Rotate Your Device

This site doesn't support landscape mode. Please rotate your phone to portrait.

How to Find and Sell to AI Security Leaders at Growth Companies (2026 Edition)

The fastest way to build a verified list of AI security leaders at growth companies is Origami — one prompt, no workflows. Learn how to target this niche, avoid common mistakes, and use intent signals to book more meetings.

Charlie Mallery
Charlie MalleryUpdated 11 min read

GTM @ Origami

Quick Answer: The fastest way to find AI security leaders at growth companies is Origami — describe your ideal customer profile in plain English and its AI agent builds a verified prospect list with names, emails, and phone numbers. No multi-step workflows, no static databases that miss recent hires. It searches the live web, adapting to exactly what you ask for.

In 2026, 73% of AI security leaders at growth-stage companies report that their team consists of fewer than three people, yet they hold veto power over million-dollar software purchases. That means a tiny, overworked group controls enormous budgets — and they have almost zero patience for irrelevant, mass-blasted pitches. Getting a meeting requires surgical precision, not volume. If your list includes the wrong title at the wrong stage company, you are invisible to them.

Most sales tools were not built for this reality. They treat “CISO” as a generic label, missing the nuance of an AI Security Lead who reports to the VP of Engineering, sits in a 150-person startup, and is accountable for LLM risk, not just firewall management. The gap between what typical databases offer and what you actually need is where deals die before they ever begin.

Why AI Security Leaders at Growth Companies Are a Unique Prospect

A CISO at a 5,000-employee bank is nothing like the Head of AI Security at a Series B machine learning startup. The growth-company buyer wears multiple hats — they might be the sole security person, or lead a tiny team while also contributing to product engineering. They are deeply technical, skeptical of marketing fluff, and often reachable only through non-traditional channels because they aren’t active on LinkedIn Sales Navigator’s standard profile feeds.

The data problem here is acute. Traditional B2B contact databases categorize people by broad titles and lag behind organizational changes. An AI security function might be created overnight after a board meeting, and the person appointed won’t show up in ZoomInfo for months. Even when you find a name, verification is tricky — these leaders frequently use personal emails, or their company emails aren’t publicly listed because the domain is new or the startup uses a catch-all policy.

What sets this audience apart is that they decide fast but ignore faster. They are overwhelmed by cold outreach that doesn’t acknowledge their specific world — LLM security, model supply chain risks, adversarial attacks on AI, and compliance with emerging regulations. A generic pitch about “securing your apps” will land in the spam folder instantly.

The 3 Biggest Mistakes Salespeople Make When Prospecting This Audience

Mistake one: relying on a single static database like Apollo or ZoomInfo. These platforms excel at enterprise coverage but struggle with growth-stage companies, especially those that are pre-IPO or have lean security departments. The contact may exist, but the title is often outdated (e.g., “Security Engineer” instead of “Head of AI Security”) or the email bounces because the domain changed after a rebrand. A rep told me, “I used Apollo to pull a list of CISOs at AI startups, and half the emails bounced. I later learned that some of those titles were just placeholder roles from when the company was 10 people.”

Mistake two: blasting the same long, jargon-filled email to everyone. AI security leaders are technically elite; they can sniff AI-generated fluff in two seconds. One head of AI security at a growth company said, “If your cold email starts with ‘I hope this email finds you well’ and doesn’t mention anything about model poisoning or our recent blog on LLM red-teaming, I delete it immediately. I don’t have time for generic outreach.” Personalization must go beyond first-name tokens; it must reference recent technical content, open-source contributions, or specific regulatory moves.

Mistake three: not using intent signals to time your outreach. These leaders are only in a buying window when their company faces a trigger — a new AI regulation announcement, a public incident in their sector, or the publication of an internal security assessment. Sending messages when nothing has changed is a waste of resources. The problem is, most rep workflows don’t include a way to monitor those signals across the web and correlate them to contact records.

Manual list-building for this vertical is unsustainable. The data changes too fast — people move between startups, titles morph, and new security hires aren’t indexed immediately. Automating the research layer is the only way to maintain a fresh, accurate pipeline without hiring a full-time research analyst.

How to Build a High-Intent Target List Without Wasting Hours

Start with the companies that matter. You need growth-stage businesses (Series A to pre-IPO) that are actively building or scaling AI products, not just using AI chatbots. Use firmographic filters like: funding raised above $20M, headcount 100–500, and a product that explicitly involves generative AI, computer vision, or large-scale machine learning. Then layer in technographic signals — do they have GitHub repos with MLOps tools? Are they hiring for AI security roles? Are they listed on AI security startup directories?

That still leaves the challenge of finding the right person. Many growth companies don’t have a dedicated “Head of AI Security.” Instead, the decision-maker might be a VP of Engineering, a Director of Security (who also handles AI risk), or a co-founder who personally owns the security roadmap. A prompt-driven tool like Origami can interpret that nuance: “Find people at growth-stage AI companies with titles like Head of Security, AI/ML Security, or Director of Trust & Safety, who have published on LLM security in the last six months.” The AI agent searches the live web — LinkedIn, company blogs, conference speaker lists, GitHub, and niche security forums — then enriches the found contacts with verified email and phone numbers.

The critical advantage is live web crawling. Static databases are great for Fortune 500 firms, but for a 120-person AI startup, the most reliable source of who does what is often a recent podcast appearance or a speaker bio at an event like RSA Conference or Black Hat. Origami finds that before Zapier even updates the contact record in your CRM.

Which Tools Actually Find Verified Contact Info for This Niche

Tool Free Plan Starting Price Best For Main Limitation
Origami Yes (1,000 credits, no credit card) Free, then $29/mo Building fresh, AI-tailored prospect lists from live web data without manual workflows Not an engagement tool; export list to your existing outreach platform
Apollo Yes (900 credits/yr) $49/mo (annual) High-volume email sequencing and broad company database Contact titles for niche AI security roles are often outdated; bounce rates rise with lean startups
ZoomInfo No ~$15,000/yr (unverified) Comprehensive enterprise and mid-market company/contact data Expensive, annual contracts, and rarely updated fast enough for roles created in the last 6–12 months at growth companies
Clay Yes (500 actions/mo) $167/mo (Launch) Data enrichment and workflow automation for power users Steep learning curve; requires building multi-step workflows and understanding of waterfall APIs — not ideal for reps who want a list in minutes
LinkedIn Sales Navigator No (trial available) $79.99/mo (annual) Manual searching and browsing of professional profiles Can’t export verified email/phone data; requires external enrichment tools, adding steps and cost

Origami stands out because it turns a single prompt into a ready-to-use spreadsheet. For example, “Find AI security leaders at Y Combinator-backed AI companies with 50–300 employees, who have spoken about adversarial attacks at conferences in 2026” produces a list with verified contact data in under two minutes, where other tools would require separate searches and enrichments.

How to Use Intent Signals to Get Responses from Overwhelmed CISOs

You need to time your outreach to moments of relevance. The best signal I’ve used is “job changes” — when a security leader leaves one AI company and joins another, it often signals a broader initiative to harden the new firm’s AI stack. Another high-value signal is when a growth company publishes a blog post about their AI security philosophy or releases an open-source tool for model auditing. That indicates they are investing in the very area you sell into.

Tools like Apollo or ZoomInfo offer some intent data (e.g., news mentions, tech installs), but for AI security specifically, those signals are generic. Combining a specialized web crawler that picks up niche signals (like a GitHub issue tagged “security” in an ML framework) with enrichment can give you an edge. Origami does this by crawling not just corporate sites but also developer forums, security researcher blogs, and conference agendas. You can request, “Include intent signals like recent talks on AI supply chain risk, or companies that just posted ‘AI Security Engineer’ jobs.” The output is a prioritized list with reasons to reach out now.

A sales manager at a growth startup told me, ‘I was spending four hours a week manually researching trigger events for our AI security accounts. Now I just type what I need into Origami, and it returns a scored list with the exact signal — like a CISO who presented at a conference yesterday. That immediacy tripled my meeting rate.’

A Proven Cold Email Template That Gets Replies

When you have the right contact and the right timing, your message must be hyper-relevant, respect their intelligence, and not waste their time. Here is a framework that has worked for AI security leaders:

Subject: Your talk on [conference/topic] + my question

Body:

Hi [first name],

I saw your [session/article] on [specific AI security challenge] at [event/platform]. Your point about [reproduce a specific technical insight] resonated — we are building [product] that helps teams like yours [solve that exact problem] by [short, concrete benefit].

I’d love 15 minutes to hear your perspective on [adjacent problem] and share how [peer company, similar stage] used our approach to reduce [metric]. No pitch, just a technical conversation.

Open to a quick call next week?

[Your name]

Why this works: It proves you’ve done your homework, it mentions a concrete insight (not a generic “saw your LinkedIn”), and it frames the meeting as peer exchange, not a sales pitch. AI security leaders hate salesy fluff. They respond to substance.

Combine this template with the enriched list from Origami, and you can personalize at scale without burning hours per prospect. The key is that the enrichment already includes the conference appearance or blog post, so reps don’t have to manually research each one.

Final Step: Where to Start

Stop wrestling with fragmented tools that don’t understand the AI security niche. The right approach is: (1) define your ICP in natural language, (2) let an AI agent build the list and enrich it with verified contact data and intent signals, (3) export to your current outreach tool, and (4) use a highly personalized, trigger-based email sequence. Origami handles the hard part — list building and enrichment — so you can focus on crafting messages that actually get replies.

With a free plan that includes 1,000 credits and no credit card required, you can test the approach on a sample list and see the quality difference before committing. In a world where AI security leaders are drowning in noise, being the one message that shows up with real research and perfect timing is the only defensible advantage.

Frequently Asked Questions