Fractional CISO & vCISO for Canadian Startups
Senior security leadership for a fraction of a full-time hire. As Head of Technical Operations at Humera I led a team of 15, built SOC 2 Type II from scratch, and owned production security across GCP, AWS, and Cloudflare. I bring that to your startup a few days a month.
The security leader you need before you can hire one.
Early-stage startups get asked hard security questions by customers, partners, and auditors long before they can justify a full-time CISO. I fill that gap. I own your security strategy, run the programs, and speak for security in the rooms where it matters.
This isn't advice from the sidelines. I do the hands-on work too: compliance, vendor reviews, cloud posture, incident readiness. And I bring in pentesting when you need it, so you get a whole security function in one engagement.
Everything the engagement covers.
A clear path from where you are to done.
Assessment
I review your current security posture, obligations, and the deals or audits driving your needs.
Roadmap
We agree on a prioritized roadmap and the cadence, typically a few days a month on a fixed retainer.
Ongoing execution
I own and run the program: compliance, vendor reviews, questionnaires, cloud posture, and incident readiness.
Reporting
You get board- and customer-ready security reporting, so security becomes a sales asset instead of a blocker.
Questions founders ask before we start.
What is a fractional CISO?
A fractional (or virtual) CISO is an experienced security leader who works with you part-time, owning strategy and execution, for a fraction of the cost of a full-time hire.
When do I need one instead of a full-time CISO?
If security work is blocking deals or audits but doesn't yet justify a $200K+ full-time hire, a fractional CISO is the right stage. I'll tell you when you've outgrown the model.
How many hours per month?
Most engagements run on a monthly retainer sized to your needs, often a few days a month, scaling up around audits, launches, or incidents.
Can you handle customer security questionnaires and due diligence?
Yes. Handling questionnaires, trust reviews, and security due diligence is one of the most common reasons startups bring me in.
Do you do the hands-on work or just advise?
Both. I own the program and do the work, compliance, cloud posture, vendor reviews, and run pentests when needed, rather than handing you a list of things to do.
Get senior security leadership without the full-time cost.
Tell me about your company and what's driving the timeline. I respond to every message personally.