Careers at ValiDeck

ValiDeck is developing PCX — a proposed protocol and reference architecture for privacy-preserving data infrastructure. The first PCX implementation, PCX-CTR, focuses on customer transaction records and cross-merchant loyalty. We’re building the team that will turn the documented architecture into a working prototype and test its security, privacy, integration, and commercial assumptions.

The proposed PCX governance model rests on four principles: a shared data commons, reciprocal participation, an open application layer, and jurisdictional oversight. ValiDeck plans to develop the protocol and reference implementations so payment providers, merchants, technology companies, and independent developers can build services under shared privacy and access rules. Governance and participation arrangements remain part of the development work.

We’re currently collecting expressions of interest for planned engineering and specialist roles. Formal hiring will begin after Phase I funding is secured. Prospective technical cofounders and academic collaborators are also welcome to start a conversation with the founder.

Phase I: prototype and feasibility build

Phase I is planned as a 24-month program measured from its funded start. The prototype build occupies months 1 to 18. Integration engineering begins at month 12, allowing connector and software development kit (SDK) work to overlap with the build. The final six months focus on hardening, privacy and security review, partner engagement, and preparation for integration with point-of-sale (PoS) or commerce systems.

The objective in this stage is to demonstrate, with working software and reviewable evidence, that qualifying transaction records can support cross-merchant services through purpose-limited outputs. The prototype will test identity separation, protected custody of canonical records, customer-controlled keys, and role-specific access. Phase I uses controlled test data. Its intended outputs are a tested prototype, documented interfaces, an independent assessment, and an integration package for partner evaluation. Phase II live integration and commercial pilots depend on those results, further funding, and partner agreements.

The work suits engineers and specialists who want to turn a proposed architecture into systems that can be tested and audited: secure transaction workflows, protected record custody, controlled analytics, cryptographic safeguards, interoperable interfaces, and observable system behavior.

What the work offers

Phase I builds on a documented architecture and patents granted in the United States, Australia, and India covering the capture and linkage of customer transaction records. Newer PCX designs remain the subject of pending applications; the Patents page distinguishes their status. The engineering task is to test and refine the architecture and turn it into practical assets: tested reference components, documented interfaces and responsibilities, independent evidence, and partner knowledge. Engineers will investigate privacy boundaries and resolve implementation trade-offs that matter in regulated data environments.

The goal is to retain core technical leadership as PCX moves from prototype development to funded partner integration. Engineers will help shape the specification, implementation decisions, and evidence that future partners need. The resulting interfaces and reference components are intended to support independent implementations under shared privacy and access rules. This work is not the execution of a fixed blueprint. It requires independent technical judgment, disciplined experimentation, and a willingness to revise the architecture when evidence exposes a weakness.

ValiDeck invites expressions of interest from senior engineers in the Waterloo–Toronto region and University of Waterloo co-op students and new graduates. Academic researchers in trusted execution and privacy-preserving computation may propose a focused collaboration. Proposals should identify the assumption to test, the method, and the evidence to be produced. Research scope, publication, and intellectual-property arrangements would be agreed before work begins.

Prospective technical cofounders

We welcome conversations with prospective technical cofounders able to set engineering direction, challenge the architecture, recruit a team, and share responsibility for delivery. Phase I funding remains to be secured. Responsibilities, commitment, decision-making authority, and any ownership arrangement would be agreed directly with the founder. Because developing the PCX Platform is a multistage program, any technical cofounder must be prepared for sustained involvement through prototype development, partner integration, and early deployment.

Planned roles, open after funding

These roles are planned for the Phase I feasibility build and will open only after funding is secured. The engagement windows below are planning assumptions, not current vacancies or fixed start dates. Scope and timing will be confirmed against the funded delivery plan.

Core prototype build

Lead Full-Stack Engineer

18 months

Leads technical delivery of the feasibility prototype: service architecture, PoS simulation, payment-partner interfaces, pseudonymous account and record services, controlled analytics, APIs, data models, and observability. Works with privacy, security, and integration specialists to translate requirements into reusable implementation patterns, test trust boundaries, and assemble evidence for partner evaluation. Provides technical leadership through Phase I and, subject to funding, continuity into Phase II.

Backend Engineer

14 months

Implements account and device-credential registration, authorized token-service interfaces, the interface to the separately deployed protected resolver, record write paths, access controls, and APIs. Builds validation and failure-handling tests with the technical lead and documents service behavior for review. Produces stable, testable and maintainable reference code suitable for independent review and later partner integration.

Data / Privacy Engineer

11 months

Designs pseudonymized data models, aggregation rules, and controls on analytical outputs. Evaluates disclosure risk under the agreed threat model, including sparse groups and repeated queries. Produces documented privacy and utility evaluations at defined milestones.

DevOps / Cloud SRE

8 months

Responsible for secure infrastructure setup, deployment pipelines, service access controls, observability, reliability, and environment hardening for the feasibility build. Documents deployment and recovery procedures so the prototype can be reproduced and reviewed.

Integration and testing

Integration Engineer, PoS SDK and connector

9 months, from month 12

Delivers an SDK integration blueprint and a reference connector for one target PoS or commerce ecosystem, tested with representative transaction records. Documents record mapping, token and account linkage, interface requirements, failure handling, and observability. The goal is a reusable provider integration that can support multiple merchants; live activation and merchant onboarding require later commercial and integration arrangements.

QA / Integration Testing

6 months, within months 12 to 24

Builds reviewable test coverage for CTR schema conformance across representative transaction formats; token and device-credential lifecycles; unauthorized-access attempts; duplicate records and transaction updates; aggregation and suppression rules; integrity proofs and audit logs; and failures at the integration boundary. Scope is set at the start of the integration phase.

Focused specialist engagements

Security / Encryption Specialist

11 months, fractional

Reviews the cryptographic design, key separation and storage, device authorization, recovery and revocation, protected computation, integrity proofs, and token-resolution boundaries. Works with engineers to define the threat model and evidence for security claims. Planned as a fractional senior engagement or a scoped academic collaboration across an eleven-month window.

UI/UX Designer

As needed

Designs the customer, operator, and analyst flows needed to demonstrate account access, device authorization, recovery, permissions, and controlled analytics. Keeps the prototype interfaces focused on understandable choices and observable system behavior.

Independent privacy and security audit

Design stage and program close

Independent assessment of the threat model, trust boundaries, key management, data handling, attestation artifacts, and evidence supporting specified privacy and security claims. Reports findings, limitations, and required remediation for partner and investor review. Planned twice: at design stage and at program close.

The founder will lead project management, partner coordination, and R&D documentation throughout Phase I, including maintaining the technical records required for SR&ED claims. External accounting, legal, or regulatory advice will be obtained where required.

Engagement terms

Formal hiring depends on funding. The outlines below explain the intended engagement model; role-specific salary, contract, and equity terms will be provided when funded roles open. Cofounder and research conversations can begin earlier to establish mutual fit and scope.

Compensation and equity

ValiDeck expects to build a small core team of long-term employees whose compensation combines cash salary with equity participation. During the early stage, cash compensation may be below market, with the balance between cash and equity reflecting the scope of the role, the responsibility assumed, and the level of commitment. Specialists engaged for defined assignments will generally receive professional fees, with milestone bonuses where appropriate.

All employment, consulting, and equity arrangements will be documented formally once funding is in place. Equity grants will include defined vesting and other applicable conditions, and recipients should obtain independent legal and tax advice.

Location and working model

Phase I is being planned for delivery in Canada or Germany and the wider EU, depending on funding and partner arrangements. The Canadian option would be based in the Waterloo region; a European option would be aligned with the selected delivery and research partners.

We expect a small, distributed technical team. Each funded role will specify eligible work locations, the working model, and the relevant employment or contracting arrangements.

Expression of interest​

To express interest in a planned role, send a short introduction to alok.narula@valideck.com with the subject line “Phase I: Expression of Interest.” A CV is not needed at this stage. Briefly include your area of specialization, relevant systems or products you have helped build, your location, and your likely availability. Links to GitHub, LinkedIn, publications, or portfolio work are useful where available.

For a cofounder conversation or research proposal, use “Technical Cofounder” or “Research Collaboration” in the subject line and outline the contribution you would like to make.

Candidate data​

What you send is used to assess fit and respond to your interest in a planned role, a cofounder conversation, or a research collaboration. Access is limited to people involved in considering that interest. Information is retained only as long as reasonably needed for that purpose and applicable obligations.

You may request correction or deletion by emailing the address above, subject to any required retention. Please do not send government identifiers or financial information.

Scroll to Top