Skip to content

Repository files navigation

Hiring Your First Security Person

When to hire versus vCISO versus MSSP, the job description that attracts operators instead of unicorn hunters, interview questions that detect substance, and how to keep them past year one.

The first security hire is the most mis-scoped job in the industry. Companies write a CISO posting for an analyst budget, demand ten years of everything, interview with trivia, and then wonder why the role has turned over twice. Meanwhile the actual job, a pragmatic generalist who makes the whole program run, goes undescribed because nobody has written it down honestly.

This is it written down honestly.


The Decision Before the Decision

Hiring is one of three answers, and picking wrong wastes a year:

Need Answer
Strategy, priorities, board credibility, a few days a month A vCISO
Eyes on alerts around the clock An MSSP or MDR service
Somebody who owns security every day, builds it into how the company works The hire

Most companies at the hiring threshold actually need a blend, a full-time doer plus fractional leadership plus outsourced monitoring, and the honest math on that lives in when-to-hire.md.

Security Is a Team Sport, and your first hire is not the team, they are the player-coach who gets everyone else playing. More in PRINCIPLES.md.


Who It's For

  • Founders, CTOs, and IT directors making the first dedicated security hire
  • HR partners who got handed "hire us a security person" with no further detail
  • vCISOs helping a client graduate to a full-timer, the handoff chapter's companion
  • Candidates who want to see the honest version of the role before taking one

Who It's Not For

Enterprises building out a mature team under an existing CISO. Different hiring problem.

Anybody staffing a SOC. That is volume hiring with its own playbook.


The Honest Job

Your first security person is a generalist operator: identity and access, endpoint hygiene, vendor questionnaires in both directions, awareness that people do not resent, incident coordination, and translating risk into sentences executives act on. They will not be, and should not be, a malware reverser, a pentester, and a compliance attorney fused into one salary, and every posting that asks for that fusion selects for people who exaggerate.

File What it is
when-to-hire.md The signals it's time, the three options priced honestly
the-job-description.md A JD template that attracts the right people and repels unicorns
interview-questions.md Substance detection, with what good answers sound like
what-to-pay.md How to benchmark honestly, and why underpaying this role costs a breach
their-first-90-days.md Setting them up so year one works, and they stay for year two

What This Isn't

Not legal or HR advice, employment law is yours and counsel's. Not salary data, numbers rot, so the pay page teaches benchmarking instead. Not a certification guide, and the posting that leads with cert requirements has already told candidates what kind of program it runs.

Nothing here comes from a client engagement.


Contributing

Want: what your first security hire actually did all day, postings that worked, interview questions that separated talkers from operators, retention stories.

Nothing person-identifiable. See CONTRIBUTING.md.


License

CC BY 4.0. Use it, adapt it, hand it to HR. Just say where you got it.

© 2026 Harrison Ward


Me

Cyber risk and technology exec. Hired, managed, and placed security people across two decades as a CTO and consultant, and sat on the candidate side enough to know which postings are lying.

github.com/HarrisonWard · LinkedIn


Published under these principles. Security Shouldn't Be Paywalled.

About

When to hire your first security person, what the job really is, what to ask, what to pay. Anti-unicorn by design.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors