For security startups
GTM infrastructure for cybersecurity startups
Security buyers get pitched daily and are trained to distrust the pitch. What earns a reply is showing you know who owns the problem there.
Security tooling sells against a deadline. An enterprise customer demands a questionnaire, an auditor names a control, an incident lands close enough to notice. Before one of those happens, nobody is buying, however good the product is.
Job postings are the earliest legible version of that deadline. A company opening a security role, or naming a framework inside an engineering ad, has decided to spend. The posting attaches to the account, and the stack columns beside it say what they are defending.
- Who this is for
- Seed to Series A security software companies: application security, identity, cloud posture, detection, or governance. Four to fifty people, with a founder still closing deals.
- What it looks like today
- Below a thousand employees there is usually no CISO, so a title filter returns almost nothing. Meanwhile every prospect gets a dozen security emails a day, most of them opening with a vague threat.
- What changes
- You target the moment a company starts taking security seriously: a first security hire, an auditor requirement, a footprint that outgrew the team. The accountable person is whoever the evidence points at.
Example searches
Ask for it the way you'd say it
Every search below runs on the same hosted Tables, with the cost previewed before anything is spent.
The first security hire
which companies between 50 and 500 people opened a security role in the last sixty days
The posting sits on the account with its date, so you can work the window while the budget is still open.
Stack that fits your product
show me companies with a cloud heavy stack and no security vendor detected on the site
Detected technology arrives as separate columns, so an absence is visible rather than buried inside a score.
Who is actually accountable
find the person responsible for security at each company, even if their title says engineering
Where no security title exists, the table names the engineering or platform leader it found instead.
Plays
Three motions you can run this week
Each one is a chain of Oxygen primitives — the same hosted objects your workspace already has, composed.
Buy-window targeting
Accounts caught in the weeks after they decided to spend on security.
- 1Track security and compliance roles across your size band into a table.
- 2Promote the accounts inside the window and drop the ones that hired months ago.
oxygen signals search runName the owner, not the title
One accountable contact per account, even where no security team exists.
- 1Ask for the role that owns the decision and verify the address that comes back.
- 2Enroll a short cadence and let a reply anywhere stop the rest of it.
oxygen sequences draftA message that does not open with fear
A first line about their stack and their hiring, not a vague threat.
- 1Write your positioning and proof into the workspace wiki so drafts read one source.
- 2Generate a line per account from the posting and the stack, then review a sample.
oxygen knowledge page upsert
Capabilities
What you get
Targeting without a CISO filter
Hiring and stack evidence pick out accounts that are buying, which matters because most companies you sell to have nobody carrying that title.
Absence as a filter
A technology column that comes back empty is usable: you can build a list of accounts where nothing in your category was detected at all.
Proof that stays on the record
Every cell keeps the run, the provider, and the source behind it, so a claim you make in an email traces back to something you can show.
Free to build, metered to research
Tables, Records, workflows, and sequence drafts are unmetered. Sourcing postings, research columns, and contact lookups draw credits, each previewed before it runs, and dispatching from a domain you own needs a plan.
Instead of
The stack this replaces
Native, on one contract and one credit balance — not another tab wired to the last one.
- Clay
- Apollo
- Smartlead
- HubSpot
- Zapier
- LeadIQ
Data sources
What the data actually comes from
Every value lands with its provider and cost recorded on the cell.

TheirStack
Security and compliance roles inside job postings, the earliest public sign that a budget exists.

BuiltWith
Technology detected on a domain, including what is already installed in and around your category.
PredictLeads
Company events such as funding and hiring bursts, which put a posting spike into context.

Blitz API
Resolves the engineering or security owner at accounts with no dedicated security team.
Run these on Oxygen's managed credits, or connect your own provider keys and pay the vendor directly — the same columns, the same runs, the same provenance either way. See every integration.
Limits
Where this stops
- Security tooling is mostly invisible from outside. There is no agent to detect, usually no console on the public site, and nothing in the marketing copy, so treat an empty detection column as unknown rather than as an account with no vendor.
- Posting language is inconsistent across companies. One firm advertises an application security engineer, another folds the same work into a platform role, so read the description before you rank an account on its title.
- An absent security role is not evidence of no budget, and nothing here touches a prospect's infrastructure. Every source is public, and implying you probed their network is how a security buyer blocks you for good.
FAQ
Questions people ask first
Most of our targets have no CISO. Who do we write to?
Is any of this data taken from our prospects' systems?
How do we not sound like the other twelve emails?
Can we run this alongside our existing CRM?
What about companies in the middle of a compliance push?
Do we need an engineer to set this up?
Put your GTM motion on one stack
Sign up, get a working workspace with a one-time credit grant, and run the first play end to end without wiring five tools together.