OXYGENOXYGEN

Find security owners

Find security leaders by compliance scope and stack

A named CISO usually means a customer asked for one. Until that happens the work sits on a CTO, a head of infrastructure, or a very tired platform engineer.

try

Security leadership is created by pressure, not by headcount. An enterprise deal that arrives with a questionnaire, an audit a customer demanded, or one bad week are what put a named person in the seat. Before that the work is spread across engineering and nobody owns the budget line.

The pressure leaves traces you can read from outside. A company hiring security engineers, or running the kind of cloud estate an audit attaches to, has just crossed that line. Postings give you the timing, domain detection gives you the estate being defended, and the person lookup runs last, on the accounts that cleared both.

Example searches

Ask for it the way you'd say it

Every search below runs on the same hosted Tables, with the cost previewed before anything is spent.

  • The first security hire

    which saas companies posted a security engineer role in the last two months

    The posting date is the trigger, not the posting itself, so the row carries both and you decide how wide the window should be.

  • Defending a named estate

    find security leads at saas companies whose sites show a cloud and container stack

    Each detected technology lands as its own column, so the estate you would be defending sits on the row before you write a line.

  • Whoever actually owns it

    if there is no ciso give me the engineering leader who carries security

    The fallback is recorded on the row with the real title, so nobody in your sequence gets addressed as a security chief they never were.

Plays

Three motions you can run this week

Each one is a chain of Oxygen primitives — the same hosted objects your workspace already has, composed.

  • Arrive with the first security hire

    You reach the new owner while the tooling decisions are still open.

    1. 1Bind a hiring search for security roles across the market segment you sell to.
    2. 2Enroll the accounts where a posting appeared, opening on the role rather than the product.
    oxygen signals search run
  • Scope the estate before writing

    A first message that names the infrastructure they defend, not a generic security pitch.

    1. 1Detect cloud and infrastructure on each domain and keep the findings as columns.
    2. 2Resolve the security owner, promote the confirmed ones, and enroll by estate type.
    oxygen companies enrich run
  • Escalate from the engineering side

    Accounts with no security title still get a real conversation with the person carrying it.

    1. 1Keep the engineering leader on accounts where no security title resolved.
    2. 2Write to them about the questionnaire they are about to receive, not about a product.
    oxygen tables query

Who you can reach

Roles you can find at CISOs and security leaders

Reachability is per channel: a role marked for mobile is one the phone waterfall usually resolves, not a guarantee for every record.

RoleSeniorityReachable by
Chief Information Security OfficerC-levelWork emailLinkedIn
VP of SecurityVPWork emailLinkedIn
Head of SecurityDirectorWork emailLinkedIn
Security Engineering ManagerManagerWork emailLinkedIn
Governance and compliance leadManagerWork email
Head of Infrastructure carrying securityDirectorWork emailLinkedIn

Filters you can search on

  • Open security roles posted recently
  • Cloud and infrastructure detected on the domain
  • Engineering headcount behind the security function
  • Headcount band and funding stage
  • Industry and regulatory exposure
  • Country and office locations
  • Seniority: C-level, VP, or Director

Security people keep a low profile on purpose, which makes this the hardest role on the list to resolve. Expect a named leader at companies past a few hundred people and an engineering leader everywhere else. Work email plus a public profile is the practical route here; direct numbers rarely are.

Data sources

What the data actually comes from

Every value lands with its provider and cost recorded on the cell.

  • TheirStack

    Security and infrastructure postings, which date the moment a company decided to staff the function.

  • BuiltWith

    Cloud and infrastructure technology visible on the domain, used to describe what is being defended.

  • People Data Labs

    Person and company records for locating a security owner or the engineering leader above them.

  • LinkedIn Scraper

    Cookieless public profile reads, which for this audience is often the only source available.

  • Blitz API

    First attempt at a security owner's work address, and the LinkedIn company read; both return less here than on any other page.

Run these on Oxygen's managed credits, or connect your own provider keys and pay the vendor directly — the same columns, the same runs, the same provenance either way. See every integration.

Limits

Where this stops

  • This group publishes less about itself than any other. A blank row often means a private profile rather than an absent function, so keep the account and reach the engineering side instead.
  • Detection shows the estate, not the posture. Knowing which cloud a company runs says nothing about who holds the security budget, which stays a person question you still have to answer.

FAQ

Questions people ask first

Why is a security leader so hard to find?
Because the job rewards being invisible. Many keep restricted profiles and no public address, so the resolution rate for this function is genuinely lower than for sales or marketing and you should plan around it.
What do I do when there is no security title?
Route to the engineering leader who carries the work. At most companies under a few hundred people that is the honest answer, and the row records which title it actually returned.
Does a security hire mean there is budget?
It means someone approved headcount, which is the strongest public proxy available. Tooling budget usually follows within a quarter or two, so the posting is a timing signal rather than a purchase order.
Can I filter on the audits a company holds?
Not from the sources behind this page. Job postings, detected infrastructure, and person records say nothing about an audit, and there is no public registry to read against. Treat compliance as the thing you ask about in the conversation, and use something dated, a posting or an infrastructure change, as the reason to start it.
Which channel works for this audience?
A short, specific work email, plus a public profile as the fallback. Broad multichannel pressure works worse here than anywhere else, because the whole function is trained to distrust unsolicited contact.
How do I keep this from becoming a cold blast?
Gate enrollment on something dated: a new posting, a change in the detected infrastructure, a security title appearing where none existed. If nothing on the account moved recently, the row stays in the table and waits rather than entering a cadence.

Build your cisos and security leaders list

Start with a search, preview the cost before anything is spent, and keep the rows, sources, and runs in a workspace you own.