Reference: GILA/ID/TECH-W/2603 Board seat: Independent Woman Director, Non-Executive Location of board meetings: Bengaluru, with one meeting per year at an overseas delivery centre Term: Five consecutive years, eligible for one re-appointment Status: Live, with a defined vacancy date approximately eight months out. Search is being run early by design.
Anonymised client snapshot
A listed Indian technology company operating at the intersection of product engineering services and proprietary enterprise software.
- Revenue in the USD 250–450 million range, growing in the low-to-mid teens, with a stated ambition to cross the half-billion mark within the plan horizon.
- Approximately 60–70% of revenue from North America, with Europe as the second market and a deliberate, sub-scale India domestic presence.
- Delivery footprint across Bengaluru and Hyderabad, with nearshore centres in Eastern Europe and a small Latin American presence added in the last three years.
- Founder-led and founder-chaired, with the founding team retaining a significant but non-majority holding; institutional investors, including two long-only foreign funds, hold meaningful stakes.
- Comfortably within the top 500 listed entities by market capitalisation, and therefore squarely within Regulation 17(1)(a).
- A proprietary software line — currently under 20% of revenue but the primary driver of multiple expansion — carrying its own ARR, net revenue retention and R&D capitalisation questions.
- Two acquisitions completed in the last 36 months, one of which is still being integrated.
Why this seat, and why now
The incumbent Independent Woman Director completes her second consecutive five-year term in approximately eight months. Under Section 149(11), she is not eligible for immediate re-appointment and must serve a three-year cooling-off period. She is not available for re-appointment in any event.
The company has chosen to run this search eight months ahead rather than in the final quarter, for three reasons that candidates should understand:
- It permits a genuine overlap and handover — the incoming director will be invited to attend two board and two committee cycles as an observer prior to formal appointment, at the board's invitation and without vote.
- It avoids the Regulation 25(6) scramble. Filling an independent director vacancy within three months is achievable; filling it well in three months rarely is.
- The outgoing director chairs a committee, and the board wishes to sequence that chairmanship transition properly rather than parachute a new appointee into the chair.
This is a mandatory woman director appointment. The company must maintain at least one independent woman director on the board under Regulation 17(1)(a) as applicable to the top 1,000 listed entities. There is no second woman independent director on the board, so this seat carries the full statutory obligation. The mandate is unambiguous and the search is being run exclusively for women candidates.
Where this seat sits
Board of ten: founder-chairman, one executive director, two nominee directors and six independent directors. Post-transition, this appointee will be the sole independent woman director — a composition the board has separately committed to improve at the next available seat.
Committee expectations:
- Risk Management Committee — Chair, taking over the chairmanship from the outgoing director after a two-cycle overlap. Under Regulation 21 the committee's remit includes cybersecurity explicitly, and this is where the seat carries the most weight.
- Audit Committee — Member. Section 177 financial literacy applies.
- NRC — Member, with particular focus on the ESOP pool, dilution management and the compensation architecture of a founder-led company approaching a scale transition.
- Attendance at the Stakeholders Relationship Committee as required.
Charter of the role — first twelve months
- Rebuild the cyber risk conversation at board level. Most listed Indian technology boards receive a cybersecurity update that is a slide of green ticks. The Risk Committee Chair is expected to require: a mapped view of crown-jewel assets, third-party and sub-processor risk in the delivery chain, incident history with root-cause and mean-time-to-detect, tabletop exercise outcomes involving the executive team, and an honest read on the gap between the SOC 2 / ISO 27001 attested position and the operational reality.
- Own regulatory readiness under the Digital Personal Data Protection Act, 2023. Data fiduciary obligations, consent architecture, the significant data fiduciary determination, breach notification mechanics, and — most materially for a company with a majority North American client base — how DPDP obligations interact with client contractual commitments under GDPR, US state privacy statutes and sector-specific regimes. The board needs a director who can tell it whether the DPO function is real or nominal.
- CERT-In directions. Verify that the six-hour incident reporting obligation can actually be met operationally, that log retention requirements are satisfied, and that the escalation path reaches a board member and not just the CISO.
- AI governance. The company is embedding AI capability into both its services delivery and its product line. The board requires a position on: model and data provenance in client engagements, IP and indemnity exposure where AI-generated code enters client deliverables, client contractual restrictions on AI usage, EU AI Act exposure for European clients, and internal usage policy. This is currently the single largest unaddressed governance gap on the board's own assessment.
- Interrogate the software line's accounting. R&D capitalisation policy under Ind AS 38, revenue recognition under Ind AS 115 for multi-element arrangements, the ARR definition being reported to the market, and net revenue retention methodology. Where a services company reports a software metric, the definition must be stable and auditable.
- Acquisition integration and impairment. Goodwill and intangibles carried from the two acquisitions, earn-out obligations, retention of acquired leadership, and whether the impairment testing assumptions still hold.
- ESOP and dilution. Pool size, grant velocity, vesting cliffs against attrition experience, and the trajectory of dilution over the plan horizon.
Statutory eligibility — hard gates
- Woman candidate — this is a statutory requirement of the mandate under Regulation 17(1)(a), not a preference.
- Full compliance with Section 149(6), tested against the listed entity, all subsidiaries including foreign subsidiaries, associates, and the promoter group.
- IICA Independent Directors Databank registration with proficiency test cleared or a documented exemption.
- No Section 164 disqualification; DIN active with current KYC.
- Within Section 165 and Regulation 17A ceilings; within Regulation 26 committee limits — noting that taking a chairmanship here consumes one of the five available.
- No SEBI debarment, no pending adjudication, and clean under the SEBI (Prohibition of Insider Trading) Regulations, 2015 — candidates will be brought into the designated persons list and structured digital database from appointment.
- Appointment will be by special resolution under Regulation 25(2A).
Professional profile
Essential
- Senior operating or governance career in technology. Credible profiles include: former CIO, CTO, CISO or Chief Digital Officer of a large enterprise; former CEO/COO of a technology services or product business; senior technology risk or assurance partner; or a technology-sector policy or regulatory leader.
- Substantive, current cybersecurity and data-protection fluency. Not conceptual familiarity — the ability to challenge a CISO's assertions and know when the answer is evasive.
- Experience of a cross-border operating model — offshore delivery, data localisation constraints, transfer pricing exposure, or multi-jurisdiction privacy compliance.
- Board or board-committee experience, whether at a listed company, a large unlisted company, or a substantial institution.
Strongly preferred
- Prior chairing of a risk or technology committee.
- Experience of a founder-led company through a professionalisation transition, and the specific governance dynamics that entails.
- Understanding of how long-only institutional investors and proxy advisory firms assess Indian technology governance — particularly on founder compensation, promoter pledges and board independence quality.
- Direct engagement with AI governance frameworks in an operating rather than advisory capacity.
On the eight-month lead time
Candidates currently in an executive role with a notice or cooling-off consideration, or those completing a term elsewhere, are specifically encouraged. The timeline is designed to accommodate a considered transition.
Conflict screens
Board, advisory or consulting positions with competing technology services or product companies; equity or advisory relationships with the company's material clients or with its acquisition targets; positions with the company's statutory auditors, internal auditors or principal technology vendors; and any relationship with the two institutional shareholders that would compromise independence.
Time commitment
Board: 5–6 per year plus one strategy offsite. Risk Management Committee: 4–5 per year as chair, with additional time between meetings on cyber incident briefings. Audit Committee: 5–6. NRC: 3–4. Separate meeting of Independent Directors: 1. Annual board evaluation participation under Section 178(2) and Regulation 17(10). One overseas delivery centre visit annually.
Plus the pre-appointment observer cycles during the transition window.
Realistic total: 22–26 days per annum.
Remuneration and terms
Sitting fees at the statutory ceiling under Rule 4; annual commission under Section 197(1) approved by members, with a committee-chair differential; D&O liability cover as mandated under Regulation 25(10) for the top 1,000 listed entities; travel including international travel at company policy. No stock options, per Section 149(9).
Process
Longlist → SYMPHONY™ assessment with a technology-risk module → structured technical interaction with the CISO and CTO (candidate assessing them as much as the reverse) → reference triangulation → NRC interaction → interaction with the outgoing Independent Director → Board interview → independence verification → NRC recommendation → Board approval → special resolution.