Design Leadership ·

Designing Security from Zero to Series D

What building a design function inside a cybersecurity startup taught me about craft, org design, and business outcomes.

When I joined, “the design team” was me and a Figma file. By Series D it was a function with its own craft bar, rituals, and a seat in how the company decided what to build. Most of what I learned in between contradicts the advice I’d have given on day one.

Good design at a startup is not great aesthetics

It’s the best solution to a real problem inside real constraints — time, headcount, technical debt, a market that won’t wait. Early on I optimized for the portfolio screenshot. The work that actually moved the company was rarely the prettiest; it was the clearest. Clarity shipped; beauty followed.

The goal of design is to make the business more money. Everything else is a means to that.

I say that plainly because hiding it behind craft-talk does designers a disservice. The teams that earn trust are the ones that connect a pixel to a number.

Hire for agency, not pixels

A strong portfolio tells you where someone has been. Agency tells you where they’ll go when you’re not in the room — which, at a startup, is most of the time. I started screening for it directly: give a candidate an ambiguous problem and watch whether they shrink or expand.

Org design is a product

The team is a system, and systems have an architecture: who owns what, where decisions happen, what the feedback loops are. When the design org felt slow, the fix was almost never “work harder” — it was a structural one. Move the decision closer to the work. Shorten the loop. Remove the meeting that was standing in for a document.

Set the bar by showing, not telling

You can’t write the craft bar into a wiki. People calibrate to what gets shipped and praised. The fastest way to raise the bar was to do one thing visibly, exceptionally well — and let it become the new floor everyone measured against.

What I’d tell day-one me

  • Tie design to outcomes out loud, early, and often.
  • Spend your scarce time on frameworks, not corrections.
  • The artifact still matters — but the team is the bigger artifact.

More on the specific org structures that worked, and the ones that didn’t, in a future post.