Career Village: WTF is an Org Chart? Building Security Teams
Matt Damco (Head of Security · Zenity)
BSides Seattle 2026 · Day 2 · Track 2
Overview
Matt Damco, Head of Security at Zenity, delivers a practical guide on how to build and scale security teams from the ground up. Drawing from his experience advising startup founders and working across companies of varying sizes, Damco walks through the organizational psychology behind security team design -- from the very first hire at a 10-person startup to structuring pillars at a 300+ person organization.

Key moments
- 0:00 Matt Damco introduces the talk on building security teams
- 1:30 Security kills companies two ways: breaches and overbearing programs
- 5:48 Nine-box security persona model: work types and superpowers
- 9:45 Phase 1 (0-50 people): find trusted partners, not full-time hires
- 14:12 Cloud provider accelerator programs for free security support
- 19:48 Phase 3 (300+): pillars form and capacity planning becomes critical
- 25:45 Using Jira service labels and metrics to justify headcount
- 28:00 Automating ticket tagging with Claude Code skills
Career Village: WTF is an Org Chart? Building Security Teams
Speakers: Matt Damco, Head of Security, Zenity
Conference: BSides Seattle
YouTube: https://www.youtube.com/watch?v=oVqGd5XKUaM
Overview
Matt Damco, Head of Security at Zenity, delivers a practical guide on how to build and scale security teams from the ground up. Drawing from his experience advising startup founders and working across companies of varying sizes, Damco walks through the organizational psychology behind security team design -- from the very first hire at a 10-person startup to structuring pillars at a 300+ person organization.
The talk confronts a fundamental tension: security kills companies in two ways. A breach can sink a business, but so can an overly burdensome security program that slows down a five-person startup with ticket queues and library reviews. The challenge is rightsizing security investment to match the company's actual risk profile, customer expectations, and growth trajectory.
This is a leadership and strategy talk aimed squarely at first security hires, founders making their first security decisions, and security leaders scaling programs at high-growth companies. Damco brings a refreshingly honest perspective, arguing that there are no bonus points for extra security and that knowing when not to build is just as important as knowing what to build.
Background
▶ Watch: Matt Damco introduces the talk on building security teams (0:00)
The security industry has long struggled with a one-size-fits-all approach to building security programs. Frameworks designed for Fortune 500 companies get cargo-culted into 20-person startups, consuming resources that should be going to product development. Damco draws on a concept from organizational psychology -- the study of how people and structures interact within organizations -- to create a more adaptive model.
The core insight is that security team design must flow from business needs, not from industry templates. A medical device company has radically different security requirements than a social media startup, even at the same headcount. Damco's framework forces founders to answer four foundational questions before making any hiring decisions: What type of product do we sell? Who are our customers? Are we in a regulated industry? How sophisticated are our customers technically?
Key Findings
▶ Watch: Nine-box security persona model: work types and superpowers (5:48)
Damco introduces a nine-box security persona model that maps three work types (corporate security, product security, and sales security) against three superpowers (compliance/audit, engineering, and evangelism). This framework lets security leaders visualize where their time goes and where gaps exist.
The key insight is that at different company stages, these personas manifest differently. At 0-50 people, one person stretches across all nine boxes. At 50-250 people, distinct roles emerge (GRC analyst, security operations, product security tech lead). At 300+ people, full pillars form with dedicated teams and service catalogs.
Damco found that the most common mistake at the scaling phase (50-250) is hiring a manager before having enough executors. His recommendation: the first three security hires should all be individual contributors and subject matter experts, not managers. A manager of one engineer creates overhead without value.
Another critical finding: by tracking security work in Jira with service labels, teams can build a data-driven case for headcount. Damco showed a lightly sanitized planning document where he measured ticket volume across service categories to determine whether to hire a product security engineer, a security operations person, or a GRC analyst first. In his case, 250 customer security questions in a single month pointed clearly toward GRC as the priority hire.
Technical Deep Dive
▶ Watch: Cloud provider accelerator programs for free security support (14:12)
The framework centers on what Damco calls business persona identification. The four diagnostic questions produce a profile that determines the thickness of each security pillar:
- Product type: B2C customers rarely demand security rigor; B2B enterprise customers (especially those like Amazon's third-party security team) will scrutinize everything; B2B2C products carry compounding risk since a failure affects the downstream customer's entire user base.
- Industry regulation: A HIPAA-compliant AI medical device requires a fundamentally different program than a consumer IoT gadget. The regulatory surface area directly determines GRC investment.
- Customer sophistication: Technical customers who evaluate your security posture require proactive engagement; non-technical customers who just want things to work require less sales security but potentially more product security.
- Growth trajectory: The hockey-stick question. If a company is at 300 people today and will be at 1,000 in nine months, capacity planning must begin immediately rather than being deferred by day-to-day firefighting.
Damco introduces composable security patterns as a scaling mechanism for early-stage companies. Rather than reviewing individual APIs, the approach is to create shared libraries for authentication and authorization, then build CI/CD pipeline checks that validate their adoption. This converts one-off security reviews into scalable, self-service security.
He also highlights a modernization opportunity: using tools like Claude Code to automate Jira ticket tagging and service classification. What previously required hours of manual ticket management can now be defined as a skill that creates tickets, applies service labels, and flags untagged work items automatically.
For financial justification when scaling back an overbuilt program, Damco recommends Axan Analytics, which uses actuarial data from cyber insurance companies to calculate annual loss expectancy. By mapping control costs against the change in ALE when a control is removed, teams can make rational investment decisions.
Demo / Proof of Concept
▶ Watch: Phase 3 (300+): pillars form and capacity planning becomes critical (19:48)
Rather than a technical demo, Damco ran three interactive case studies with the audience. Each presented a fictional company (Novabyte, Clear Path Retail, and a knife manufacturer) and challenged attendees to ask diagnostic questions before making security decisions.
The Novabyte exercise demonstrated the importance of understanding B2B vs. B2C dynamics and industry sensitivity (pharmaceuticals vs. farm equipment). The Clear Path Retail exercise (12,000 employees) revealed a critical insight: most of those employees may be retail workers or delivery drivers who never touch technology, dramatically changing the security team size requirements. The knife manufacturer exercise highlighted the most provocative question a first security hire should ask: "Why are you hiring me instead of outsourcing?" -- especially when the business primarily operates in the physical world.
Defensive Implications
▶ Watch: Automating ticket tagging with Claude Code skills (28:00)
For defenders and security leaders, the talk offers several actionable frameworks. First, always ask who was doing security before you arrived. A third-party auditor or managed service provider may already have significant institutional knowledge, and building in a silo wastes time and creates friction.
Second, the concept of the Point of Mediocrity (PALM) is useful for assessing organizational readiness. If a company is profitable at 50 people with minimal effort, expecting transformational security investment may be unrealistic. Leaders need to honestly assess whether they can drive change or whether they should find a team more aligned with their ambitions.
Third, cloud provider startup accelerator programs (AWS, Google, Microsoft) provide credits usable for professional services, not just compute. Damco reports getting six months of expert security support at zero cost through these programs -- a critical resource for early-stage companies that cannot afford full-time senior hires.
Key Takeaways
- Security kills companies two ways: through breaches and through overly burdensome programs that slow business execution
- The first three security hires should be individual contributor experts, not managers -- a manager of one engineer creates overhead without value
- Use the nine-box persona model (work type vs. superpower) to identify gaps and plan hiring based on where time is actually spent
- Track security work with service labels in Jira (now automatable with AI tools) to build data-driven headcount justifications
- Always ask "who was solving this before me?" when joining as a first security hire -- institutional knowledge from third parties may already exist
- Use annual loss expectancy calculations (via tools like Axan Analytics) to financially justify or rightsize security program investment
About the Speaker(s)
Matt Damco is the Head of Security at Zenity. He is passionate about security engineering and leadership theory, with a particular interest in organizational psychology. He has experience working at large companies including Amazon and advises startup founders on building security programs from scratch. He draws on both his enterprise background and his work with early-stage companies to develop practical frameworks for security team growth.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
A management and organizational strategy talk with zero technical depth. Damco presents a reasonable framework for scaling security teams at startups, but there is no vulnerability research, no exploit development, no novel tooling, and no measurable technical contribution. The nine-box persona model is common sense dressed up as methodology.
Heather Calloway (CISO) — STRONG ACCEPT
A genuinely useful talk for any CISO or security leader building a program from scratch or scaling one at a high-growth company. Damco's business-first approach to security team design, his data-driven headcount justification method, and his honest framing of when not to build are exactly the kind of practical governance thinking that the industry needs more of.