Talent.com
ndax canada
Fractional vCISO (Financial Services/Crypto experience)ndax canada • Calgary, AB, CA
Search for other jobs
Fractional vCISO (Financial Services/Crypto experience)

Fractional vCISO (Financial Services/Crypto experience)

ndax canada • Calgary, AB, CA
5 hours ago
Job type
  • Part-time
  • Quick Apply
Job description

Ndax is a Canadian cryptocurrency trading platform headquartered in Calgary, Alberta. We are registered with the Canadian Investment Regulatory Organization (CIRO) as an investment dealer and operate as a marketplace. We're looking for an experienced Fractional Chief Information Security Officer (vCISO) to lead our information security program on a part-time basis.

You'll own our security program end to end and lead our internal security team. You'll work directly with the CEO and leadership to set security direction, meet our regulatory obligations, and protect our platform, our clients, and the digital assets we hold in custody.

This role suits a security leader who already serves other clients and wants to make a real impact in a regulated fintech and digital asset environment.

Key responsibilities:

Leadership and strategy

  • Lead, manage, and mentor our internal security team
  • Own our information security strategy and multi-year roadmap
  • Assess our current security posture and identify gaps, risks, and priorities
  • Report security risks, metrics, and program progress to executives and the board

Governance, risk, and compliance

  • Build and maintain security policies, standards, procedures, and controls
  • Keep us compliant with Canadian securities, AML, and privacy requirements, including CIRO, the CSA, FINTRAC, PIPEDA, and Alberta's PIPA
  • Lead audit readiness for SOC 2, ISO 27001, or similar frameworks, and act as the security point of contact for auditors and regulators
  • Oversee vendor and third-party risk, including custodians, cloud providers, and key technology partners

Platform and digital asset security

  • Set security standards for custody, wallet infrastructure, and cryptographic key management
  • Guide cloud, application, and identity and access security across our trading platform
  • Oversee vulnerability management, penetration testing, and threat monitoring

Resilience and culture

  • Develop, test, and maintain incident response and business continuity plans
  • Lead the response to security incidents, including regulatory notifications where required
  • Drive security awareness and training across the company

Requirements

Required

  • 10+ years in information security, including at least 5 years in a CISO, vCISO, or head of security role
  • Experience leading security programs at a regulated financial services, fintech, or digital asset company
  • Working knowledge of Canadian regulatory expectations for registered dealers and money services businesses (CIRO, CSA, FINTRAC) and Canadian privacy law
  • Hands-on experience taking an organization through SOC 2 or ISO 27001 audits
  • Track record of building incident response programs and leading real incidents
  • Experience managing and developing security staff
  • Clear communicator who can brief a board as comfortably as an engineering team

Nice to have

  • Experience securing cryptocurrency custody, hot and cold wallet operations, or HSM and MPC key management
  • Familiarity with NIST CSF, CIS Controls, or CCSS (Cryptocurrency Security Standard)
  • Background in cloud security (AWS or Azure) and securing trading or payments platforms
  • Certifications such as CISSP, CISM, CISA, or CCSK

Engagement details

  • Fractional, part-time independent contractor engagement
  • Hours tracked and invoiced monthly
  • Reachable for urgent security incidents outside regular hours, as agreed in the contract
  • Expected to sign a confidentiality agreement and pass a background check before starting
Create a job alert for this search

Fractional vCISO (Financial Services/Crypto experience) • Calgary, AB, CA