This company is possessed of the rare and wonderful opportunity to take feedback to heart and show that they do indeed understand the importance of security. They can do that by doing something different from the security-team-in-one-person JDs that we security specialists see a dozen times a month. They all want netadmin, cloud admin, compliance, policy, governance, patching, software architecture, and IR in a single engineer's role, authority, and paycheck. Fortunately, a company with four years of runway can afford to take a better approach!
Thank you for bringing optimism and hope to HN. It's often in short supply. That's to be applauded.
The 4 years runway feels like a lie to me. Certainly they mean, if we don't grow and don't hire. Startups should be running out of money as fast as they can, not slowly eroding. I am not faulting them for that statement though. It is what it is. A well versed candidate will understand that.
I do believe that a single person can fill the role, at this stage of a company. That person is obviously (?) going to outsource some of the work, not handle it directly. Their job is to see that the task is done, not necessarily to do it.
Did your friend's startup did make it to an exit? Or to the next round of financing even?
If you got the level of skills this position wants... you'll have plenty of places to go.