Confidential mandate

Banking Cyber-Fusion Decision-Authority Scale Leader

Urgent / Replacement

Banking Cyber-Fusion Decision-Authority Scale Leader mandate in Mumbai, India · Global Transaction Banking

A global bank needs a fifteen-month executive to establish decision authority within its Mumbai cyber-fusion centre for identity, cloud and payment threat containment.

The mandate

The Mumbai cyber-fusion centre assembles strong identity, cloud and payment threat narratives, yet containment decisions currently wait for separate regional commanders who receive different evidence. The bank requires unified decision authority that meets board tolerance for response time and provides coverage depth beyond two expatriate leaders.

The interim must assume command in Mumbai within fourteen days and serve for fifteen months. A permanent cyber-fusion leader search opens once two India-commanded severe-event exercises meet decision and evidence thresholds, anticipated in month eight. The appointed successor will shadow one live incident cycle, lead the final regional simulation and share command for six weeks before taking the seat.

Handover requires a single fusion operating picture across threat, identity, cloud and payment signals; severity and containment decisions with timed rights; three exercised multi-region attack paths; regulator-ready decision records; twenty-four-hour leadership coverage; and a successor accepted by regional security and operational-risk officers. All temporary delegations, dissenting risk decisions and unresolved telemetry gaps must be recorded.

The interim may declare a cyber severity, activate cross-domain command, isolate named non-customer assets, suspend privileged identities, direct forensic preservation and commit up to ₹45 crore within the approved remediation portfolio. Customer-channel shutdown, payment-network disconnection, employee discipline, regulator notification and risk acceptance beyond the delegated threshold remain with named executives. India team leaders receive defined incident decisions, not proxy approval titles.

Enterprise security strategy, replacement of the SIEM estate, ordinary fraud-case ownership, disaster recovery outside cyber events and wholesale regional reorganisation remain outside this mandate. Scope is limited to fusion decision authority, evidence, incident interfaces, specialist bench, exercises, remediation sequencing and permanent succession. The interim may identify adjacent weakness but cannot absorb it to manufacture broader control.

Why this seat is open

The failed exercise and launch executive’s departure created a time-bound leadership discontinuity under supervisory attention. Existing regional commanders helped create the fragmented escalation model and cannot independently arbitrate its redesign. An experienced banking incident executive is needed to exercise authority from Mumbai, prove the control change and leave durable local command.

What you will own

  • Reconstruct the failed simulation’s signals, decisions, waits, regional disagreements and customer consequences against the board tolerance.
  • Establish one fusion narrative linking adversary intent, identity compromise, cloud movement, payment exposure and confidence levels.
  • Allocate severity, containment, evidence-preservation, business-engagement and escalation rights through explicit financial and customer thresholds.
  • Build Mumbai incident commanders, intelligence leads and domain deputies with tested overnight and leadership-absence coverage.
  • Run multi-region exercises involving compromised administration, deceptive signals, payment abuse and incomplete business availability evidence.
  • Repair regulator evidence through timestamped hypotheses, rejected actions, containment rationale, risk ownership and after-action closure.
  • Transfer the command ledger, delegations, exercise library, talent slate and open control gaps through successor-led incidents.

Candidate qualifications

  • Commanded severe cyber incidents for a regulated global bank across identity, cloud, payments and regional business boundaries.
  • Built a cyber-fusion function in India with genuine containment decisions, not merely alert enrichment and overseas escalation.
  • Integrated threat intelligence and fraud context while maintaining evidential, privacy and investigation boundaries between teams.
  • Negotiated rapid technical containment when customer availability, financial crime and operational-risk officers held competing priorities.
  • Produced supervisory evidence showing who decided, what uncertainty remained and why a high-impact action was proportionate.
  • Succession-tested local incident commanders through adversarial simulations, overnight events and deliberate absence of expatriate leadership.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.