The Artistic Science of Building Lean-and-Mighty Security Teams

Santosh Kandala (Security Startup Leader (6 startups · currently on 7th))

BSides Seattle 2026 · Day 1 · Track 2

Overview

Santosh, who has built and scaled six security startups and is working on his seventh, delivers a talk on the art and science of building effective security teams -- particularly in startup and high-growth environments. The talk deliberately avoids AI topics, focusing instead on the human dynamics of security leadership: understanding business context, hiring the right alpha team, balancing builders versus multipliers, investing beyond security, managing developer experience friction, and cultivating team culture intentionally.

Watch on YouTube

Visual summary for The Artistic Science of Building Lean-and-Mighty Security Teams by Santosh Kandala
Visual summary for The Artistic Science of Building Lean-and-Mighty Security Teams by Santosh Kandala

Key moments

  1. 0:00 Introduction: six startups built and scaled
  2. 4:00 Building the rocket ship: security must map to product-market fit
  3. 5:45 Alpha team hiring: the co-founder mindset
  4. 7:30 Builders vs. multipliers: sequencing your hires
  5. 10:00 Investing beyond security: asset inventory and vuln management
  6. 12:00 Azure Green Team: the ugly tool that cleared 150K certificates
  7. 15:30 Coachability over brilliance: hiring intelligent jerks
  8. 18:00 Psychological safety: the knife analogy and radical candor

The Artistic Science of Building Lean-and-Mighty Security Teams

Speakers: Santosh, Security Startup Leader (6 startups, currently on 7th)

Conference: BSides Seattle 2026

YouTube: https://www.youtube.com/watch?v=xLVmrx1SrOQ

Overview

Santosh, who has built and scaled six security startups and is working on his seventh, delivers a talk on the art and science of building effective security teams -- particularly in startup and high-growth environments. The talk deliberately avoids AI topics, focusing instead on the human dynamics of security leadership: understanding business context, hiring the right alpha team, balancing builders versus multipliers, investing beyond security, managing developer experience friction, and cultivating team culture intentionally.

The talk draws from Santosh's experience across multiple Microsoft teams (Xbox, Windows, Azure), Salesforce, and several startups. His central thesis is that security leadership failures most often stem from building security programs in isolation from business context, and that the difference between success and failure in security teams is cultural alignment -- specifically, the gap between what people think, what they say, and what they do.

This is a leadership and management talk grounded in hard-won operational experience, delivered with candor about personal failures including accidentally bringing down Xbox Live by uploading an updated version of Tripwire.

Background

▶ Watch: Introduction: six startups built and scaled (0:00)

Santosh frames the problem as one of context mismatch: security leaders are hired for technical chops but must succeed by understanding the business. Startups are optimized for survival and product-market fit, so security features must enable and unlock business opportunities rather than exist as standalone initiatives. Zero trust, patch-everything mandates, and compliance frameworks are "great implementation ideas" but may not be applicable to every business context.

The same principle applies to security entrepreneurs inside large organizations who must justify their headcount and program priorities against business outcomes. Santosh argues that jumping into implementation without understanding whether the initiative maps to business strategy is the most common failure mode for security teams.

Key Findings

▶ Watch: Alpha team hiring: the co-founder mindset (5:45)

Alpha Team Hiring (Co-Founder Mindset): The first hires on a security team set the cultural framework for everything that follows. These people must have a co-founder mindset -- willing to sacrifice comfort, stand through failures, and iterate with the mission. They are not just bringing skills; they are establishing the cultural norms that will persist as the team scales.

Builders vs. Multipliers: There are two types of hires: doers who ship and multipliers who scale. Hiring all builders early creates a congestion of subject matter experts solving independent problems in silos without bridging to product-market fit. The optimal sequence: bring in one or two subject matter experts to make things happen, then bring in multipliers to stabilize, productize, and scale.

Non-Security Hires: Security teams should hire from engineering, partner, and customer teams. Santosh hired people from Bing to work on Xbox security and from customer support to build the Windows security team. Diverse context enriches the team more than deep security specialization alone.

Investments Beyond Security: Asset inventory and vulnerability management remain unsolved across the industry because they require cultural transformation across the entire company, not just security team effort. Security outcomes depend on engineering leaders, business leaders, and platform teams being aligned -- most of the work is outbound, not inward.

Developer Experience is Critical: Friction between engineering and security kills adoption. Santosh shares the Azure Green Team story: they built "the world's dumbest thick client and the world's stupidest dashboard that looks like crap" -- but it worked. It went organically viral in the developer community without security doing anything, and cleared 150,000 management certificates off Azure subscriptions. The lesson: build what developers actually use, even if it's ugly.

Culture is the Differentiator: Culture is the difference between what you think, what you say, and what you do. When all three align, that is a healthy culture. One crack in the cultural foundation can ruin a security team's trajectory. Santosh emphasizes coachability as the key hiring signal -- he has hired "intelligent jerks" and had to fire some, while others who were coachable became extremely successful (including one of Microsoft's youngest partners).

Technical Deep Dive

▶ Watch: Investing beyond security: asset inventory and vuln management (10:00)

The talk is leadership-focused rather than technically deep. The most technical references include bringing down Xbox Live by deploying an updated version of Tripwire (a file integrity monitoring tool) without proper regional deployment safeguards, which led Santosh to invest time with the Xbox autopilot team learning regional deployment, staged rollback, and canary deployment patterns. He also references Azure Green Team tooling for certificate management at scale.

The broader technical insight is architectural: security programs fail when they focus only on internal security team capabilities without investing in CI/CD security, developer experience, platform teams, and the engineering infrastructure that ships security features.

Demo / Proof of Concept

▶ Watch: Azure Green Team: the ugly tool that cleared 150K certificates (12:00)

No demo was presented. The talk experienced PowerPoint compatibility issues (Mac adapter to Microsoft display), and Santosh adapted by presenting in a more conversational format. The Azure Green Team example serves as the closest thing to a case study.

Defensive Implications

▶ Watch: Psychological safety: the knife analogy and radical candor (18:00)

For security leaders building or scaling teams:

  • Align every security initiative with a business outcome before starting implementation -- if the business does not see it enabling revenue or customer trust, it will not get traction
  • Sequence hires deliberately: co-founder mindset first, then builders, then multipliers
  • Invest in teams outside security (engineering, platform, developer experience) that directly impact security outcomes
  • Build developer tools that work, even if ugly -- adoption beats sophistication
  • Treat asset inventory and vulnerability management as company-wide cultural transformation problems, not security team problems
  • Watch for cultural misalignment: the gap between what people think, say, and do is the leading indicator of team dysfunction
  • Use psychological safety and radical candor (reference: the book "Radical Candor") to deliver feedback that develops people rather than protecting feelings

Key Takeaways

  • Security leadership fails when it ignores business context -- understand sales, marketing, legal, HR, and product before building security programs
  • First hires define culture; hire for co-founder mindset and coachability, not just technical expertise
  • Balance builders (subject matter experts) with multipliers (people who scale and productize) to avoid expertise silos
  • Invest outward in engineering, platform, and developer experience teams -- security outcomes depend on them
  • Developer experience trumps sophistication: the "ugly tool that works" beats the "beautiful tool nobody uses"
  • Culture is the difference between what you think, what you say, and what you do -- be intentional about protecting it
  • Vulnerability and self-honesty in leadership (admitting you brought down Xbox Live) builds the psychological safety that teams need to take risks

About the Speaker(s)

Santosh has built and scaled six security startups and is currently working on his seventh. His experience spans Microsoft (Xbox, Windows, Azure), Salesforce, and multiple startup environments. He has hired across diverse backgrounds, including from Bing engineering, customer support, and partner teams, and references mentorship from Avi Ben Menahem. His wife is a social media influencer, which informs his thinking about what makes security tools "go viral" in developer communities.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A leadership talk from a seasoned security startup operator with genuine war stories (bringing down Xbox Live with Tripwire, clearing 150K Azure certificates with ugly tooling). The operational wisdom is real but the talk contains no technical research, no security analysis, and no novel methodology. This is a management masterclass, not a security talk.

Heather Calloway (CISO) — STRONG ACCEPT

A deeply practical security leadership talk from someone who has built six security startups and operated across Microsoft, Salesforce, and multiple growth-stage companies. The frameworks for alpha team hiring, builders-vs-multipliers sequencing, and investing beyond security are directly applicable to any CISO building or restructuring a security organization.

→ Top-rated talks at BSides Seattle 2026

All talks from BSides Seattle 2026