Trust Engineering: Building Security Leadership at Early-Stage Startups
Mike Privette
BSidesSF 2025 — Here Be Dragons · Day 2 · Main
Overview
Being the first security hire at a startup is fundamentally different from enterprise security — it is a business leadership role that happens to do security. Mike Privette's "trust engineering" framework provides five concrete steps for building credibility and influence before attempting to build a security program, flipping the conventional model on its head. ---

Key moments
- 3:29 Startups hire security leaders for customer pressure, not security desire
- 6:00 Key skills: translation, ambiguity navigation, resource-constrained mindset
- 8:59 Trust engineering framework: four pillars for early-stage security success
- 12:59 Misconception shattered: startup CISO reality vs. enterprise expectations
- 16:59 Practical step: security as business enabler, not compliance checkbox
- 20:59 Building trust capital: security leader as internal sales function
- 24:59 Framework applied: mapping security wins to company growth phases
- 28:01 Key lesson: influence without authority is the core startup security skill
Trust Engineering: Building Security Leadership at Early-Stage Startups
Speaker: Mike Privette
Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco
YouTube: Watch the full talk
Reading time: ~7 minutes
TL;DR
Being the first security hire at a startup is fundamentally different from enterprise security — it is a business leadership role that happens to do security. Mike Privette's "trust engineering" framework provides five concrete steps for building credibility and influence before attempting to build a security program, flipping the conventional model on its head.
Introduction
Most security professionals enter a startup with a mental model calibrated for the enterprise: defined scope, an existing team, frameworks to build on, and an organizational mandate to drive compliance. That mental model, according to Mike Privette, will get you fired. Privette, founder of the security research firm Return on Security and a self-described specialist in being the first security hire at early-to-growth-stage B2B SaaS companies, has spent years studying what separates security leaders who thrive in startup environments from those who flame out.
His answer is trust engineering — a systematic approach to positioning yourself as a business leader first and a security professional second. The premise is simple and uncomfortable: in an early-stage startup, the business cannot afford for security to be security's top priority. Without revenue, growth, and survival, there is no security program to build.
▶ Watch: The startup security mindset (02:00)
Why Startups Hire Security Leaders (And What They Actually Want)
Privette opens by dismantling a common misconception: startups do not hire security leaders because they want to be secure. They hire them because of external forcing functions — customer security questionnaires, deals stalled by procurement teams conducting third-party risk assessments, regulated markets like healthcare and financial services requiring a named accountable person, competitive pressure from rivals who can advertise their security posture, or simply because a funding round finally made a full-time hire possible.
This matters because the expectations are almost always misaligned from day one. The company thinks it has hired someone to fill compliance checkboxes and unblock sales deals. The new hire thinks they have been given a mandate to build a real security program. Both are partially right and almost entirely talking past each other.
▶ Watch: Why the expectations gap is your actual challenge (10:00)
"There's what you think you were hired to do, and then there's what they think you were hired to do. And they often are not the same — but therein lies your actual challenge. You have to make those meet."
The sooner a first security hire recognizes and closes this gap, Privette argues, the sooner they can stop fighting the organization and start building something durable.
The Five Steps of Trust Engineering
Privette's framework distills to five steps, none of which begins with "assess the attack surface."
▶ Watch: Introducing the five steps (14:00)
1. Align with sales and marketing. This is the one that surprises people most, and Privette calls it the highest-leverage starting point. By proactively addressing customer security concerns, a new security hire immediately takes pressure off the sales team. They create standardized questionnaire response documents — artifacts that exist and can be reused — which streamlines deals and makes the security org visibly useful to revenue generation. At most large companies, security is too far removed to ever see whether a deal closes or stalls; at a startup, that feedback loop is immediate and powerful.
2. Make security work visible. Security work that nobody knows about earns no organizational trust. Privette emphasizes creating documentation, policies, and artifacts that can be left behind and referenced by others. Beyond the practical value, these artifacts signal to the executive team that the new security leader is in control of the program — even when the program is still nascent.
3. Use compliance as a security tool. The conventional wisdom that "compliance is not security" is true — but irrelevant at an early-stage startup. "When you're at an early-stage startup, there is no difference. They are one and the same, so stop treating them as separate things." Compliance frameworks provide external mandate, pre-prioritized control sets, and executive-intelligible rationale for security investments. PCI, SOC 2, HIPAA — each is a vehicle for getting security work done that would otherwise compete poorly against feature development.
4. Make clear decisions. This one, Privette says, is undervalued to an extreme. Decisions do not need to be perfect. They need to exist. Deciding that incident response SLA for a contractual obligation will be 24 hours rather than six, then defending that position with customers, is an act of organizational leadership. Responding consistently to inbound "beg bounty" pseudo-reports is an act of organizational leadership. Every clear decision a first security hire makes adds to the cumulative perception that someone is steering the ship.
5. Build a scalable roadmap. With compliance integrated into the roadmap as both a driver and a communication tool, the security leader can explain prioritization decisions in terms the rest of the business understands. When PCI tightens requirements, that goes on the roadmap with an explanation. This approach works within whatever resources exist — it does not assume headcount or budget that isn't there — and it develops the diplomatic capital needed to eventually pursue deeper, more interesting security work.
Security Is Diplomacy, Not Defense
One of Privette's most quotable frames is his assertion that security at a startup is more about diplomacy than defense. He means this literally. The security leader is trying to borrow time from engineering teams who have sprint commitments, convince executives to trade off product velocity for risk reduction, and persuade a sales team to include them in deal cycles without becoming a bottleneck.
▶ Watch: Diplomacy, influence, and the scalable roadmap (22:01)
The technical depth requirement cuts both ways: a first security hire must be able to discuss vulnerability specifics with developers and translate the same risk into business impact for the C-suite, often in the same day. Privette calls this "balancing technical depth" — one of the core skills that separates candidates who succeed in the role from those who don't.
The Q&A reinforces this theme. Asked how to expand the security team and justify the headcount, Privette ties the answer directly to business outcomes: frame security hires as enabling developer productivity, accelerating deals, or providing a competitive edge. Asked whether startup politics are better or worse than corporate politics, he notes that while corporate politics are about influence within large bureaucracies, startup politics reduce to managing personalities and translating security posture for board members — a much smaller surface area with much faster feedback loops.
Notable Quotes
"Trust engineering is a way to position yourself as a business leader first and a security leader second." — ▶ 12:00
"If you're the first security hire, you're not building a security program. You are building a business function that did not exist, that just so happens to do security." — ▶ 24:01
"Security is more about diplomacy than it is defense, and especially true in early-stage startups." — ▶ 22:01
Key Takeaways
- Lead with business, follow with security. The startup's survival and revenue generation capacity are prerequisites for everything else. Frame every security initiative in terms of how it enables the business.
- Align with sales first. Streamlining security questionnaires and reducing deal friction generates visible, measurable goodwill faster than almost any other activity.
- Never waste a compliance framework. Use certifications and regulatory requirements as vehicles to get real security work prioritized, funded, and executed — even when "compliance is not security."
- Make decisions, even imperfect ones. Organizational trust accumulates through consistent, clear decision-making. Indecision signals the opposite of leadership.
- Close the expectations gap quickly. The mismatch between what you were hired to do and what the company thinks you were hired to do is your primary obstacle. Identify it, name it, and bridge it early.
Reviews
Dr. Zero (Offensive Security Researcher) — ACCEPTABLE
Privette knows his lane and works it well. The trust engineering framing — security leader as business diplomat first, technical practitioner second — is pragmatic advice for first security hires who keep getting fired for doing their jobs too well. Doesn't pretend to be more than it is.
Heather Calloway (CISO) — WEAK
Privette's trust engineering framework is a useful corrective for first security hires who arrive with an enterprise mental model, and the expectations-gap insight is real. The governance and impact dimensions are minimal — this is an organizational effectiveness talk for individual practitioners, not a talk about the security risks that matter at scale.