Skip to content
A job requisition filtered down to zero candidates beside a single accountable security owner marked on a startup org chart.
SITREP // TECH SECTOR // FIRST SECURITY HIRE

Your First Security Hire: How to Build a Security Team at a Startup

The requisition you wrote is the reason the role has been open for nine months, and the candidate who could actually do the job is probably already on your payroll. This is the staffing blueprint for building a security function from zero without hiring a unicorn.

The security engineer role has been open for nine months. Recruiting says the market is impossible. The market is difficult, but it is not the reason the seat is empty.

The reason is the requisition. Ten years of hands-on experience across every tool in the stack, a stack of certifications, cloud and application and detection engineering depth, all in one person, at a salary the company can actually approve. That person exists in roughly the numbers you would expect. Meanwhile the filter you wrote is the filter your applicant tracking system runs, and it is quietly rejecting the people who could have done the work.

This is the staffing side of the problem — who to hire, what to screen for, what “enough” looks like at Seed and Series A, and how to keep the people you land. It is a resilience question, not an HR question. A security function that churns every eighteen months never accumulates the institutional knowledge that makes it effective.

The Unicorn Requisition Is Why the Role Is Still Open

The Filter You Wrote Is the Filter HR Runs

Whatever goes into the requirements section becomes a screening rule. If nobody clears it, you do not see a thin candidate pool. You see no résumés at all, and you conclude the talent shortage is worse than it is.

The industry has started measuring this honestly. ISC2’s 2025 Cybersecurity Workforce Study — its largest ever, with more than 16,000 respondents — declined to publish a global workforce-gap number for the first time in the study’s history. The stated reason was that shortfalls in specific skills now matter more to practitioners than raw headcount. The constraint moved. Most job descriptions did not.

The clearest evidence that requisitions have drifted from reality: ISC2 has found employers requiring certifications for entry-level postings that themselves mandate five or more years of experience. That is not a high bar. It is a contradiction, and it filters out every candidate who could have grown into the role.

Certifications Are a Signal, Not a Guarantee

Move certifications to “nice to have.” Every one of them. A certification tells you someone studied a body of knowledge and passed a test on a specific date. It does not tell you whether they will notice the thing nobody flagged, or whether they will tell you when they are wrong.

You can send someone to training. You can fund a certification. What you cannot fund is desire, and you cannot install curiosity in a hire who arrived certain they already know everything.

What to Screen For Instead

The traits that predict performance on a small security team are not the ones résumés are built to display. Interview for them directly:

  • Curiosity — the willingness to pull a thread that looks boring. This is the single most common gap in deeply technical candidates, because expertise and curiosity compete: the more certain someone is that they already understand the environment, the less they look.
  • Coachability — will they run your process, or the process from their last company? Experienced hires arrive with strong opinions about how things should be done. That is valuable right up until it becomes non-negotiable.
  • Ownership — do they take accountability when something breaks on their watch, without being asked to?
  • Integrity — you are handing this person standing access to everything.
  • Common sense — hard to define, impossible to teach, and immediately obvious in a scenario question. Ask what they would do with an ambiguous alert at 2 a.m. with no runbook.

There is a business framework that maps almost exactly onto this: does the candidate get it, do they want it, and do they have the capacity to do it. Most hiring processes test only the third and assume the first two.

Diversity of Background Is a Detection Capability

The failure mode is a team of five people with the same résumé. They read the same sources, reach for the same tooling, and share the same blind spots — which means the thing all five of them would miss stays missed permanently.

Hire the deep technical senior. Just do not hire only that person five times. Different backgrounds catch different threads: someone from IT operations sees the change-management angle, someone from support sees the user-behavior angle, someone from software engineering sees the pipeline. Diversity of background and thought is not a staffing nicety here. It is the mechanism by which a small team covers a surface larger than any individual on it.

Build vs. Buy: Your Best Candidate May Already Work Here

The Operations Advantage

The person who already runs your infrastructure understands what your environment actually does, which is knowledge that takes a new hire six months to build and that no interview can test for.

They also understand something a security purist frequently does not: controls have an operating cost. A candidate who has only ever done security will want everything patched, every gap closed, every control deployed — without a working model of what maintaining those controls costs in engineering hours, change windows, and reliability risk. Someone who came up through operations has lived on the other side of that trade-off, and their recommendations tend to be ones the company can actually sustain.

This path is far better established than most hiring managers assume. ISACA’s research has found that a substantial share of working cybersecurity professionals — roughly 46% in its 2025 study — moved in from non-security roles. Career changers are not the exception in this field. They are close to half of it.

Beg, Borrow, and Dotted Lines

You do not need every contributor on your headcount. Dotted-line arrangements — an ops engineer with a defined security portion of their week, a platform engineer who owns detection tuning, a legal or compliance partner who owns vendor review — give you working hands against a budget you already have.

The requirement is that the responsibility is written down and named. An informal understanding that “IT sort of handles that” is not a dotted line. It is an unowned control that will be discovered by an auditor, a customer’s security questionnaire, or an incident.

// INCOMING TRANSMISSION

Our 031 The Talent Gap, Burnout Culture, and How to Build a High-Performing Security Team podcast episode covers what a high-performing team actually looks like, why unicorn requisitions fail, and how leaders keep the people they hire.

INITIATE PLAYBACK »

The Honest Minimum at Seed and Series A

Founders ask what the floor is when a full team is not affordable yet. There is a real answer, and it is smaller than most people expect.

One Named, Accountable Owner

Walk into the company and ask who is responsible for security. Every person should say the same name.

That is the entire first requirement, and nearly every framework and regulation starts in the same place. If the answer varies by who you ask, you do not have a small security program. You have no security program, regardless of what tooling is deployed.

Ideally this is not something handled on the side of someone’s desk. If it must start as a partial role, it needs to be at least half of that person’s job — not ten or twenty percent — with a written plan for when it becomes the whole job. Security work compressed into the margins of another role is the first thing dropped in a busy quarter, which is precisely when it matters.

Know What You Have

Before controls, inventory. Systems, data, who can access what, which third parties touch production, where the sensitive data actually lives. Most early-stage security failures are not sophisticated attacks. They are things nobody knew were exposed.

Identity and Access Before Anything Advanced

Then the basics, in order. Identity and access management first — it is the control that most attacks route through and the one auditors examine first. Advanced capability comes later, built on an understanding of your own environment.

The sequence matters more than the speed. Build the team from what the environment requires. Do not build a team and then work out what it should be doing.

Right-Size the Team, Not the Tool Stack

The most expensive mistake in early security programs is buying capability instead of hiring it.

A platform gets purchased, deployed, and then operated at a fraction of what it can do — twenty or twenty-five percent of its features, configured once and never revisited. The budget is spent. The capability was never acquired, because nobody on staff has the time or depth to maximize it.

Buy one tool. Have the team genuinely learn it. Get full value from it before buying the next one.

And treat security tooling like the rest of the infrastructure. It needs patching, configuration review, and periodic reassessment against new features. Security tools frequently get treated as exempt from the maintenance discipline the security team demands of everyone else. What is good for the other teams is good for yours.

Then size the team to the actual threat model. If you genuinely run 24/7, you need coverage that can sustain 24/7 without destroying three people. If your risk concentrates in business hours, staff accordingly. Asking for twenty when the environment requires twelve costs you credibility you will need for the next request — a dynamic covered in depth in our field guide on quantifying cyber risk in dollars.

Retention Is a Security Control

Hiring well and losing them in eighteen months is not a hiring success. Every departure takes institutional knowledge that is not written down anywhere, and the seat sits empty while the surface stays exposed.

Burnout Is Measurable, and So Is Its Cost

The numbers on this are not subtle. Tines research found 71% of SOC analysts reporting burnout driven primarily by alert fatigue, with average tenure at many organizations dropping below eighteen months. Proofpoint’s Voice of the CISO work put the share of security leaders who experienced or witnessed burnout at 63%; Sophos measured it at 76%. The 2026 IANS and Artico Search talent report found only about a third of security professionals planning to stay in their current role.

Replacement runs somewhere between half and twice an analyst’s annual salary once recruiting, onboarding, and lost institutional knowledge are counted. IBM has separately measured roughly $1.76 million in additional breach cost at organizations operating with severe staffing shortfalls. Turnover is not a soft cost. It shows up in the same model as everything else.

The human version underneath those numbers matters too. Security analysts spend their working hours inside the worst material the internet produces, constantly on alert, frequently on call. Watch for the signals — the person who used to be warm getting short in their replies, the engineer who stopped asking questions. Fatigue is visible before it becomes attrition, and it degrades detection quality long before anyone resigns.

The Growth Path Problem

The structural trap on a small team: there is one security manager, that person is not leaving, and there is nowhere for anyone below them to go.

If you do not build a path, you lose them anyway. The options are real — senior individual-contributor tracks, mentorship responsibility, ownership of a domain, or a deliberate move out of your team into another part of the company. Losing someone into a promotion elsewhere in the organization is a far better outcome than losing them to a competitor because the conversation never happened.

And accept that people want different things. Some engineers want to run the function someday. Others want to do excellent work between nine and six and never think about the place again — and will do that excellent work for a decade if you let them. Both are valuable. Assuming everyone wants the first path is how you push out the second kind.

Blameless Culture Is Not a Perk

Nobody wants to fund security, and then when something happens, it is security’s fault. That cannot be the culture, because it produces teams that hide problems.

The posture to build is that security exists to get the company through an incident, not to be blamed for it. Manage on-call so the same two people are not always carrying it. Ensure the rest of the team is cross-trained enough to share the rotation. Recognize the work publicly — everyone needs to know their work is seen. That is the whole retention strategy, and it costs almost nothing.

Where Audit Readiness Fits

A small team can pass a demanding audit. What a small team cannot absorb is discovering the scope of the work four weeks before a customer’s deadline.

That is where a structured Audit Readiness program does the load-bearing work. Assessment establishes what you have and where the real gaps are, which is the same inventory your first security owner needs anyway. Remediation sequences the work so a two-person team can execute it without stopping the product roadmap. Liaison is representation during the audit itself — the keystone step, and the one that spares your single security owner from being solely responsible for defending the company’s posture in a room full of assessors.

For startups, SOC 2 is usually the framework that gates enterprise deals, with HIPAA entering the picture the moment you touch health data. Our Tech Startups industry brief covers what enterprise buyers and acquirers actually examine.

Marching Orders

1. Rewrite the Requisition Before You Repost It

Strip every certification down to “preferred.” Cut the years-of-experience floor by half. Remove any tool named in the requirements that a competent engineer could learn in a month. Then look at how many résumés arrive.

2. Interview the Candidates Who Look Underqualified on Paper

Résumés are optimized documents and everyone knows it, so stop using them as the hiring gate. Talk to the people who have the fundamentals but not the full list. Test for curiosity, coachability, and common sense in the conversation.

3. Look Inside Before You Look Outside

Identify the two people already on staff who understand your environment and have shown interest in security work. Fund their training. They will be productive months before an external hire clears onboarding, and they already know what breaks when a control goes in.

4. Name One Accountable Owner This Week

Write it down. Put it in the org chart. Make it at least half of that person’s role, with a plan to reach full time. This costs nothing and is the single highest-leverage move available to a company that has no security function today.

5. Operate the Tools You Own Before You Buy Another

Audit your current stack for actual utilization. If a platform is running at a quarter of its capability, the next purchase makes the problem worse, not better.

6. Build the Growth Conversation Into the First Ninety Days

Ask each person what they want in two years, and revisit it on a schedule. The departures that hurt most are the ones where nobody ever asked.

Execute the Standard

Tools do not defend a company. People do.

A high-performing security team is not the one with the most impressive résumés on paper. It is the one with the right mix of backgrounds, a leader who translates upward, a culture where mistakes get fixed instead of assigned, and people who do not want to leave. Small but mighty is not a consolation prize. For most companies, it is the correct answer.

If you need an outside read on your control baseline, a remediation sequence a two-person team can actually execute, or representation when the auditor arrives, that is the work we do. Book a strategy call or establish a secure line.

Hire for the gap. Right-size to your threat model. Lead for retention.

Execute the standard.

SECURE YOUR PERIMETER.

DON'T WAIT FOR THE BREACH TO READ THE SITREP.

Join The Watch for immediate access to Declassified Sitreps and Strategic Intel before the threat reaches your door.