OXYGENOXYGEN

For security startups

GTM infrastructure for cybersecurity startups

Security buyers get pitched daily and are trained to distrust the pitch. What earns a reply is showing you know who owns the problem there.

try

Security tooling sells against a deadline. An enterprise customer demands a questionnaire, an auditor names a control, an incident lands close enough to notice. Before one of those happens, nobody is buying, however good the product is.

Job postings are the earliest legible version of that deadline. A company opening a security role, or naming a framework inside an engineering ad, has decided to spend. The posting attaches to the account, and the stack columns beside it say what they are defending.

Who this is for
Seed to Series A security software companies: application security, identity, cloud posture, detection, or governance. Four to fifty people, with a founder still closing deals.
What it looks like today
Below a thousand employees there is usually no CISO, so a title filter returns almost nothing. Meanwhile every prospect gets a dozen security emails a day, most of them opening with a vague threat.
What changes
You target the moment a company starts taking security seriously: a first security hire, an auditor requirement, a footprint that outgrew the team. The accountable person is whoever the evidence points at.

Example searches

Ask for it the way you'd say it

Every search below runs on the same hosted Tables, with the cost previewed before anything is spent.

  • The first security hire

    which companies between 50 and 500 people opened a security role in the last sixty days

    The posting sits on the account with its date, so you can work the window while the budget is still open.

  • Stack that fits your product

    show me companies with a cloud heavy stack and no security vendor detected on the site

    Detected technology arrives as separate columns, so an absence is visible rather than buried inside a score.

  • Who is actually accountable

    find the person responsible for security at each company, even if their title says engineering

    Where no security title exists, the table names the engineering or platform leader it found instead.

Plays

Three motions you can run this week

Each one is a chain of Oxygen primitives — the same hosted objects your workspace already has, composed.

  • Buy-window targeting

    Accounts caught in the weeks after they decided to spend on security.

    1. 1Track security and compliance roles across your size band into a table.
    2. 2Promote the accounts inside the window and drop the ones that hired months ago.
    oxygen signals search run
  • Name the owner, not the title

    One accountable contact per account, even where no security team exists.

    1. 1Ask for the role that owns the decision and verify the address that comes back.
    2. 2Enroll a short cadence and let a reply anywhere stop the rest of it.
    oxygen sequences draft
  • A message that does not open with fear

    A first line about their stack and their hiring, not a vague threat.

    1. 1Write your positioning and proof into the workspace wiki so drafts read one source.
    2. 2Generate a line per account from the posting and the stack, then review a sample.
    oxygen knowledge page upsert

Capabilities

What you get

  • Targeting without a CISO filter

    Hiring and stack evidence pick out accounts that are buying, which matters because most companies you sell to have nobody carrying that title.

  • Absence as a filter

    A technology column that comes back empty is usable: you can build a list of accounts where nothing in your category was detected at all.

  • Proof that stays on the record

    Every cell keeps the run, the provider, and the source behind it, so a claim you make in an email traces back to something you can show.

  • Free to build, metered to research

    Tables, Records, workflows, and sequence drafts are unmetered. Sourcing postings, research columns, and contact lookups draw credits, each previewed before it runs, and dispatching from a domain you own needs a plan.

Instead of

The stack this replaces

Native, on one contract and one credit balance — not another tab wired to the last one.

  • Clay
  • Apollo
  • Smartlead
  • HubSpot
  • Zapier
  • LeadIQ

Data sources

What the data actually comes from

Every value lands with its provider and cost recorded on the cell.

  • TheirStack

    Security and compliance roles inside job postings, the earliest public sign that a budget exists.

  • BuiltWith

    Technology detected on a domain, including what is already installed in and around your category.

  • PredictLeads

    Company events such as funding and hiring bursts, which put a posting spike into context.

  • Blitz API

    Resolves the engineering or security owner at accounts with no dedicated security team.

Run these on Oxygen's managed credits, or connect your own provider keys and pay the vendor directly — the same columns, the same runs, the same provenance either way. See every integration.

Limits

Where this stops

  • Security tooling is mostly invisible from outside. There is no agent to detect, usually no console on the public site, and nothing in the marketing copy, so treat an empty detection column as unknown rather than as an account with no vendor.
  • Posting language is inconsistent across companies. One firm advertises an application security engineer, another folds the same work into a platform role, so read the description before you rank an account on its title.
  • An absent security role is not evidence of no budget, and nothing here touches a prospect's infrastructure. Every source is public, and implying you probed their network is how a security buyer blocks you for good.

FAQ

Questions people ask first

Most of our targets have no CISO. Who do we write to?
Whoever the evidence names, usually a VP of engineering, a platform lead, or a technical co-founder. The lookup asks for the owner of the decision and the table records the title it resolved.
Is any of this data taken from our prospects' systems?
No. Every source is public: job postings, public pages, company records. There is no scanning and no probing, and nothing a prospect's team would read as an unsolicited test.
How do we not sound like the other twelve emails?
Stop leading with risk. The evidence that selected the account, a role they opened or a tool they run, is more specific than any threat line and already sits on the row when the draft is written.
Can we run this alongside our existing CRM?
Yes. Two way sync keeps accounts and contacts aligned while the outbound state stays here, where runs and costs are visible. Nothing has to be migrated before you start.
What about companies in the middle of a compliance push?
Those surface through hiring and posting language rather than a tidy field. A role naming an audit framework is a stronger buying signal than any firmographic filter you could set.
Do we need an engineer to set this up?
No. The web app and the Copilot cover the whole motion, with the terminal there if you prefer to script it. The plumbing a specialist normally wires together is already hosted here.

Put your GTM motion on one stack

Sign up, get a working workspace with a one-time credit grant, and run the first play end to end without wiring five tools together.