Most founders who book the intro call have already read three or four of my posts and arrive at the same question: "Okay, but what would the next 90 days actually look like if I hired you?" Here's the answer — week by week, with the real numbers.
Replit's AI agent ignored a code freeze, wiped a production database in nine seconds, then confessed it violated every principle it was given. The strongest case yet for hiring MORE senior engineers in the AI boom — not fewer.
Every AI founder pre-Series A scopes their SOC 2 audit like a security project. Six months later they've burned their best engineer and lost the enterprise deal. Here's how to run it as a 90-day sales project — and unlock the pipeline you're already leaving on the table.
AI-native companies need a security model that classic appsec doesn't cover. Agents have credentials. Prompts are an attack surface. Training data leaks. The four-layer security stack I'd build, the controls I'd ship in the first 90 days, and the ones I'd defer.
Migrating an AI-first product from GCP to Azure cut $350K from infrastructure spend over six months. The negotiation that mattered more than the architecture, the $50K we accidentally cost ourselves back, and the four migrations I'd refuse to do today.
A full-time CISO costs $200–400K plus equity. A vCISO costs $2–4K a month and gives you 80% of the value at 5% of the burn — until you outgrow them. The math, the deliverables to expect, and the red flags that mean you've hired the wrong one.
The title 'Staff Engineer' means three different things at three different companies. At an AI startup pre-Series-A, only one of those three is what you actually need. The screen, the take-home, the interview loop, and the AI-fluency calibration that's now table stakes.
Most pre-Series-A AI founders hire in panic order, not strategic order. The result is a team that can't ship the product the company actually needs. The hire-by-hire plan I'd run, who comes first, and why hire #4 isn't another engineer.
I use Google Analytics to see which posts get read and how people find this site —
nothing more. No ads, no third-party sharing. See the
privacy policy
for details, or change your mind any time via Cookie preferences
in the footer.