Find security owners
Find security leaders by compliance scope and stack
A named CISO usually means a customer asked for one. Until that happens the work sits on a CTO, a head of infrastructure, or a very tired platform engineer.
Security leadership is created by pressure, not by headcount. An enterprise deal that arrives with a questionnaire, an audit a customer demanded, or one bad week are what put a named person in the seat. Before that the work is spread across engineering and nobody owns the budget line.
The pressure leaves traces you can read from outside. A company hiring security engineers, or running the kind of cloud estate an audit attaches to, has just crossed that line. Postings give you the timing, domain detection gives you the estate being defended, and the person lookup runs last, on the accounts that cleared both.
Example searches
Ask for it the way you'd say it
Every search below runs on the same hosted Tables, with the cost previewed before anything is spent.
The first security hire
which saas companies posted a security engineer role in the last two months
The posting date is the trigger, not the posting itself, so the row carries both and you decide how wide the window should be.
Defending a named estate
find security leads at saas companies whose sites show a cloud and container stack
Each detected technology lands as its own column, so the estate you would be defending sits on the row before you write a line.
Whoever actually owns it
if there is no ciso give me the engineering leader who carries security
The fallback is recorded on the row with the real title, so nobody in your sequence gets addressed as a security chief they never were.
Plays
Three motions you can run this week
Each one is a chain of Oxygen primitives — the same hosted objects your workspace already has, composed.
Arrive with the first security hire
You reach the new owner while the tooling decisions are still open.
- 1Bind a hiring search for security roles across the market segment you sell to.
- 2Enroll the accounts where a posting appeared, opening on the role rather than the product.
oxygen signals search runScope the estate before writing
A first message that names the infrastructure they defend, not a generic security pitch.
- 1Detect cloud and infrastructure on each domain and keep the findings as columns.
- 2Resolve the security owner, promote the confirmed ones, and enroll by estate type.
oxygen companies enrich runEscalate from the engineering side
Accounts with no security title still get a real conversation with the person carrying it.
- 1Keep the engineering leader on accounts where no security title resolved.
- 2Write to them about the questionnaire they are about to receive, not about a product.
oxygen tables query
Who you can reach
Roles you can find at CISOs and security leaders
Reachability is per channel: a role marked for mobile is one the phone waterfall usually resolves, not a guarantee for every record.
| Role | Seniority | Reachable by |
|---|---|---|
| Chief Information Security Officer | C-level | Work emailLinkedIn |
| VP of Security | VP | Work emailLinkedIn |
| Head of Security | Director | Work emailLinkedIn |
| Security Engineering Manager | Manager | Work emailLinkedIn |
| Governance and compliance lead | Manager | Work email |
| Head of Infrastructure carrying security | Director | Work emailLinkedIn |
Filters you can search on
- Open security roles posted recently
- Cloud and infrastructure detected on the domain
- Engineering headcount behind the security function
- Headcount band and funding stage
- Industry and regulatory exposure
- Country and office locations
- Seniority: C-level, VP, or Director
Security people keep a low profile on purpose, which makes this the hardest role on the list to resolve. Expect a named leader at companies past a few hundred people and an engineering leader everywhere else. Work email plus a public profile is the practical route here; direct numbers rarely are.
Data sources
What the data actually comes from
Every value lands with its provider and cost recorded on the cell.

TheirStack
Security and infrastructure postings, which date the moment a company decided to staff the function.

BuiltWith
Cloud and infrastructure technology visible on the domain, used to describe what is being defended.

People Data Labs
Person and company records for locating a security owner or the engineering leader above them.
LinkedIn Scraper
Cookieless public profile reads, which for this audience is often the only source available.

Blitz API
First attempt at a security owner's work address, and the LinkedIn company read; both return less here than on any other page.
Run these on Oxygen's managed credits, or connect your own provider keys and pay the vendor directly — the same columns, the same runs, the same provenance either way. See every integration.
Limits
Where this stops
- This group publishes less about itself than any other. A blank row often means a private profile rather than an absent function, so keep the account and reach the engineering side instead.
- Detection shows the estate, not the posture. Knowing which cloud a company runs says nothing about who holds the security budget, which stays a person question you still have to answer.
FAQ
Questions people ask first
Why is a security leader so hard to find?
What do I do when there is no security title?
Does a security hire mean there is budget?
Can I filter on the audits a company holds?
Which channel works for this audience?
How do I keep this from becoming a cold blast?
Build your cisos and security leaders list
Start with a search, preview the cost before anything is spent, and keep the rows, sources, and runs in a workspace you own.