Developer tools

Where to find customers who are security engineers

Security engineers are easiest to sell when a CVE, a SIEM invoice, or a failed questionnaire is the villain — not when they are posting a CTF writeup. They compare SAST that developers will not open, argue about Okta MFA fatigue, and ask which vuln scanner still cannot tell a true positive from a dependency they do not ship. If you sell AppSec, identity, endpoint, SIEM, secrets, or anything that sits in a SOC 2 screenshot, find them in r/netsec, r/cybersecurity, HN, LinkedIn, Black Hat and DEF CON talks, and G2 threads on CrowdStrike, Okta, and Snyk. Ignore 'how do I get into cyber' posts. Hunt comments that name a false-positive flood, an EDR that bricked a laptop fleet, or a questionnaire that killed a deal. That is switching intent with a security budget, not a student collecting certs.

Where security engineers actually hang out

These are the rooms where security engineers ask for recommendations, compare tools, and name the competitor they want to leave. Start here before you buy ads.

  • Redditlarge, practitioner-heavy
    r/netsec

    r/netsec is where people who actually read advisories hang out. Threads that follow a CVE with 'our SAST never caught this' or 'the EDR vendor wants another agent' are buying notes. Commenters compare scanners, WAF rules, and identity vendors with enough environment detail — air-gapped, regulated, or a 40-person startup — that you can tell if you fit. Skip CTF and news-only posts. Hunt named tools plus false positives.

    Rules gotcha: Vendor blogs disguised as research get called out. Disclose affiliation. Do not drop a landing page into a CVE thread. Never ask for a demo while people are patching.

  • Redditvery large, mixed SOC and GRC
    r/cybersecurity

    This room mixes SOC analysts, GRC, and AppSec. The buying signal is operational: 'Splunk ingest is now the security budget,' 'Okta push fatigue, people approve everything,' 'Snyk is a ticket factory.' Those sentences describe a job to be replaced. Career threads are noise. Tooling and incident threads are where founders selling to this audience should live.

    Rules gotcha: The subreddit is flooded with cert questions. Filter by flair and by named vendors. Do not recruit. Disclose if you sell in the category being roasted.

  • Hacker Newsvery large, skeptical
    Hacker News security threads

    Security engineers still treat HN as the place to ask whether a SAST vendor is theater, whether to self-host the SIEM, and which identity provider just locked them out. The gold is the comment on an Okta, CrowdStrike, or CVE thread where someone names agent performance, a false-positive flood, or a questionnaire that paused a deal. 'Ask HN: what are you using for secrets in 2026?' is a buying committee that will fact-check you.

    Rules gotcha: Anything that reads like marketing gets flagged. No tracking links. Answer the vuln or identity question in the comment itself. Do not hijack a breach thread with a pitch.

  • LinkedInslower, higher ACV
    AppSec and CISO operator posts

    Once security is selling risk to a board, they spend more time on LinkedIn than Reddit. Posts about questionnaire fatigue, replacing a SIEM, or 'developers ignored 8,000 Snyk tickets' collect comments from AppSec leads who will forward a useful reply. A comment that names language support, CI minutes, or an agent that bricked macOS can become an internal evaluation.

    Rules gotcha: Skip fear-bait 'this CVE will end you' posts. Reply under operator posts that include a ticket count, a vendor, or a failed audit. Do not pitch in a hiring post.

  • YouTubeevergreen comments
    Black Hat, DEF CON, and AppSec talks

    Conference talks age; comments do not. An AppSec engineer watches a SAST comparison or a SIEM cost talk and then asks which tool the speaker actually ran after the keynote. Those commenters are researching under a questionnaire deadline more often than they will admit on a sales call. Pair with 'we left CrowdStrike' and 'Okta alternatives' videos.

    Rules gotcha: Conference channels delete obvious spam. Answer the question in the comment. Link only if someone asks for the product name. Never pitch during a live keynote chat.

  • Reviewsdecision-stage
    G2 reviews of CrowdStrike, Okta, and Snyk

    When a security engineer reviews Snyk, CrowdStrike, Okta, Splunk, or a WAF, they are usually mid-switch or warning the next buyer. Filter 2–3 star reviews and titles like security engineer or AppSec. Cons paragraphs name false-positive floods, agent performance, ingest pricing, and SSO that broke a contractor workflow. Substitutes map the comparison you should monitor on r/netsec and HN.

    Rules gotcha: Do not astroturf. Vendor replies on G2 are fine when you are named. Do not email reviewers after a 2-star about false positives — they will screenshot it on r/netsec.

  • Xreal-time, high skepticism
    Security practitioners on X

    X is where security engineers live-tweet a CVE they cannot patch, an identity outage, or a vendor blog they think is theater. Quote-tweet chains that name the tool they will rip out are the thread you want. Search live for CVSS, false positive, ingest, and the incumbent in your category. A public reply with a detection note beats a brand voice that says 'AI-powered.'

    Rules gotcha: Do not ratio someone during an incident. Do not celebrate a breach with a pitch. Cold DMs from a new security-branded account look like bots.

How security engineers talk about their problems

Search and replies land when you use their words, not your category name. These phrases show up in threads when they are close to buying or switching.

  • false-positive flood
  • SAST ticket factory
  • Splunk ingest pricing
  • Okta push fatigue
  • EDR bricked the fleet
  • questionnaire killed the deal
  • CVSS versus reachable
  • secrets in CI logs
  • agent performance tax
  • SOC 2 evidence screenshot
  • shift-left nobody asked for

What security engineers complain about — and what that means

PainHuntr classifies conversations by intent: actively asking, comparing, frustrated, discussing, or a passing mention. The quotes below are the shape of demand, not a promise that a specific post is live today.

  • Frustrated
    Snyk opened eight thousand tickets and developers marked them wontfix in a week. I do not need another dashboard. I need reachable vulns in the languages we actually ship, in CI, without a thirty-minute scan.

    r/netsec tooling threads, G2 cons on SAST platforms, and LinkedIn AppSec posts after a failed rollout.

  • Comparing
    Splunk vs 'please just let me keep the logs.' Ingest is now the security budget. We have a small SOC and a compliance calendar, not a logging platform team.

    r/cybersecurity SIEM threads, Ask HN logging posts, and YouTube comments under SIEM cost talks.

  • Actively asking
    Need identity that does not train people to tap Approve on every push. Okta is fine until MFA fatigue and the contractor offboarding mess. What are you running for a 80-person company?

    HN identity threads, LinkedIn CISO operator posts, and X after an Okta incident.

  • Discussing
    We added an EDR and now laptops hitch during compiles. Security wants coverage. Engineering wants the agent gone. Nobody owns the exception process.

    r/cybersecurity endpoint threads and slower Twitter/X conversations after a CrowdStrike-class incident.

Search queries that surface security engineers in buying mode

Paste these into Google, Reddit, or X search. They are the manual version of what PainHuntr runs when you paste a product URL.

  • site:reddit.com/r/netsec (Snyk OR Okta OR CrowdStrike OR Splunk) (false positive OR expensive OR alternative)
  • site:reddit.com/r/cybersecurity (SIEM OR SAST OR EDR) (ingest OR ticket OR switching)
  • site:news.ycombinator.com ("Ask HN") (secrets OR SAST OR Okta OR SIEM) (alternative OR expensive)
  • ("security engineer" OR AppSec) ("false positives" OR "we moved off" OR ingest) (Snyk OR Splunk OR Okta)
  • site:g2.com ("security engineer" OR AppSec) (cons) (Snyk OR CrowdStrike OR "false positive")
  • site:youtube.com (Snyk OR Splunk ingest OR Okta MFA) (alternative OR regretted OR expensive)

How to reach security engineers without getting ignored

Lead with the risk constraint they already named — reachable vulns, ingest, MFA fatigue, an agent that hitchs compiles — and answer that before your product appears. Security engineers reward people who have triaged a false-positive flood, not a brand that says 'AI-powered XDR.' A language-support matrix, a CI-minute number, or a detection note beats a fear slide. Never pitch in a live incident or a CVE thread that is still unpatched. Offer a public comparison, a silent-fail mode, or a sandbox with their language stack. If you sell ingest-based SIEM, show the bill at their GB/day. Follow up in the same thread. Do not scrape r/netsec usernames into a sequence. The fastest way to get banned is celebrating a breach with a CTA.

Frequently asked questions

Are security engineers the same buyer as startup CTOs shopping for SOC 2?

Sometimes the CTO signs and the security engineer still owns the tool. CTOs shop questionnaires and vendor consolidation. Security engineers shop false positives, agent tax, and ingest. Pitching a GRC spreadsheet into a Snyk ticket-factory thread will miss. Pitching a packet-level IDS into a SOC 2 founder thread will miss. Use both pages.

Where do security engineers complain about Snyk, Okta, and SIEMs?

r/netsec, r/cybersecurity, G2 cons, HN, and LinkedIn when the pain is political. X during identity outages. YouTube comments under Black Hat and SIEM-cost talks. Watch for false positives, ingest, and MFA fatigue as buying criteria.

Should I hang out in Discord CTF servers?

No if you are selling to people with production budgets. CTF rooms are for learning and will treat a vendor account as a joke. Public Reddit, HN, G2, and LinkedIn operator posts are where production pain is written. Pick one practitioner Slack only if your category already lives there.

How do I tell a cert-hunter from a buyer?

Look for a named scanner, a ticket count, an ingest bill, or a questionnaire that paused a deal. 'How do I get into cyber' is not a buyer. 'Eight thousand Snyk tickets and developers marked wontfix' is a buyer. PainHuntr's frustrated and comparing labels exist for that cut.

What should I paste into PainHuntr if I sell to security engineers?

Your product URL plus the incumbent they already run — Snyk, CrowdStrike, Okta, Splunk, a WAF. The engine looks for people asking for a replacement, comparing AppSec and identity, and venting about false positives or ingest. Pair that with the queries on this page if you still want to hunt by hand.

Related audiences

More in this sector

Reading 1,000 threads a month doesn't scale. PainHuntr does.

Paste your product URL. PainHuntr finds the conversations where security engineers ask, compare, and complain on Reddit, X, Hacker News, YouTube, and review sites — then helps you reply, track what worked, and do it again.

Join the waitlist to get early access and help shape the product.