Terravek's application security function is small. That changes what a good hire looks like in ways that generic security hiring advice does not capture.

The first thing: breadth beats depth at our size. A specialist in one class of vulnerability is enormously valuable in a team of thirty. In a team of three, the person who can threat model a new service on Monday, review a dependency policy on Tuesday and triage an inbound disclosure report on Wednesday is worth more.

The second: the ability to be wrong in public. Most of the job is telling engineers that something they built has a problem, and being told back — sometimes correctly — that you have misunderstood the system. People who cannot update in front of an audience become people that engineers route around.

The third, and the one I weight most heavily: whether they can explain a finding to the person who has to fix it. A perfectly correct report that lands as an accusation gets fixed slowly and resented permanently.

What I do not weight much: certifications, and the ability to recite the OWASP Top 10 in order. I have both and neither has ever helped.

We have a Tier 2 SOC analyst role and an appsec role open in Tallinn and Delft respectively.