When to hire versus vCISO versus MSSP, the job description that attracts operators instead of unicorn hunters, interview questions that detect substance, and how to keep them past year one.
The first security hire is the most mis-scoped job in the industry. Companies write a CISO posting for an analyst budget, demand ten years of everything, interview with trivia, and then wonder why the role has turned over twice. Meanwhile the actual job, a pragmatic generalist who makes the whole program run, goes undescribed because nobody has written it down honestly.
This is it written down honestly.
Hiring is one of three answers, and picking wrong wastes a year:
| Need | Answer |
|---|---|
| Strategy, priorities, board credibility, a few days a month | A vCISO |
| Eyes on alerts around the clock | An MSSP or MDR service |
| Somebody who owns security every day, builds it into how the company works | The hire |
Most companies at the hiring threshold actually need a blend, a full-time doer plus fractional leadership plus outsourced monitoring, and the honest math on that lives in when-to-hire.md.
Security Is a Team Sport, and your first hire is not the team, they are the player-coach who gets everyone else playing. More in PRINCIPLES.md.
- Founders, CTOs, and IT directors making the first dedicated security hire
- HR partners who got handed "hire us a security person" with no further detail
- vCISOs helping a client graduate to a full-timer, the handoff chapter's companion
- Candidates who want to see the honest version of the role before taking one
Enterprises building out a mature team under an existing CISO. Different hiring problem.
Anybody staffing a SOC. That is volume hiring with its own playbook.
Your first security person is a generalist operator: identity and access, endpoint hygiene, vendor questionnaires in both directions, awareness that people do not resent, incident coordination, and translating risk into sentences executives act on. They will not be, and should not be, a malware reverser, a pentester, and a compliance attorney fused into one salary, and every posting that asks for that fusion selects for people who exaggerate.
| File | What it is |
|---|---|
when-to-hire.md |
The signals it's time, the three options priced honestly |
the-job-description.md |
A JD template that attracts the right people and repels unicorns |
interview-questions.md |
Substance detection, with what good answers sound like |
what-to-pay.md |
How to benchmark honestly, and why underpaying this role costs a breach |
their-first-90-days.md |
Setting them up so year one works, and they stay for year two |
Not legal or HR advice, employment law is yours and counsel's. Not salary data, numbers rot, so the pay page teaches benchmarking instead. Not a certification guide, and the posting that leads with cert requirements has already told candidates what kind of program it runs.
Nothing here comes from a client engagement.
Want: what your first security hire actually did all day, postings that worked, interview questions that separated talkers from operators, retention stories.
Nothing person-identifiable. See CONTRIBUTING.md.
CC BY 4.0. Use it, adapt it, hand it to HR. Just say where you got it.
© 2026 Harrison Ward
Cyber risk and technology exec. Hired, managed, and placed security people across two decades as a CTO and consultant, and sat on the candidate side enough to know which postings are lying.
github.com/HarrisonWard · LinkedIn
Published under these principles. Security Shouldn't Be Paywalled.