Your First Security Hire Is Not an Engineer
Founders hire a strong application security engineer into the first security role and get an unhappy engineer doing spreadsheet work while the queue keeps growing. The job is program work.
For
You are a technical founder holding security, or the first person hired to own it. The job is not the one described in most security writing, because most security writing assumes a team, a budget, and an org chart you do not have.
The decisions that matter at this stage are about sequence and ownership rather than about controls. These pieces cover when the work changes shape, what the first hire should actually be, and which architectural choices are nearly free now and cost quarters later.
Founders hire a strong application security engineer into the first security role and get an unhappy engineer doing spreadsheet work while the queue keeps growing. The job is program work.
Buy a non-human identity tool first and you get a list of eleven thousand identities nobody owns. The ownership decision has to come before the discovery, and it is unglamorous policy work.
An agent built by an engineer who left still holds credentials and still takes actions. Your offboarding checklist was designed for accounts a human logs into, and this is not one.
A software company runs two security programs and funds them as one line. They have different customers, different failure modes, and different people, and merging them starves one of them.
Vendors treat questionnaires as overhead. Buyers treat them as diligence. Both readings are wrong: a questionnaire is the cheapest way one side of a deal shifts work onto the other.
For most B2B software companies SOC 2 is a sales requirement wearing compliance clothing. Reading it correctly changes three decisions: scope, timing against pipeline, and which exceptions you can live with.
Identity debt never arrives as a security incident. It arrives as onboarding that takes nine days, an audit finding that recurs, and a migration estimated at one quarter that takes three.
A technical founder holding security has one real advantage nobody else has, and one disadvantage that compounds. Knowing which is which decides when to hand it over.
Auditors do not evaluate your identity architecture. They pick names off a list and ask you to prove what happened. Elegant design earns nothing if the record is missing.
The usual advice ties this to headcount or revenue. Both are wrong. The trigger is the week security work stops being project-shaped and becomes a queue nobody can drain.