I've also run tech for a 60 person startup, run security for a 300 person company, and worked closely with security & compliance at a 6000 person company.
What I will say is there is a lot of waste and overhead in the tech security industry overall. You can pay a vendor any amount of money you can afford, and they will add some incremental value via automated scanning, pentests, compliance reporting, but the value has no correlation to the money spent unless you have no baseline security awareness to begin with, and if you don't have that then no amount of money will save you (eg. Equifax breach).
IMHO the right way to do it is: make sure your tech and infra leadership have baseline understanding and do the fundamentals right (eg. use bcrypt, put your infra in VPCs with private subnet and bastion only access, use IAMs with least privilege, etc). The incremental cost of those things is negligible if you know what you are doing, so make sure you have at least one person on the early-stage team who knows what they're doing. Next step up (if you are consumer app) do a bug bounty and minimal scanners (prioritize infra scans). Eventually you'll need more, but it should be a function of success where you have hundreds of engineers, are making tons of money, or have specific compliance requirements as a result of lucrative enterprise sales.