I suspect this is largely dependent on the type of company and the information that they deal with as to how early a company decides to have dedicated security engineers.<p>Can you share your experiences and reasons as to when you decided to hire your first security engineer? How many employees did you have?<p>This is the initial hire that is responsible for bettering the overall security posture of the company from administration to technical.
A good security guy (not someone who just has a ton of certifications) is very expensive. If you have to ask, you don't need one. That is unless your partners or clients demand one or you screwed big previously or you're in business under threat (e.g. of Chinese government interest).