HireACISO

Your first security hire, or not a hire

Below about 80 people the first security hire is the wrong purchase: what you are short of is decisions, not hands. When it is right, the role to hire is a security engineer, not a leader.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A Canadian startup under about 80 people should not make a security hire yet. An engineer costs $140,000 to $210,000 CAD loaded, and what companies of that size are short of is decisions, not hands. When a hire is right, hire a security engineer who builds things, keep the accountability with a founder, and buy the senior judgement fractionally. Hiring a leader first is the expensive mistake: they arrive with nobody to lead.

$140k to $210k First security engineer, loaded, CAD

$275k to $540k Full-time CISO, first year, loaded, CAD

4 to 7 months Time to fill a senior security role in Canada

Are you short of hands or short of decisions?

Answer it by writing down the last ten pieces of security work your company did or failed to do.

If the list is mostly implementation that nobody had time for, such as access reviews, log configuration, hardening and evidence collection, you are short of hands and a hire is a real option. If the list is mostly questions nobody could answer, such as which framework to target, whether a contract clause is acceptable, or what to tell a customer, you are short of decisions and hiring a mid-level engineer will not help. Most founders of 20 to 60 person companies are in the second case and buy the first solution.

Which role should the first hire be?

Candidate first security roles at a Canadian company, CAD, loaded cost
RoleLoaded costRight whenWrong when
Security engineer, mid-level $140,000 to $210,000 There is a backlog of implementation work and someone to direct it Nobody has decided what should be built
Security engineer, senior $165,000 to $235,000 You need someone who can both decide and build, which is rare and worth paying for The market at this level is thin and the search runs long
Compliance or GRC analyst $100,000 to $155,000 You have committed to a first audit and the load is evidence and coordination There is no framework program running, in which case there is no job
Security manager $155,000 to $230,000 There are already two or three security people to manage There are none, which is the situation you are in
Full-time CISO $275,000 to $540,000 first year A regulator or a large customer contract requires a dedicated officer Almost always, under 200 people

The third row is the most commonly mistimed hire. A compliance analyst is useful and cheap relative to the alternatives, and the job only exists once there is an audit to feed. Hire one before committing to a framework and their work product is a spreadsheet nobody asked for. What each title is allowed to decide is on CISO versus vCISO versus security manager, and the senior salary picture is on CISO salary in Canada.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Hiring against buying it fractionally

First security hire against fractional leadership, first year in CAD
DimensionSecurity engineer hireFractional leadership
First year cost$140,000 to $210,000$36,000 to $144,000 depending on hours
Time to productiveThree to six months including the searchDays to weeks
What you getImplementation capacity, present dailyDecisions, ownership and customer-facing accountability
What you do not getSeniority to accept risk, or credibility with a buyer's reviewerHands. Nothing gets built by the retainer
Risk if it goes wrongA termination, a severance and six months lostA notice period, usually 30 days
Scales downNoYes, and it should after the first quarter
Best combined answer under 80 staffEngineer only if there is a build backlogAdvisory hours or a small retainer for the decisions

The fourth row decides it for most companies. A retainer builds nothing, and a mid-level engineer decides nothing. The companies that get this right buy a small amount of senior judgement and give the implementation work to engineers they already have, the arrangement on supporting an engineering lead who is already doing security. The full cost comparison, including benefits and recruiting, is on fractional CISO cost.

Before you post the job

  1. Write down the ten things this person will do in their first quarter. If you cannot fill ten lines, the job does not exist yet. If eight of them are decisions rather than work, you want fractional help instead.
  2. Decide who they report to, and write down what they can decide alone. A security hire reporting into engineering, with no authority to say no, will spend a year being outvoted and then leave.
  3. Set the budget they control. A security person with no spending authority has to escalate every tool and every test, which consumes the seniority you hired.
  4. Check the market before you fix the salary. Canadian security salaries are compressed at the middle and thin at the senior end, and a role posted below band will sit open for months while the work does not get done.
  5. Plan the first ninety days. Hire into a company with no written security position and the first month is discovery you could have done yourselves for far less. An assessment at $5,000 to $15,000 CAD before the hire makes the hire land better.
  6. Decide what happens to the internal owner. The founder or engineer who has been carrying this needs to know what they keep. Handing the whole thing over on day one is how companies lose the context.

A Canadian hiring note

The senior security market in Canada is small, concentrated in Toronto, Montreal, Vancouver, Calgary and Ottawa, and competing with American employers paying US dollars for remote work. That is why a senior search runs four to seven months. The person you hire has options, so retention starts the day they accept, not at their first review.

When hiring is clearly the right answer

Four situations, narrower than the enthusiasm for building a team suggests. You have a committed audit with a date and a large evidence load, which makes a compliance analyst the cheapest way through. You have an implementation backlog engineering will never get to, and someone senior enough to direct it. A customer contract or a regulator requires a dedicated internal officer. Or there are already security people working under a fractional leader, which is the moment that arrangement should convert. Moving from a vCISO to a full-time CISO covers that transition without losing the program.

Hire, or buy the hours

Tell us the ten things you want this person to do in their first quarter. We will tell you whether that is a job description or a retainer, and what each one costs in CAD.

Get matched

Common questions

Can we hire a junior and grow them into the role?

For implementation work, yes, and it is often a good idea because the market at that level is deeper and the person tends to stay. For the decisions, no. A junior cannot arbitrate between shipping and securing with a VP of engineering, and putting them in that position is unfair to them. Pair a junior or mid-level hire with a small amount of senior fractional judgement and the arrangement works well.

What does a first security engineer actually do in year one?

Identity and access work, cloud configuration hardening, logging and alerting, dependency and vulnerability triage, and the technical half of customer security reviews. That is a full year of real work at most companies of 50 to 150 people. It is not a full year of work in a small team of 25, which is why the hire lands badly there and the person leaves inside eighteen months.

Should our first security person be a contractor?

For a defined build with an end date, a contractor is often better and faster, and a fixed-scope project at $15,000 to $60,000 CAD buys a deliverable with an acceptance test. For ongoing operational work a contractor is expensive relative to an employee and the context walks out at the end. Match the shape of the engagement to whether the work ends, which is the argument on engagement models.

How do we interview for security when nobody here is a security person?

Bring in one experienced person for the technical interview, for a few hours at $200 to $400 CAD an hour. It is the cheapest insurance available on a $180,000 CAD commitment. Ask candidates to talk through a real decision they made and were later proved wrong about, because the answer separates people who have owned something from people who have advised on it.

What if we just cannot afford anyone?

Then assign the accountability internally, protect the time, and do the free work, which is most of what matters under 50 people. That is a defensible position and it answers the majority of a customer security review. The list is on security with no budget, and what the arrangement costs you in absorbed hours is on 30 people and no security person.