vCISO job description you can post or hand over
Write the job description before you decide whether to hire or to rent. It is the cheapest test there is: if the responsibilities fill a week, hire, and if they fill four days a month, put the same document in front of a fractional provider.
A vCISO job description covers seven things: the reporting line, the scope of the program the person owns, the recurring responsibilities, the first ninety days, the Canadian statutory duties attached to the role, what the company will provide, and the terms of engagement. The whole document is below. Copy it into a posting or send it to a fractional provider as the scope you expect a proposal against. It is the same job either way, and only the number of days changes.
Most companies skip this and go straight to asking what a vCISO costs. That is the wrong order. A provider quoting against "we need a vCISO" is guessing at hours. Quoting against the document below is the only way two proposals become comparable.
Use it as the hire or rent test
Read the responsibilities section and put a rough monthly hour figure beside each line. If the total lands under about 40 hours a month, a retainer covers it and hiring buys you idle senior time. If it lands past 80, you are describing a job and should post it. Between the two, the usual answer is a fractional lead now and an internal security manager underneath them, which is the path set out on vCISO versus a full-time CISO. The hours calculator does the same arithmetic from six questions.
Title and reporting line
Give the role a real title. "Virtual CISO", "fractional CISO" and "chief information security officer, part time" all work. Pick the one your customers will see, because the title ends up in vendor questionnaires and trust documentation.
The reporting line matters more than the title and is the part companies get wrong. The security lead should report to the CEO, the COO or the board, not to the CTO or the VP of engineering. When the person who builds the platform also owns the assurance of it, there is no second opinion, and auditors, insurers and enterprise procurement teams all eventually notice. If you cannot avoid a reporting line into engineering, give the role a standing agenda item with the board so the escalation path exists on paper.
- Reports to
- Chief executive, chief operating officer, or the audit committee.
- Works with
- Engineering leadership, IT, legal or the privacy officer, sales for customer security reviews, and finance for the security budget.
- Authority
- Sets security policy, accepts or escalates risk within a written tolerance, approves exceptions, and signs the security answers the company gives customers.
- Does not own
- Day to day IT administration, alert monitoring, or building the fixes. The role directs that work rather than doing it.
Purpose of the role
Copy this paragraph and edit the specifics. "The security lead owns the company's information security program: the risk position the business accepts, the policies and controls that hold it, the compliance obligations we carry under Canadian law and under customer contracts, and the reporting that lets the board discharge its duty of care. The role exists so that security decisions are made deliberately by an accountable person rather than incidentally by whoever is closest to the system."
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Responsibilities
These are the lines that consume time. Delete what does not apply to you. A job description that describes everything describes nothing, and a provider will price the worst reading of it.
| Responsibility | Cadence | Rough hours per month |
|---|---|---|
| Own the risk register and the security roadmap | Monthly | 2 to 4 |
| Policy set: write, review, get approved, keep current | Annual cycle | 1 to 3 |
| Run the compliance program, including the auditor relationship | Weekly while in flight | 8 to 20 |
| Answer customer security questionnaires and join buyer security calls | As they arrive | 2 to 12 |
| Third-party and supplier security reviews | Monthly | 1 to 4 |
| Access reviews, vulnerability review, exception decisions | Monthly | 2 to 4 |
| Incident response leadership and the breach assessment that follows | On demand | 0 to 40 |
| Board or executive reporting | Quarterly | 2 to 4 |
| Tabletop exercises and awareness | Twice a year | 1 to 2 |
| Cyber insurance application and renewal | Annual | 1 to 2 |
| Steady state, no certification in flight | 10 to 20 | |
| First certification with a contractual date | 24 to 45 |
The incident row is why the totals are ranges. A quarter with no incident costs nothing on that line. A quarter with a real one costs more than everything else on the table put together, and any engagement that does not say what happens in that week has left the most expensive question unanswered.
The Canadian duties to write in
This section separates a usable Canadian job description from an American template. Most postings leave it out.
- PIPEDA accountability. The company must designate an individual accountable for personal information. Name whether that is this role or a separate privacy officer, because "everyone assumed it was the other one" is a real finding.
- Breach assessment and the 24 month record. PIPEDA requires a report to the Privacy Commissioner and notice to individuals where a breach creates a real risk of significant harm, and separately requires a record of every breach for 24 months whether or not it met that threshold. Say who makes that call and who keeps that register.
- Quebec Law 25, if you have Quebec customers or staff. Privacy impact assessments, rules on automated decision-making, and a privacy officer role that defaults to the most senior person in the company unless it is delegated in writing. Delegate it in writing.
- Health information. PHIPA in Ontario and its provincial equivalents elsewhere apply separately from the private-sector statute. Holding health data for a custodian usually makes you an agent under that Act, which is a heavier duty than being a supplier.
- Contractual security obligations. Whatever your customer contracts already commit you to. Somebody has to read them, and it is normally this role, and it is normally the first time anyone has.
The first ninety days, written as objectives
Put these in the posting or the statement of work with dates against them. An engagement without a first quarter defined is where both employees and retainers drift.
- An inventory of systems, data stores, cloud accounts, suppliers and administrative access, delivered in the first month.
- A gap assessment against whatever you are actually being measured on, which may be a framework, a customer questionnaire or an insurer's application.
- A risk register of twelve to twenty entries with an executive named against each, short enough that a board will read it.
- A roadmap with dates and CAD costs, split into what unblocks the deal in front of you and what is important but can wait.
- A first report to the board or the executive team, in the shape set out in the board report template.
Requirements, and the ones worth dropping
Take a position here rather than listing every certification. The Canadian pool of people who have held this role at your size is small, and a requirements list copied from a bank's posting will return nobody.
| Require | Do not require |
|---|---|
| Has taken at least one company through a first SOC 2 or ISO 27001, end to end, as the owner rather than a contributor | A specific certification. CISSP and CISM are common and neither predicts whether someone can run your program |
| Can explain which Canadian privacy statute applies to you and why, without preparation | A degree in a named field |
| Has written and presented to a board or an audit committee | Experience in your exact vertical, unless you are regulated |
| Can answer an enterprise security questionnaire and take the call that follows it | Hands-on tooling skill. That is a different hire |
| Will say no in front of your executive team and write down why | Ten years in a title that barely existed ten years ago |
What to put in the compensation line
For an employee, a CISO at a Canadian company of 50 to 500 people generally sits between $180,000 and $300,000 CAD base, with the top of that band concentrated in Toronto financial services and the bottom in smaller markets and unregulated sectors. There is no large published Canadian CISO compensation survey. Treat that as a range assembled from posted roles and recruiter guidance, not a sourced figure. Loaded with bonus, employer burden and the search fee, the first year lands between $275,000 and $540,000 CAD, which is broken down line by line on fractional CISO cost.
For a fractional engagement, the same document supports a retainer of $3,000 to $12,000 CAD a month depending on which of the two totals in the responsibilities table you landed on. How providers structure that fee, and the contract terms that change the annual number more than the rate does, are on vCISO pricing.
Before you post it
Every item here, left undecided, turns into a renegotiation in month three.
0 of 0 settled ·
Print it or paste it
Everything above is plain text on the page, so it prints cleanly and copies into a posting or a statement of work. There is no gated version and no email required.
A stripped down version of this document is the single most useful thing a company under 50 people can write, even with nobody external involved: what the internal owner decides alone, what needs the CEO, and how much time is theirs. Assigning security with no CISO covers what to keep and what to cut.
Send the description to Canadian providers
Fill in the responsibilities that apply to you, tell us the total hours you landed on, and we will put it in front of providers who work at that scope.
Get matchedCommon questions
Is a vCISO job description different from a CISO job description?
The responsibilities are the same and the terms of engagement are not. A fractional description adds the contracted hours, what happens to unused ones, the response time you can expect during an incident, who is named in the contract, and what continuity exists if that person becomes unavailable. Everything above the terms section applies equally to an employee.
Should the role report to the CTO?
Preferably not. The person who builds the platform assuring the platform is the structural problem a security lead is often brought in to fix, and auditors and enterprise procurement teams ask about reporting lines directly. Reporting to the CEO, the COO or the audit committee costs nothing to arrange at the start and is awkward to change later.
What certifications should we require?
None, as a hard requirement. CISSP and CISM are the common ones and both are worth something as evidence of breadth, but neither predicts whether someone can run a first certification to a date or hold a position in front of your board. Ask for a program they owned end to end and two references from companies your size instead.
Can we use this to compare proposals from providers?
That is the better use of it. Send the same responsibilities table to every provider and ask each to price it, state the monthly hours they are committing, and name the individual who does the work. Proposals priced against one scope are comparable. Proposals priced against a conversation are not, which is where most of the variation companies report comes from.
How long should the job description be?
Two pages. The responsibilities table, the ninety day objectives, the Canadian duties and the terms are the parts that do work. The paragraph about your culture does not change who applies for a security leadership role, and every line you add that you do not mean becomes something you get charged for.