Rotate Your Device

This site doesn't support landscape mode. Please rotate your phone to portrait.

How to Run an Email Campaign Targeting AI Security Leaders at Growth Companies (2026)

Step-by-step guide to running cold email campaigns for AI security leaders. Includes a full 3-touch sequence, subject lines, and how to send everything natively in Origami's sequencer.

Finn Mallery
Finn MalleryUpdated 10 min read

Founder @ Origami

Quick Answer: Origami isn't just a list-building tool — it has a built-in email sequencer that lets you find, enrich, sequence, and send outreach to AI security leaders at growth companies from a single platform. This guide shows you the exact workflow: refine your prospect list, plug in a 3-touch cold email sequence (with full copy you can steal), and launch directly inside Origami. No exporting CSVs, no syncing with another tool.

You already read how to build a list of AI Security Leaders at Growth Companies. Now you have a clean, verified list of names, emails, titles, and company details — all generated by a single prompt inside Origami. But a list sitting in a spreadsheet doesn’t book meetings. This post picks up where that one ended. I’ll walk you through the one-hour workflow that turns that list into replies and pipeline, using nothing but the platform you already have.


Step 1: Build the List (If You Haven’t Already)

If you skipped the parent guide, here’s the 30-second version. Inside Origami, you tell the AI agent exactly what you want in plain English. For AI security leaders at growth companies, a prompt like this works every time:

“Find VP-level or Head of AI Security at US-based B2B SaaS companies with 50–500 employees that raised Series A or B funding in the last 18 months. Include only verified business email addresses and direct dials.”

Origami searches the live web, chains together data sources, enriches each contact, and qualifies them. Within minutes you get a list with:

  • Full name, job title, and department
  • Verified email and phone number
  • Company name, size, funding stage, HQ location
  • Tech stack signals (e.g., uses AWS SageMaker, Hugging Face, Wiz, or CrowdStrike)

You can run this on the free plan — 1,000 credits, no credit card required — so there’s zero risk to test it. Now, whether you’re starting fresh or using the list from the parent guide, move to the next step.


Step 2: Refine and Qualify the List

Not every lead on the raw list deserves a spot in your sequence. Spending 15 minutes on segmentation here will double your reply rate. Inside Origami, you can filter, tag, or delete contacts right from the same interface.

What a Qualified AI Security Leader Looks Like

For this audience, qualified means:

  • Title signals genuine AI security ownership: VP of Security, Head of AI Safety, CISO, Director of ML Security, sometimes a Lead Security Engineer at smaller teams.
  • Company has real AI exposure: They ship AI features, train models, or use open-source LLMs. Origami often surfaces technology signals — look for mentions of LangChain, LlamaIndex, OpenAI API, or internal ML platforms.
  • Growth stage, not enterprise: 50–500 employees, Series A to C funding. Lean teams that move fast and feel security debt creeping in. They’re past the “we’ll deal with it later” phase and before a massive security bureaucracy.

How to Segment

Create three tiers:

  1. Hot (immediate first touch): AI security title, company raised funds in the last 12 months, and Origami’s enrichment found a direct dial. These are priority leads.
  2. Warm (second wave): Slightly broader titles (e.g., VP of Engineering) at AI-native companies, or a CISO with no explicit AI mention but at a company with public ML job postings.
  3. Cold (nurture only): Head of InfoSec at slower-moving verticals, or companies with stale signals. Save these for a lighter touch later.

Don’t overcomplicate this. Just add a custom tag in Origami (“hot-ai-sec”, “warm-ai-sec”) so you can launch targeted sequences to each tier later. I usually send the first sequence only to the hot tier, then expand if it works.


Step 3: Create the Email Sequence

Here’s where most campaigns fall apart. Generic cold emails to AI security leaders get ignored — these people are drowning in vendor pitches. Your messages need to reference their specific pain points: model poisoning, adversarial robustness, compliance with the EU AI Act, or simply the fear of their next board meeting.

Origami gives you two paths for this, both inside the platform:

  1. Paste your own templates: You write the sequence yourself, drop the templates into Origami’s sequencer, set the delays (Day 1, Day 3, Day 7), and hit send.
  2. Let the agent write it: You can ask Origami’s AI agent to generate a personalized 3-touch sequence for all your leads automatically. The agent uses each lead’s profile data — title, company size, industry, tech stack — so every message feels custom, even at scale.

If you choose the second path, you can still review and tweak the messages before sending. For this guide, I’ll give you a battle-tested template sequence that I’ve used to open conversations with AI security folks at growth companies. Use it as your starting point, then let the agent personalize if you want.


Full 3-Touch Sequence for AI Security Leaders

Message 1 — Cold Reach (Day 1)

Subject: AI security at — quick thought

Preview text: Not a pitch, just an observation

Body:

Hi ,

Heads-up: growth-stage AI teams often skip adversarial testing because it feels too slow. But I’ve noticed ’s latest release uses open-weight models — which makes poisoning and prompt injection real exposure before your SOC even sees it.

I’m not selling anything today. Would you be open to a 15-minute call next week to share how a few CTOs in your space are handling this without slowing down sprint cycles?

Best,


Message 2 — Different Angle (Day 3)

Subject: One thing most AI sec leaders ignore until it’s too late

Preview text: Board-level visibility

Body:

,

Spoke with a Series B CISO yesterday who got grilled after an incident because he couldn’t show a single artifact of AI security testing. His team had done the work, but nothing was documented for the board.

It’s not just about stopping attacks — it’s about showing the board you’re proactive. I’ve got a 3-step framework that takes 10 minutes a week and gives you the paper trail you need.

Worth a quick look?


Message 3 — Breakup (Day 7)

Subject: Closing the loop

Preview text: No hard feelings

Body:

,

Tried to reach you a couple of times. I get it — AI security isn’t something you can drop everything for.

If you ever want to bounce ideas on how fast-moving teams secure GenAI deployments without hiring a full red team, my inbox is open. No pitch, just some hard-won patterns from the field.

Thanks,


Each message is 70-90 words. No fluff, no passive voice. They reference real, specific problems that only AI security leaders face. Personalization variables like and get filled automatically by Origami from your enriched list data.

Cadence and Timing

I set delays of 2 business days between touches. Origami lets you configure this per sequence — Day 1, Day 3, Day 7 works for most B2B cold outreach. Send between 8-10 a.m. Tuesday-Thursday for best open rates on security leaders (they scan email in the morning and then vanish into meetings).


Step 4: Send the Sequence Directly from Origami

You don’t leave Origami to launch this. Once your sequence is loaded, hit “Launch Campaign” and the built-in sequencer handles everything:

  • Sends each touch on the delay schedule you set
  • Tracks opens, clicks, and replies — all visible in the same dashboard where your list lives
  • Automatically un-enrolls any lead who replies, so they never see a breakup message after booking a meeting
  • Shows prospect context while you review activity. When you see that the VP of AI Security at Acme opened three times but didn’t reply, you can click in and still see her enriched profile — title, company, tools they use. So you know exactly why you reached out in the first place. No tab-switching.

What About Integrations?

Origami’s sequencer is built in. You don’t need to export a CSV and upload it to Mailchimp, Lemlist, or a CRM. You don’t need to buy a separate email sending tool. The sequencer is included on all paid plans — you only pay for the credits used to enrich your leads. Sending is free. That’s the whole pitch: one platform from list-building to outreach. Find, enrich, sequence, send, track.


What Response Rates to Expect (And How to Improve)

For a well-segmented list of AI security leaders at growth companies, expect:

  • Open rates: 45–65%. These are verified business emails; if you’re below 40%, your subject lines need work.
  • Reply rates: 5–12% positive. This audience is selective but curious — if you reference their world correctly, they’ll engage.
  • Meeting conversion: About half of replies turn into booked calls.

If open rates are low after 200 sends, run A/B tests on subject lines inside Origami (you can clone the campaign and change only the subject). If reply rates are low, your list might be too broad — re-segment and tighten the title filter to true AI security roles. If you get tough objections about budget (growth companies always push back), handle them in a one-off reply, not by derailing the template sequence. You can also ask Origami’s agent to generate an objection-handling snippet based on the lead’s profile if you’re stuck.


Frequently Asked Questions