Skip to content

Open nowPosted 7 hours ago

Fractional vCISO (Financial Services/Crypto experience)

Workable (global search)107,801 open roles

Where
Calgary, AB, Canada
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowFractional vCISO (Financial Services/Crypto experience)Workable (global search) · Calgary, AB, Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 2 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.1%30 days
This job: posted 7 hours ago

Workable (global search) median: 2 days open

The posting

Ndax is a Canadian cryptocurrency trading platform headquartered in Calgary, Alberta. We are registered with the Canadian Investment Regulatory Organization (CIRO) as an investment dealer and operate as a marketplace. We're looking for an experienced Fractional Chief Information Security Officer (vCISO) to lead our information security program on a part-time basis.

You'll own our security program end to end and lead our internal security team. You'll work directly with the CEO and leadership to set security direction, meet our regulatory obligations, and protect our platform, our clients, and the digital assets we hold in custody.

This role suits a security leader who already serves other clients and wants to make a real impact in a regulated fintech and digital asset environment.

Key responsibilities:

Leadership and strategy

  • Lead, manage, and mentor our internal security team
  • Own our information security strategy and multi-year roadmap
  • Assess our current security posture and identify gaps, risks, and priorities
  • Report security risks, metrics, and program progress to executives and the board

Governance, risk, and compliance

  • Build and maintain security policies, standards, procedures, and controls
  • Keep us compliant with Canadian securities, AML, and privacy requirements, including CIRO, the CSA, FINTRAC, PIPEDA, and Alberta's PIPA
  • Lead audit readiness for SOC 2, ISO 27001, or similar frameworks, and act as the security point of contact for auditors and regulators
  • Oversee vendor and third-party risk, including custodians, cloud providers, and key technology partners

Platform and digital asset security

  • Set security standards for custody, wallet infrastructure, and cryptographic key management
  • Guide cloud, application, and identity and access security across our trading platform
  • Oversee vulnerability management, penetration testing, and threat monitoring

Resilience and culture

  • Develop, test, and maintain incident response and business continuity plans
  • Lead the response to security incidents, including regulatory notifications where required
  • Drive security awareness and training across the company

Requirements

Required

  • 10+ years in information security, including at least 5 years in a CISO, vCISO, or head of security role
  • Experience leading security programs at a regulated financial services, fintech, or digital asset company
  • Working knowledge of Canadian regulatory expectations for registered dealers and money services businesses (CIRO, CSA, FINTRAC) and Canadian privacy law
  • Hands-on experience taking an organization through SOC 2 or ISO 27001 audits
  • Track record of building incident response programs and leading real incidents
  • Experience managing and developing security staff
  • Clear communicator who can brief a board as comfortably as an engineering team

Nice to have

  • Experience securing cryptocurrency custody, hot and cold wallet operations, or HSM and MPC key management
  • Familiarity with NIST CSF, CIS Controls, or CCSS (Cryptocurrency Security Standard)
  • Background in cloud security (AWS or Azure) and securing trading or payments platforms
  • Certifications such as CISSP, CISM, CISA, or CCSK

Engagement details

  • Fractional, part-time independent contractor engagement
  • Hours tracked and invoiced monthly
  • Reachable for urgent security incidents outside regular hours, as agreed in the contract
  • Expected to sign a confidentiality agreement and pass a background check before starting
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.