How to Run a LinkedIn Outreach Campaign for AI Security Leaders at Growth Companies (2026 Edition)
Step-by-step LinkedIn sequence and messaging to sell to AI security leaders at growth companies in 2026. Use Origami's built-in sequencer to find, enrich, sequence, and track all in one platform.
GTM @ Origami
Quick Answer: You already built a list of AI security leaders at growth companies using Origami's AI-powered lead generation. Now it's time to turn that list into conversations. Origami has a built-in LinkedIn sequencer — included on all paid plans — so you can send a 3‑touch connection‑to‑meeting campaign without exporting a single CSV. Below, you'll find the exact segmentation steps, a copy‑paste‑ready outreach sequence tailored to AI security buyers at scale‑ups, and how to launch and track everything from one dashboard.
Before You Sequence: Qualify and Segment Your AI Security List
Even though Origami already delivers verified names, emails, phone numbers, and enriched company details, not every contact on your list is ready for the same outreach. You ran a prompt like:
"Give me AI security leaders (CISO, VP Security, Head of AI Trust) at growth-stage companies in North America that use Kubernetes in production and raised a Series A or B in the last 18 months."
Origami returned a tight list with titles, company headcount, funding data, and even technology‑stack signals. Now, before you feed the whole list into the sequencer, spend 15 minutes refining.
1. Remove the obvious misfits. Look at the title field and the company description. Some “AI security” leaders might be IT generalists at an AI startup, not owning the AI security roadmap. Focus on titles that include AI/ML Security, Product Security (AI), Trust & Safety, CISO, VP of Security Engineering, or roles where the words AI, ML, or Trust appear next to Security. If a contact is a SOC manager overseeing classic incident response but nothing in AI, archive them — you can always add them to a separate awareness campaign later.
2. Segment by growth stage and pain point. Inside Origami, create two segments: Early Growth (Series A, 50‑200 employees, likely scaling fast, security often a 1‑person show or a small team) and Mid Growth (Series B/C, 200‑1000 employees, formal security team, compliance pressures creeping in). The messaging for each segment will differ slightly:
- Early Growth cares most about speed, preventing catastrophic AI incidents that kill the runway, and getting a security foundation without slowing product velocity.
- Mid Growth is dealing with enterprise RFPs, SOC2/ISO 42001 preparation, board questions about adversarial robustness, and securing multiple AI pipelines across different teams.
3. Add a priority flag. In the enriched data Origami provides, check tools like LangSmith, Weights & Biases, or Hugging Face. If a company uses these, they’re almost certainly deploying AI in production — not just experimenting. Mark those contacts as high priority. They’ll feel the pain of model extraction attacks or data poisoning tomorrow, not next year.
You’ll end up with two sub‑lists: one for Early Growth, one for Mid Growth, each with a clear priority cluster. That’s enough to launch a campaign that feels personal instead of spray‑and‑pray.
The LinkedIn Sequence: Exact 3‑Touch Format for AI Security Leaders
You can take two paths inside Origami:
- Paste your own templates. Write the 3‑touch sequence below (or tweak it), paste the messages directly into Origami's sequencer, set your delays (Day 1, Day 3, Day 7 — adjust to your rhythm), and hit launch.
- Let the agent write it. Ask Origami's AI agent to generate a personalized 3‑day LinkedIn sequence for all leads automatically. The agent uses each lead’s enriched profile data — title, company, industry, tech stack — so every message feels custom, not a mail merge.
The sequence below assumes you’re pitching a solution that helps secure AI/ML systems, whether that’s adversarial testing, LLM guardrails, model monitoring, or governance. Steal the structure, but make sure the hook reflects the actual problem you solve.
Touch 1: Connection Request + Note (Day 1)
Subject line (connection note): quick thought on AI security at your scale
Message: Hi , I’ve been following ’s work on AI‑driven . One thing I hear from AI security leads at growth companies: the second you move from prototype to production, the threat surface explodes — adversarial prompts, data poisoning, model inversion — but building an AI security program from scratch without slowing sprint cycles is brutal. I’m working on a way to make that practical at Series A/B stage. Would be great to connect and swap notes.
Why it works: It recognizes their reality (growth company, fast cadence, limited security staffing) and teases a solution without pitching. The “swap notes” framing signals you’re not there to sell yet.
Touch 2: Follow‑up (Day 3)
Subject line: one common AI security gap I keep seeing
Message: , thanks for connecting. Quick thought — a lot of security teams at growth companies focus on data classification and traditional appsec, but miss that their ML pipeline introduces new risks: training data quality, model serialization attacks, or proprietary algorithm leakage through inference APIs. When I talk to CISOs at AI‑first companies, they often say the biggest surprise was that none of their existing tooling caught these until after a close call. Happy to share a 2‑page checklist we put together on the top 5 AI‑specific attack vectors — no pitch, just a sanity check for your roadmap. If you’d like a copy, let me know.
Why it works: Gives concrete value (a checklist) while reframing the problem in terms they might not have considered. The follow‑up doesn’t just say “bumping,” it adds new insight. It also qualifies them — if they ask for the checklist, they’re actively thinking about AI security.
Touch 3: Final Message (Day 7)
Subject line: AI security — when do you typically evaluate tools?
Message: , I’ll keep this short since I know your inbox is chaos. If securing AI/ML workloads is on your radar for the next couple quarters, I’d love to understand what matters most to right now — whether it’s getting ahead of a board‑level AI risk question, prepping for a due diligence review, or just making sure your next model deploy doesn’t introduce a vulnerability. No rush — but if there’s a 15‑minute window in the coming weeks, I’ll come prepared with benchmarks from other AI‑native growth companies.
Why it works: Low pressure, framed around their timeline and real triggers (board questions, due diligence, vulnerability prevention). The specific mention of “benchmarks from other AI‑native growth companies” gives social proof without any “our customers include…” blathering.
Note on delays: Cadence can be adjusted. For Early Growth segments, a tighter 1‑3‑5 day might work because the urgency is higher. For Mid Growth, 1‑3‑7 is safe. Origami's sequencer lets you set per‑sequence delays, so you can even clone the sequence and have two versions.
Launch, Send, and Track Directly from Origami
This is where most outreach workflows fall apart: you build a beautiful list in one tool, export it to a CSV, clean it, upload it to a LinkedIn automation tool, set up sequences in a third place, and pray the sync doesn’t break. Origami cuts that chain.
The same platform where you described your ideal customer and got an enriched lead list now lets you send the LinkedIn sequence you just wrote — without leaving the dashboard.
- Attach the sequence. In the prospects view, select the refined list (or specific segments), click “Launch Sequence,” and either paste your 3‑touch templates or let the AI agent generate them. Set your touch delays.
- Hit launch. Origami's built‑in LinkedIn sequencer sends connection requests and follow‑up messages automatically. You don’t need to export anything or juggle multiple browser extensions.
- Monitor in real time. The same dashboard shows opens, clicks, and replies. Even better, while looking at a contact’s activity, you still see their enriched profile — title, company, tools used, industry — so you instantly know why you reached out and can tailor your manual reply when they respond.
- Auto‑un‑enrollment. If someone replies, they automatically exit the sequence. No risk of sending a “just circling back” after a booked meeting. This keeps your reputation intact and your mind at ease.
The sequencer is included on all paid plans; you only pay for the credits used to enrich your leads. The sending itself is free. If you’re on the free plan (1,000 credits, no credit card), you can enrich a handful of leads and try the sequencer on a small batch before upgrading.
What Results to Expect (and When to Tweak)
For a well‑refined list of AI security leaders at growth companies—assuming your messaging is relevant and your targeting is tight—expect a connection acceptance rate of 35–50%. Of those who connect, a properly timed sequence with a value‑first angle should generate a 12–18% reply rate, with about one‑third of those replies being positive (a meeting or a request for more info).
Red flags that it’s the list, not the messaging:
- Connection acceptance under 25% → your ICP is too broad, or your headline/tagline isn’t resonating. Refine the prompt you used in Origami and rebuild a tighter sub‑segment (e.g., only those with “AI Security” in title, or only Series A/B).
- Many “Accepted” but zero replies after two touches → your industry hook is off. Go back to LinkedIn, look at the posts these leaders engage with, and adjust the pain point you lead with. Are they talking more about model supply chain security than adversarial robustness? Mirror that language.
Green flags to double down:
- High connection rate and a few replies that directly ask for the checklist or mention a specific trigger (board meeting, due diligence) → clone the sequence for the other segment and increase volume.
- Someone replies with a “not now, but maybe next quarter” → create a separate nurture sequence in Origami with lighter touchpoints (a quarterly insight email, an invite to a private roundtable). You can track all of this from the same prospect record.
The power move? Use the reply data to refine your prompt for the next batch of leads. If you notice that AI security leaders at Series A companies running Kubernetes and using LangSmith respond twice as well, you can tell Origami's AI agent: “Find more prospects like that.” The system constantly learns from what works.