HireACISO

Your engineering lead is doing security

This is the default arrangement at almost every company under 60 people and it fails in two specific ways: no protected time, and no independence. Both are fixable without taking anything away from the person doing it.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Your VP of engineering, CTO or lead engineer picked up security because somebody had to, and it is not going well. It fails for two reasons that have nothing to do with the person. The time is not protected, so security work loses to a release. The person building the system is also the person assuring it, so nobody independent checks the answer. Fix those two and the arrangement works up to about 60 people.

Do not let the conversation sound like a performance discussion. This is a structural problem with a job you never scoped.

Which of the two failures do you have?

They look similar from outside and the fixes are different. Most companies have both.

The time failure
Security work is listed, agreed and never finished. The access review is three quarters overdue, the questionnaire sat for two weeks, the policy set has been eighty per cent done since spring. Nobody disputes that these matter. The symptom is a backlog with no disagreement attached to it.
The independence failure
Things get done and nobody outside the engineering team has ever checked them. Risk decisions are made by the person who benefits from shipping. An auditor, an insurer or an acquirer will name this eventually, and it is invisible internally because everything appears to be working.
The experience failure, less common
The decisions being made are wrong in ways nobody in the company can see: a framework chosen badly, a contract clause accepted that should not have been, a risk accepted informally that should have gone to the CEO. This is the one that most justifies buying outside help, and the one people least often name out loud.

Signals that it has stopped working

What you observe, what it usually means, and what fixes it
ObservationUnderlying causeFix
Security items roll from sprint to sprint for a quarter Time failure Protected time on the calendar, defended by the CEO, not by the person
Customer questionnaires take three weeks to come back Time failure, plus no answer library Write the answers once, and move the administration to operations
The same person writes the control and signs that it works Independence failure Risk acceptances signed by the CEO, one external test a year
Nobody can say what was decided or when No decision log One shared file. This is fifteen minutes a week
Answers to buyers are optimistic and later corrected Pressure without authority to say no Give the owner explicit authority to answer no with a date
Decisions get deferred rather than made Experience failure Buy advisory hours against the specific decision, not a retainer
The person has said twice that they cannot keep carrying this All three, usually Believe them. This is the cheapest warning you will get

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

How to have the conversation

  1. Open by taking responsibility for the scope. In a small team nobody wrote down what this job was or how much time it gets. That is a management failure, not theirs, and saying so first changes the conversation.
  2. Ask them what they would drop. An engineer carrying an unscoped second job knows what is not getting done and has been reluctant to say it.
  3. Separate the four parts of the job. Accountability, decisions, delivery and administration do not have to sit with one person, and at this size they should not. Splitting them is what makes the job survivable.
  4. Give the administration away first. Evidence chasing, vendor lists, questionnaire logistics and date tracking are operations work and cost a fraction of engineering time. This alone recovers a third of the hours.
  5. Put a number on the time. One day a week, on the calendar, protected by their manager. Vague agreement produces the same outcome you already have.
  6. Decide what you buy, and buy it against a decision. A handful of advisory hours at $200 to $400 CAD an hour against a real pending decision beats a retainer bought to make the problem go away.

Do not hand it to them as a title

Making the engineering lead the Head of Security without changing their time, their authority or their workload ends with them leaving. A title is not a fix, and at 30 to 60 people it creates customer expectations that one overloaded person cannot meet. Read what actually separates these roles first: it is decision rights and reporting line, not seniority.

What to buy, and when it is genuinely a purchase

These work alongside an internal engineering owner, in Canadian dollars, at 20 to 80 people.

Options that support rather than replace an internal owner
OptionCost, CADSolves
Advisory hours against named decisions $200 to $400 per hour The experience failure, at the smallest possible cost
One-off assessment and roadmap $5,000 to $15,000 An independent view of what is actually weak, which the internal owner cannot produce about their own work
Operations or program support, part time internal Reallocated time The administration third of the job, which is the cheapest to move
Advisory retainer, 8 to 16 hours a month $3,000 to $6,000 per month A standing second opinion and someone to take the customer calls
Fixed-scope project with an end date $15,000 to $60,000 A specific outcome, such as clearing a blocked customer review
External test, annually $8,000 to $25,000 The independence failure, with an artifact you can show a buyer

Notice what is not on that list: hiring a security engineer. Adding hands under an overloaded lead does not fix a time or independence problem, and it adds a person to manage. Whether your first security person should be a hire at all works through that.

When the arrangement genuinely has to end

Two situations end it. A regulated or contractual requirement for a named, independent security officer, which some customers and some sectors impose regardless of your size. And scale: once there are security people to manage rather than security work to do, you have a management job. Where that line sits is on vCISO versus a full-time CISO.

Short of those, an engineering lead with protected time, an independent annual check and a few advisory hours is the right arrangement for a Canadian startup under 60 people.

Support the person you already have

Tell us who is doing security now, how much time they get, and which decisions are stuck. We will tell you whether the fix is hours, a project or a retainer.

Get matched

Common questions

Is it a conflict of interest for the CTO to own security?

It is a real independence weakness and it is the normal condition of companies under about 50 people. Manage it rather than pretending it is not there: have risk acceptances signed by the CEO rather than the CTO alone, have someone who did not build the system run the access review, and get one external test a year. Those three cost almost nothing and are what an auditor is looking for at your size.

Our engineering lead does not want to do security. Should we make them?

No. Reluctance is a legitimate answer and forcing it produces a job done badly by someone who resents it. Find out whether the reluctance is about the work or about the time, because if it is the time then splitting off the administration and protecting a day a week often changes their answer. If it is the work itself, put the accountability with a founder and buy the expertise.

How much time does this job actually need at 40 people?

Between four and twelve hours a week in steady state, with spikes to a full week during a customer security review or an audit. The spikes are the hard part, because they arrive without notice and land on someone with a delivery commitment. Budget for the average and agree in advance what gets dropped during a spike.

Will a vCISO take the job off our engineering lead?

Not the delivery. A vCISO decides what needs to happen and holds people to it, and your engineers still do the implementation work. A company that buys a retainer expecting the workload to disappear gets a good roadmap and no change, which is the most common way these engagements disappoint. Buy the decisions and the independent view, keep the delivery internal, and budget engineering time alongside the retainer.

What if we cannot afford either the time or the retainer?

Then do the free work, which is most of what matters at this size, and accept that some deals will be slow. The ordered list is on security with no budget. What you should not do is leave the job nominally assigned to somebody with no time, because that produces the appearance of ownership and none of the substance, and the appearance is what gets you in trouble with a customer.