You Can't Hire Badasses

Wed Aug 19, 2026

You Can’t Hire Badasses

There’s a particular mistake companies make when they hire exceptional technical people, and I’ve watched it play out enough times to recognize the shape of it before it happens.

They meet the hacker. The researcher. The builder. The person who presents at conferences, tears apart systems at midnight, ships strange projects nobody asked for, and somehow knew about a class of vulnerabilities three months before it landed in anyone’s threat briefing. They watch that person for a while and think, we should hire that person. What a lot of them actually mean, whether they’d admit it or not, is that they’d like to rent the useful parts of that person between nine and five.

Those are not the same thing, and the gap between them is where good people quietly go sour.

You can’t hire a badass and expect them to be a badass only for you. You can’t recruit someone for an obsessive curiosity about technology and then get irritated when that curiosity keeps running after business hours. You can’t hire someone because they spent years building a reputation in the security community and then act surprised when their corporate title doesn’t feel more important to them than the name they built themselves. And you certainly can’t hire someone for the fire in their eyes and then spend three years trying to extinguish anything that doesn’t map cleanly onto a Jira board.

The person you hired existed before your company

The best hackers I know didn’t get good because someone handed them a quarterly objective. They got good because they couldn’t leave things alone.

They stayed up too late figuring out why something worked. They rebuilt tools because the existing ones annoyed them, wrote exploits for things nobody at work cared about, and reverse-engineered whatever hardware happened to be sitting on the desk simply because it was there. They accumulated strange radios, locks, badges, dev boards, antennas, and questionable secondhand enterprise gear, all in the name of understanding how it worked. They spent weekends at cons, argued about implementation details at two in the morning, competed in CTFs, published research, and maintained projects that paid them exactly nothing. They learned because learning was its own reward.

That is how they became the person you eventually wanted to hire. The company didn’t create that person — the community did. Curiosity did. Obsession, failure, a handful of good friends, and a decade of projects did. DEF CON did. Expecting all of it to evaporate the moment someone is issued an employee number is a fundamental misreading of what you actually hired.

The 9-to-5 hacker is mostly a corporate fantasy

There’s a comforting idea inside a lot of organizations that employment draws a neat boundary around technical talent. From nine to five you are a security engineer; at 5:01, apparently, you’re expected to lose interest in security.

In that fantasy, your conference talks drift toward approved messaging, your research conveniently aligns with whatever is on the roadmap this quarter, and your side projects stay harmless enough that Legal never has to learn they exist. Your professional network is supposed to benefit the company without ever producing an opportunity outside of it, and your public reputation should burnish the org’s credibility while never becoming more valuable than your internal title.

That arrangement would be wonderful if you were designing people from scratch. But humans don’t ship with configurable operating hours. The curiosity that makes someone exceptionally useful doesn’t punch a clock, and neither does their ambition, their community, or their sense of who they are.

Your best people may not feel like your best people at work

Here’s the uncomfortable part. Some of the most respected people in technical communities are nearly invisible inside their own organizations.

Outside the company, people know their handle. They’ve read the research, watched the talk, and use the tool. They still remember something that person published three years ago. They invite them onto podcasts, ask them to review work, message them for advice, and buy them a beer at DEF CON because something they wrote once got them unstuck.

Then Monday arrives, and that same person logs into an org where their most interesting idea has been sitting in an approval queue for six months. The research proposal got rejected for lack of an immediate business case. The training request raised eyebrows. The conference talk needed three layers of comms sign-off. The side project makes management nervous, the experimental work keeps getting deprioritized, and the performance review rewards ticket throughput above all else. The title hasn’t moved. Neither has the comp. And internally, almost nobody actually knows what they do.

Eventually someone in leadership wonders aloud why this person seems more energized talking to their hacker friends than sitting through the company town hall. It isn’t a mystery. People go where they feel understood.

Home might be a conference hallway

There’s a feeling at hacker conferences that’s genuinely hard to explain to anyone who hasn’t stood in it. You can spend eleven months of the year being the strangest person in every room, and then you walk into DEF CON and, for a few days, you’re normal.

The person next to you is reverse-engineering a badge. Someone else built a radio project far more complicated than it needed to be. Down the hallway there’s an argument about lock mechanisms, and somewhere nearby a conversation about firmware, satellites, malware, or some obscure protocol that maybe five people on earth care about — three of whom are, improbably, standing right there. Nobody asks why you sank six months into the thing you built. They ask how it works.

That distinction matters more than it looks. For a lot of technical people this is one of the only environments where their intensity isn’t something to be moderated — it’s appreciated. They don’t have to explain why they care, translate everything into executive language, or build a business case for curiosity. They’re just among their people, and that turns out to be enormously powerful. Once someone has felt that kind of belonging, no company is going to out-compete it with branded hoodies and a quarterly pizza lunch.

The community keeps its own scoreboard

Technical communities run on a different status system than companies do. Corporate environments tend to reward hierarchy; communities reward contribution.

Nobody at a con cares that you’re a Senior Principal Associate Vice President of Cyber Something. They care whether you know what you’re talking about. Can you build? Can you teach? Can you break something interesting, or explain something complicated so it finally clicks? Did you contribute, did you help someone, did you make something worth remembering?

That creates some strange asymmetries. Inside the company, a person might be “Security Analyst II.” Outside it, they might be the name hundreds of practitioners immediately associate with a specific corner of research. Given enough time, it’s not hard to guess which identity ends up mattering more to them. Companies routinely underestimate this, because an internal org chart feels enormous when you live inside it — and the outside world has never once cared about your org chart.

Appreciation is not the same as employment

A paycheck is not appreciation. It’s compensation. Both matter, but they are not the same thing, and paying someone does not automatically make them feel valued. Neither does telling them they’re valued.

People pay attention to where the resources actually go. They notice who gets promoted and whose ideas get funded, who gets the conference budget, and whether leadership genuinely understands the work or just nods along to it. They notice when someone less capable gets more authority because they’re better at internal politics. They notice when their external wins show up in the marketing but never in the promotion conversation. And they very much notice when the organization wants the credibility attached to their reputation without granting them any of the autonomy that let them build that reputation in the first place.

You don’t get to borrow someone’s badassery for the corporate website and treat that same quality as an inconvenience the rest of the week.

Side projects are not betrayal

Another common mistake: reading independent ambition as disloyalty. Someone starts an open-source project — suspicious. They start speaking at conferences — suspicious. They build a bit of a consulting brand or start collaborating with people outside the org, and suddenly the question in the room is whether they’re really engaged.

This is exactly backwards. They were almost certainly doing these things before you hired them; it’s probably part of why you hired them. The same engine that produces the external work is the one producing the expertise you benefit from internally. Trying to throttle it doesn’t manufacture loyalty — it manufactures resentment.

None of this means boundaries don’t exist. Confidential information stays confidential, employer systems stay in scope, conflicts of interest get handled properly, and ethical obligations don’t evaporate because someone has a hacker handle. But there’s an enormous difference between enforcing legitimate boundaries and claiming ownership over a person’s professional identity. Employment buys someone’s work. It doesn’t buy their entire existence.

You are competing with their own projects

Here’s a reality organizations don’t love to say out loud: sometimes the personal project is more interesting than the one you’re paying for. Sometimes a lot more interesting.

Their project might let them play with technologies you won’t approve internally for another three years. It might involve hardware, exploitation, AI, radio, malware analysis, embedded systems, or whatever rabbit hole currently has its hooks in them. Your project might involve updating seventy-two findings in a spreadsheet. Be honest about which one they’re thinking about in the shower.

That doesn’t mean they’ll drop the ball at work — professionals deliver. But there’s a difference between doing the job well and making the job the center of your identity, and those are not the same requirement. Someone can be excellent at the work while caring deeply about things far outside it. In practice, the people with the most interesting lives outside the office are usually the ones dragging the most unexpected ideas into it.

Don’t hire the hacker and then demand the employee

If you want someone predictable, hire for predictability — there’s nothing wrong with that. Plenty of important work depends on dependable people executing well-defined responsibilities extremely well.

But if you deliberately go after the eccentric researcher, the obsessive builder, the prolific speaker, the exploit developer, the tinkerer, the community figure — precisely because of what makes them unusual — then understand the bargain you’re making. You’re hiring the whole ecosystem that produced them: the curiosity and the independence, the network and the experimentation, the occasional all-consuming obsession, the side projects, the talks, the community, the identity. You don’t get to keep only the slices that convert neatly into quarterly business value. Trying to usually destroys the exact thing that made them worth hiring.

The companies that get this right win

The smartest organizations I’ve seen don’t compete with their people’s passions. They align with them.

They give researchers room to research and let engineers publish when it’s reasonable. They encourage people to speak, they sponsor experimentation, they stand up internal labs, and they hand technically ambitious people genuinely ambitious problems. They treat external contributions as professional development rather than distraction, and they understand that an employee with a respected reputation outside the walls becomes a magnet for other talented people. Most importantly, they give people real reasons to bring their curiosity back inside.

That quietly rewrites the whole relationship. Instead of stop doing interesting things outside work, the question becomes how do we make this a place where interesting things happen too? It’s a much harder question to answer. It’s also the right one.

You can’t demand loyalty you haven’t earned

Organizations sometimes talk about loyalty as if payroll creates an obligation. It doesn’t. Loyalty is reciprocal.

If someone’s community celebrates their work, funds their ideas, invites them to speak, helps them get better, and opens doors for them — while their employer treats them like interchangeable headcount — nobody should be shocked about which group gets their emotional loyalty. People remember who believed in them. They remember where they were allowed to grow, who opened the door, who actually listened, and where they got to feel like themselves.

For some people, that place is an office. For others, it’s a village at DEF CON at 1:30 in the morning, surrounded by exhausted friends arguing about something absurdly technical. A company doesn’t get to dictate which one feels like home. It only gets to decide whether it’s willing to become one of those places too.

You can’t hire badasses

That’s the paradox, and it’s worth sitting with. You can hire their time, their expertise, and their judgment. You can hire them to go solve extraordinarily hard problems. But you can’t hire the part of them that made them extraordinary in the first place. You can only build an environment where they choose to bring it with them.

And if you don’t appreciate it, someone else will — another employer, their own company, an open-source project, a conference village, or twenty friends around a table in Las Vegas building something ridiculous simply because they can. The best technical people always have somewhere else to put their energy.

So if you hire a badass, don’t spend your time figuring out how to contain them. Give them reasons to care. Give them hard problems and the autonomy to chase them. Recognize what they actually contribute. Let them belong to communities that existed before you and will keep existing after you. And understand one thing before you slide the offer letter across the table:

They were never badasses because they worked for you. You hired them because they already were.