast: Acquired; interview question themes: curiosity and self-awareness
- •Contact: @SemanticBen on LinkedIn/Twitter; advisory work mentioned