The Unicorn Requisition Nobody Can Clear
Ten years on every tool, a dozen certifications, one person. The CISO on why that posting produces zero résumés — and why whatever you write in the requirements becomes the filter HR actually runs.
Certifications Are a Signal, Not a Guarantee
What to screen for instead: aptitude, curiosity, coachability, ownership, common sense. Plus why a team of five identical résumés shares five identical blind spots.
Build vs. Buy, and the Operations Advantage
Why the CISO prefers upskilling someone who already knows your environment over hiring a security purist who has never carried the operating cost of a control.
The Tool You're Running at 25%
Companies buy the platform and skip the people, then operate a fraction of what they paid for. Plus the maintenance discipline security teams demand of everyone else and exempt themselves from.
Why Good Security People Leave
Two reasons, and the CISO names both. The story of an analyst who broke down from what the job requires you to look at every day, and the fatigue signals leaders miss until it’s attrition.
The Growth Path Trap
One security manager, no open seat above anyone. If you don’t build a path, you lose them regardless — and losing someone into a promotion elsewhere in the company beats losing them to a competitor.
Marching Orders: Don't Hire the Unicorn
Right-size the team before the tool stack, manage on-call so the same two people aren’t always carrying it, and lead as the team’s chief cheerleader.
The Honest Minimum for a Startup
If you think you can’t afford a security function: one named accountable owner at 50–60% of their role, the basics in order, and a small but mighty team built from what the environment actually requires.
// INCOMING SITREP
The episode covers who to hire. The SITREP is the staffing blueprint — requisitions, screening, and the honest minimum at Seed and Series A.
ACCESS THE BRIEF »Last week we covered how to get security funded. This week is the question that follows it: once you have the budget, how do you build the team that performs?
Security is fundamentally a people problem. Tools do not stop attackers — the people running them do. And for a startup, this is not an abstract HR discussion. Your entire security function might be one person, which means every decision about who that person is, what they own, and whether they stay carries more weight than it would anywhere else.
The Myth of the Unicorn Security Professional
The CISO’s opening diagnosis is one most hiring managers will recognize immediately, if uncomfortably.
Ten years of hands-on experience across every tool in the stack. A dozen certifications. Deep expertise in cloud, application security, and detection engineering. All in one person, at a salary the company can approve.
“You end up filtering out really, really great people.”
The mechanism matters here. Whatever goes into the requirements section becomes a screening rule, and HR filters for exactly what you wrote. If nobody clears the bar, you do not see a shallow candidate pool. You see nothing — and then conclude the talent market is worse than it is.
What to Screen For Instead
Certifications belong in the “nice to have” column. Every one of them.
“You can send them to training… but you can’t teach desire.”
The traits that actually predict performance on a small team are the ones résumés are worst at showing: aptitude, curiosity, problem-solving, coachability, integrity, ownership, and — the CISO’s own addition — common sense.
Two of those deserve emphasis. Curiosity is the most common gap in deeply technical candidates, because certainty and curiosity compete: the more convinced someone is that they already understand the environment, the less they look. Coachability is the second. Experienced hires arrive with strong opinions about how things should be done, which is valuable right up until “this is how it should be done” becomes non-negotiable in a company where it isn’t.
Actual connected this to a framework founders will already know — get it, want it, capacity to do it. Most hiring processes test only the third and assume the first two.
Diversity of Background Is a Detection Capability
Hire the deep technical senior. Just don’t hire that same person five times.
“Diversity of background and thought is really an advantage.”
A team of identical résumés reads the same sources, reaches for the same tooling, and shares the same blind spots — which means the thing all of them would miss stays missed permanently. Different backgrounds catch different threads. Someone from IT operations sees the change-management angle. Someone from support sees the user-behavior angle. Someone from engineering sees the pipeline.
For a small team covering a surface far larger than any individual on it, that variety isn’t a staffing nicety. It’s the mechanism.
Build vs. Buy: The Case for Upskilling
You do not need a large team to start. The CISO has watched functional security programs begin with one person who genuinely wanted the work.
Her preference is to build rather than buy, and the reasoning is specific: someone who came up through your operations team already understands what your environment does, and — critically — understands that controls have an operating cost.
A security purist wants everything patched, every gap closed, every control deployed, without a working model of what maintaining those controls costs in engineering hours, change windows, and reliability risk. Someone from ops has lived on the other side of that trade-off, and their recommendations tend to be ones the company can actually sustain.
“You want people who actually understand the entire company and not just security.”
Beyond upskilling, the CISO’s advice is to beg and borrow — dotted-line arrangements that give you working hands without new headcount. The requirement is that the responsibility is written down and named. “IT sort of handles that” is not a dotted line. It’s an unowned control waiting to be discovered by an auditor or a customer’s security questionnaire.
The Tools Trap
This is where startup security budgets most often get wasted.
Companies buy the platform and skip the people. The tool goes in, and the organization ends up running maybe twenty or twenty-five percent of its features — configured once, never revisited, nobody on staff with the depth to maximize it.
Buy one tool. Have the team genuinely learn it. Get full value before buying the next one.
And treat security tooling like the rest of the infrastructure: patched, reviewed, reassessed. Security tools frequently get treated as exempt from the maintenance discipline the security team demands of everyone else. As the CISO put it, what’s good for the other teams should be good for yours.
Then size the team to the actual threat model rather than the org chart. Genuine 24/7 coverage requires staffing that can sustain it. If your risk concentrates in business hours, staff accordingly.
The Cost of Burnout
People leave for two reasons, and the CISO named both: burnout from the work itself, and disagreement with leadership.
The burnout side is structural. On call, in the logs, permanently on alert. She told the story of an analyst who had a breakdown from what the job requires you to look at — the constant stream of the worst material the internet produces, filtered day after day.
“You need to be looking for signs of fatigue.”
The signals show up before the resignation does. The person who used to be warm getting short in their replies. The engineer who stopped asking questions. Fatigue degrades detection quality long before it becomes attrition.
The cultural half is just as important. Nobody wants to fund security, and then when something happens it’s security’s fault. That cannot be the operating culture, because it produces teams that hide problems rather than surface them. The posture to build is that security exists to get the company through an incident, not to be blamed for it.
The Growth Path Problem
The structural trap on a small team is simple. There’s one security manager, that person isn’t leaving, and there’s nowhere for anyone below them to go.
If you don’t build a path, you lose them anyway. Senior individual-contributor tracks, mentorship responsibility, domain ownership, or a deliberate move into another part of the company — all beat losing someone to a competitor because the conversation never happened.
And people want different things. The CISO described an engineer who told her he intended to die at his desk: in at nine, out at six, never thought about the place again, and would happily do excellent work there for the rest of his career. Assuming everyone wants the management track is how you push out that second kind of person.
The Honest Minimum for a Startup
The closing segment is the one we’d point founders to directly.
If a full team isn’t affordable yet, there’s still a real floor, and it starts in the same place every framework and regulation starts: one single accountable security owner. Walk into the company, ask who’s responsible for security, and every person should say the same name.
Ideally that isn’t something handled on the side of someone’s desk. If it has to start as a partial role, it needs to be at least fifty to sixty percent of that person’s job — not ten or twenty — with a written plan for when it becomes the whole job.
From there: understand what you have, then the basics in order, starting with identity and access. Build the team from what the environment requires. Don’t build a team and then work out what it should be doing.
“Small but mighty team. That’s what you’re looking for.”
This is where the episode hands off. We cover who to hire here; the companion SITREP is the staffing blueprint. Your First Security Hire: How to Build a Security Team at a Startup works through rewriting the requisition that’s been filtering out your candidates, what to screen for in the interview, how to structure dotted-line coverage, and what “enough security” actually looks like at Seed and Series A — with the current data on hiring, burnout, and what turnover costs.
Where Audit Readiness Fits
A small team can pass a demanding audit. What a small team cannot absorb is discovering the scope of the work four weeks before an enterprise customer’s deadline.
That’s the work of a structured Audit Readiness program: assessment to establish what you have, remediation sequenced so a two-person team can execute it without stopping the roadmap, and liaison — representation during the audit itself — so your single security owner isn’t solely responsible for defending the company’s posture in a room full of assessors.
For startups, SOC 2 is usually the framework gating enterprise deals. Our Tech Startups industry brief covers what enterprise buyers and acquirers actually examine.
Execute the Standard
Tools don’t defend a company. People do.
A high-performing security team isn’t the one with the most impressive résumés on paper. It’s the one with the right mix, the right leadership, a culture where mistakes get fixed instead of assigned, and people who don’t want to leave. You build that, and you build it on purpose.
If you need an outside read on your control baseline, a remediation sequence a two-person team can actually execute, or representation when the auditor arrives, that’s the work we do. Verify your security posture or book a strategy call.
Hire for the gap. Right-size to your threat model. Lead for retention.
Execute the standard.
// DECODED TRANSCRIPT
Access the full text logs of this transmission for compliance and review purposes.