Feb 17, 2021 · 32m · mad

Fireside Chat: Guy Podjarny (Founder & President, Snyk) with Matt Turck (Partner, FirstMark)

Guy Podjarny · 24m spoken Matt Turck · 4m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this Data Driven NYC fireside chat hosted by FirstMark's Matt Turck, Snyk Founder and President Guy Podjarny discusses Snyk's hypergrowth journey, product-led GTM strategy, and the evolution of cloud-native DevSecOps. Podjarny shares how prioritizing developer experience over traditional security buyer workflows enabled Snyk to build a massive enterprise security business from the bottom up.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Matt holds 15.1% of the talking time here. How this is scored →

Matt as informed peer 3.0 Guest teaching 3.2 Guest disagreement 0.3 Matt pushing back 0.3
05100:0010:0020:0030:000:08–2:33 · Matt as informed peer 2/10 Snyk's Hypergrowth and Recent Milestones Matt opens the fireside chat by congratulating Snyk on its growth and asking Guy to recount key operational milestones. Guy summarizes their headcount expansion, revenue trajectory, fundraising, and strategic acquisitions in a highly collaborative manner.2:33–7:52 · Matt as informed peer 4/10 Understanding Snyk, Cloud Native Security, and DevSecOps Matt demonstrates an understanding of how legacy security tools fail in modern cloud environments and prompts Guy on DevSecOps. Guy politely reframes Matt's question by separating the impact of DevOps (dev-first workflows) from Cloud (turning infrastructure into APIs).7:52–19:13 · Matt as informed peer 3/10 Snyk's Product Journey: Open Source, Containers, IaC, and Code Matt asks informed prompts about Snyk's expansion across Node.js, containers, Infrastructure as Code, and static code analysis. Guy educates the host on SAST limitations, false positives, and why they acquired DeepCode for machine-learning-based code analysis.19:13–21:28 · Matt as informed peer 2/10 Building Snyk's Proprietary Vulnerability Database Matt asks about Snyk's vulnerability database as a core asset. Guy details their threat intelligence infrastructure, combining natural language processing models with human curation to feed ecosystem partners.21:28–24:50 · Matt as informed peer 4/10 Go-to-Market Strategy: Freemium vs. Open Source Models Matt highlights that Snyk operates a freemium commercial model rather than an open-source business model. Guy agrees and clarifies how freemium serves developer use cases while monetization targets governance and enterprise buyers.24:50–29:51 · Matt as informed peer 3/10 Structuring and Scaling Product-Led Growth Teams Matt asks how product-led growth interacts with enterprise sales and scales structurally. Guy explains how Snyk creates dedicated product and marketing sub-teams to prevent enterprise client demands from starving free developer features.0:08–2:33 · Guest teaching 2/10 Snyk's Hypergrowth and Recent Milestones Matt opens the fireside chat by congratulating Snyk on its growth and asking Guy to recount key operational milestones. Guy summarizes their headcount expansion, revenue trajectory, fundraising, and strategic acquisitions in a highly collaborative manner.2:33–7:52 · Guest teaching 4/10 Understanding Snyk, Cloud Native Security, and DevSecOps Matt demonstrates an understanding of how legacy security tools fail in modern cloud environments and prompts Guy on DevSecOps. Guy politely reframes Matt's question by separating the impact of DevOps (dev-first workflows) from Cloud (turning infrastructure into APIs).7:52–19:13 · Guest teaching 4/10 Snyk's Product Journey: Open Source, Containers, IaC, and Code Matt asks informed prompts about Snyk's expansion across Node.js, containers, Infrastructure as Code, and static code analysis. Guy educates the host on SAST limitations, false positives, and why they acquired DeepCode for machine-learning-based code analysis.19:13–21:28 · Guest teaching 3/10 Building Snyk's Proprietary Vulnerability Database Matt asks about Snyk's vulnerability database as a core asset. Guy details their threat intelligence infrastructure, combining natural language processing models with human curation to feed ecosystem partners.21:28–24:50 · Guest teaching 3/10 Go-to-Market Strategy: Freemium vs. Open Source Models Matt highlights that Snyk operates a freemium commercial model rather than an open-source business model. Guy agrees and clarifies how freemium serves developer use cases while monetization targets governance and enterprise buyers.24:50–29:51 · Guest teaching 3/10 Structuring and Scaling Product-Led Growth Teams Matt asks how product-led growth interacts with enterprise sales and scales structurally. Guy explains how Snyk creates dedicated product and marketing sub-teams to prevent enterprise client demands from starving free developer features.0:08–2:33 · Guest disagreement 0/10 Snyk's Hypergrowth and Recent Milestones Matt opens the fireside chat by congratulating Snyk on its growth and asking Guy to recount key operational milestones. Guy summarizes their headcount expansion, revenue trajectory, fundraising, and strategic acquisitions in a highly collaborative manner.2:33–7:52 · Guest disagreement 1/10 Understanding Snyk, Cloud Native Security, and DevSecOps Matt demonstrates an understanding of how legacy security tools fail in modern cloud environments and prompts Guy on DevSecOps. Guy politely reframes Matt's question by separating the impact of DevOps (dev-first workflows) from Cloud (turning infrastructure into APIs).7:52–19:13 · Guest disagreement 0/10 Snyk's Product Journey: Open Source, Containers, IaC, and Code Matt asks informed prompts about Snyk's expansion across Node.js, containers, Infrastructure as Code, and static code analysis. Guy educates the host on SAST limitations, false positives, and why they acquired DeepCode for machine-learning-based code analysis.19:13–21:28 · Guest disagreement 0/10 Building Snyk's Proprietary Vulnerability Database Matt asks about Snyk's vulnerability database as a core asset. Guy details their threat intelligence infrastructure, combining natural language processing models with human curation to feed ecosystem partners.21:28–24:50 · Guest disagreement 1/10 Go-to-Market Strategy: Freemium vs. Open Source Models Matt highlights that Snyk operates a freemium commercial model rather than an open-source business model. Guy agrees and clarifies how freemium serves developer use cases while monetization targets governance and enterprise buyers.24:50–29:51 · Guest disagreement 0/10 Structuring and Scaling Product-Led Growth Teams Matt asks how product-led growth interacts with enterprise sales and scales structurally. Guy explains how Snyk creates dedicated product and marketing sub-teams to prevent enterprise client demands from starving free developer features.0:08–2:33 · Matt pushing back 0/10 Snyk's Hypergrowth and Recent Milestones Matt opens the fireside chat by congratulating Snyk on its growth and asking Guy to recount key operational milestones. Guy summarizes their headcount expansion, revenue trajectory, fundraising, and strategic acquisitions in a highly collaborative manner.2:33–7:52 · Matt pushing back 1/10 Understanding Snyk, Cloud Native Security, and DevSecOps Matt demonstrates an understanding of how legacy security tools fail in modern cloud environments and prompts Guy on DevSecOps. Guy politely reframes Matt's question by separating the impact of DevOps (dev-first workflows) from Cloud (turning infrastructure into APIs).7:52–19:13 · Matt pushing back 0/10 Snyk's Product Journey: Open Source, Containers, IaC, and Code Matt asks informed prompts about Snyk's expansion across Node.js, containers, Infrastructure as Code, and static code analysis. Guy educates the host on SAST limitations, false positives, and why they acquired DeepCode for machine-learning-based code analysis.19:13–21:28 · Matt pushing back 0/10 Building Snyk's Proprietary Vulnerability Database Matt asks about Snyk's vulnerability database as a core asset. Guy details their threat intelligence infrastructure, combining natural language processing models with human curation to feed ecosystem partners.21:28–24:50 · Matt pushing back 1/10 Go-to-Market Strategy: Freemium vs. Open Source Models Matt highlights that Snyk operates a freemium commercial model rather than an open-source business model. Guy agrees and clarifies how freemium serves developer use cases while monetization targets governance and enterprise buyers.24:50–29:51 · Matt pushing back 0/10 Structuring and Scaling Product-Led Growth Teams Matt asks how product-led growth interacts with enterprise sales and scales structurally. Guy explains how Snyk creates dedicated product and marketing sub-teams to prevent enterprise client demands from starving free developer features.

speaking balance: gold is Matt, purple is the guest (3 minute bins)

0:00 · Matt 15.2% · guest 84.8%0:00 · Matt 15.2% · guest 84.8%3:00 · Matt 13.8% · guest 86.2%3:00 · Matt 13.8% · guest 86.2%6:00 · Matt 15.9% · guest 84.1%6:00 · Matt 15.9% · guest 84.1%9:00 · Matt 0% · guest 100%9:00 · Matt 0% · guest 100%12:00 · Matt 5.2% · guest 94.8%12:00 · Matt 5.2% · guest 94.8%15:00 · Matt 5.8% · guest 94.2%15:00 · Matt 5.8% · guest 94.2%18:00 · Matt 8.5% · guest 91.5%18:00 · Matt 8.5% · guest 91.5%21:00 · Matt 17.7% · guest 82.3%21:00 · Matt 17.7% · guest 82.3%24:00 · Matt 15% · guest 85%24:00 · Matt 15% · guest 85%27:00 · Matt 32.4% · guest 67.6%27:00 · Matt 32.4% · guest 67.6%30:00 · Matt 45% · guest 55%30:00 · Matt 45% · guest 55%
Sharpest disagreement ▶ 6:11 Soft reframe on DevOps vs. Cloud

Guy gently pushes back on Matt mixing DevOps and Cloud concepts, distinguishing between workflow changes and infrastructure API shifts.

Hardest push from Matt ▶ 21:28 Calling out freemium vs. open source

Matt directly challenges the premise that Snyk is an open source company, pointing out that their model is actually commercial freemium.

Biggest teaching moment ▶ 6:11 Explaining cloud-native application security layers

Guy breaks down how pre-cloud IT stacks differed from cloud repos, educating the host on why containers require app security rather than IT security.

Matt holds his own ▶ 5:47 Synthesizing the failure of legacy security tools

Matt demonstrates strong domain knowledge by articulating how firewalls and endpoint security broke under microservices and cloud architectures.

the scores for every segment, with the reasoning behind each
ChapterTopicMatt as informed peerGuest teachingGuest disagreementMatt pushing backWhy
Snyk's Hypergrowth and Recent Milestones 2200 Matt opens the fireside chat by congratulating Snyk on its growth and asking Guy to recount key operational milestones. Guy summarizes their headcount expansion, revenue trajectory, fundraising, and strategic acquisitions in a highly collaborative manner.
Understanding Snyk, Cloud Native Security, and DevSecOps 4411 Matt demonstrates an understanding of how legacy security tools fail in modern cloud environments and prompts Guy on DevSecOps. Guy politely reframes Matt's question by separating the impact of DevOps (dev-first workflows) from Cloud (turning infrastructure into APIs).
Snyk's Product Journey: Open Source, Containers, IaC, and Code 3400 Matt asks informed prompts about Snyk's expansion across Node.js, containers, Infrastructure as Code, and static code analysis. Guy educates the host on SAST limitations, false positives, and why they acquired DeepCode for machine-learning-based code analysis.
Building Snyk's Proprietary Vulnerability Database 2300 Matt asks about Snyk's vulnerability database as a core asset. Guy details their threat intelligence infrastructure, combining natural language processing models with human curation to feed ecosystem partners.
Go-to-Market Strategy: Freemium vs. Open Source Models 4311 Matt highlights that Snyk operates a freemium commercial model rather than an open-source business model. Guy agrees and clarifies how freemium serves developer use cases while monetization targets governance and enterprise buyers.
Structuring and Scaling Product-Led Growth Teams 3300 Matt asks how product-led growth interacts with enterprise sales and scales structurally. Guy explains how Snyk creates dedicated product and marketing sub-teams to prevent enterprise client demands from starving free developer features.

Statements from this episode (15)

Assertion Not checkable as stated
Podjarny: Snyk scaled staff annually from 23 to 450 employees
“We've gone from 23 to 84 to 250 to 450 people in annual increments in terms of staff.”
Guy Podjarny Feb 17, 2021 ▶ 0:31
Assertion Not checkable as stated
Podjarny: Snyk grew revenue and ARR by around 200%
“We've grown I think about 200% in, in revenue and sort of a similar number in, in ARR.”
Guy Podjarny Feb 17, 2021 ▶ 1:21
Assertion Supported
Podjarny: Snyk raised roughly $350M over 12 to 18 months
“We did raise about three hundred and fifty million dollars during during that period of time as well.”
Guy Podjarny Feb 17, 2021 ▶ 2:08
Insight
Podjarny: Security must be embedded in the development process to scale
“Security has to be built into the development process because nothing else scales.”
Guy Podjarny Feb 17, 2021 ▶ 2:43
Insight
Podjarny: Developer-first security requires building a developer tooling company
“To achieve that, you need to build a developer tooling company, not a security company.”
Guy Podjarny Feb 17, 2021 ▶ 2:53
Insight
Podjarny: Security products require broad stack coverage to deliver real value
“A security person needs breadth. They need, if you solve the security threat, but you only solve it for 50% of my apps, you're not very helpful security. I'm going to need to buy another tool or find another solution for the other 50% because I need to cover a…”
Guy Podjarny Feb 17, 2021 ▶ 9:38
Insight
Podjarny: Containers are the evolution of the app, not the VM
“The industry has been seeing containers as the evolution of the VM. And they've been trying to retrofit VM patching practices onto containers while we saw containers as the evolution of the app.”
Guy Podjarny Feb 17, 2021 ▶ 10:55
Disclosure
Snyk launches new products as narrow add-ons before making them standalone
“We ship every new product we've added, and now we do it intentionally... We ship it as an add-on first. So we don't ship, you know, crap products pardon my French here. You know, we ship very good products, but very narrow ones. And we ship them as add-ons. An…”
Guy Podjarny Feb 17, 2021 ▶ 11:23
Opinion
Podjarny: Traditional SAST security tools are not usable for developers
“Unless we can actually build something that is fast enough for CICD, which these tools are not. And that is accurate enough to actually be usable to developers, because as it stands, these tools are not usable for developers.”
Guy Podjarny Feb 17, 2021 ▶ 16:21
Opinion
Tech giants rely on Snyk's vulnerability database due to lacking alternatives
“Many players rely on it now as their sort of information source for properties because there is no other good one really in the yeah.”
Guy Podjarny Feb 17, 2021 ▶ 21:16
Assertion Not checkable as stated
Guy Podjarny: GitHub is not open-source but gets its halo
“GitHub is not an open source company. It's but it benefits from the halo of open source.”
Guy Podjarny Feb 17, 2021 ▶ 23:53
Insight
Guy Podjarny: Open source struggles with maintenance and vulnerability tracking
“Open source is not known for being very good at maintenance. So things like the vulnerability database and things like that. They don't really work that well in most cases”
Guy Podjarny Feb 17, 2021 ▶ 24:14
Disclosure
Podjarny: Majority of Snyk's business is freemium and inbound led
“The majority of our business is still freemium and inbound led.”
Guy Podjarny Feb 17, 2021 ▶ 25:49
Insight
Protect freemium growth from enterprise demands using structural resource isolation
“It became hard for someone leading both the product that growth aside and the enterprise motion to say, no, no, no, I will put aside this like very large customer's requirement. And I will prioritize this sort of freemium user. Need instead of that. So you hav…”
Guy Podjarny Feb 17, 2021 ▶ 29:02
Insight
Podjarny: DevSecOps practitioners must be software builders, not passive auditors
“A DevSecOps person is very similar to an SRE. They should be a person able to build software build services and help developers successfully find issues and fix them as opposed to an auditor who should be good at finding those issues themselves and doing it.”
Guy Podjarny Feb 17, 2021 ▶ 30:18
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 400 conversations transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.