Confidential mandate
Chief Risk Officer — Advanced-Node Design Organisation
Urgent / Replacement
CRO - Risk mandate in Chennai, India · Semiconductor
Establish independent commitment risk for an advanced-node design organisation whose customer design wins depend on unproven tape-out, IP, yield and supply assumptions.
The mandate
An advanced-node design organisation has secured prominent customer nominations, but conversion depends on IP readiness, tape-out quality, foundry yield, package availability, software and customer validation. Risks are reviewed inside functions, allowing the overall commitment to appear healthier than its weakest dependency. The Chief Risk Officer will establish independent, cumulative risk before commercial and capacity promises become irreversible.
Approximately 675 employees and material partners sit across design, programmes, operations, commercial and corporate functions. The CRO owns enterprise and programme risk, third-party assurance, resilience, cyber coordination, crisis readiness and board reporting. Engineering and business leaders own delivery; risk sets appetite, challenges evidence and reports accepted downside to the relevant board committee.
Design-win risk begins with milestone clarity. Customer selection, specification freeze, tape-out, qualification and production are different commitments. The CRO will require probability and dependency evidence and prevent a programme from remaining green when a critical IP block or customer decision moves.
Cumulative risk must combine individually managed issues. A late memory, tight mask schedule, unqualified package alternate and scarce verification expert may together make a launch implausible. Exceptions require named acceptance, expiry and contingency rather than optimistic aggregation.
Third-party concentration spans tools, IP, foundry, packaging and cloud compute. Contract rights, service access, data security and recovery time will be tested. A supplier’s financial strength does not prove the programme can switch or recover.
Commercial risk includes promises based on engineering samples, unsupported yield or uncertain end use. Risk will not replace sales approval, but will set independent gates and ensure deviations reach the board before customer commitment.
Model and data risk can distort the board view. Conversion probabilities, schedule simulations and yield projections need source, owner, version and back-testing. The CRO will challenge correlation presented as causal recovery and require management overlays to be documented, preventing convenient assumptions from entering forecasts without trace.
Intellectual-property and confidentiality risk grows when customers request deep pre-production access. Evaluation environments, debug logs and joint engineering must have approved boundaries and segregation. A valuable design win cannot justify exposing reusable architecture or another customer’s information.
People concentration belongs in programme risk. One architect, verification specialist or customer applications lead may be the only person able to resolve a critical dependency. The CRO will require observed backup capability, retention action and workload limits and will test whether a successor can act during an exercise.
Insurance and contractual limitation will be assessed but not treated as operational recovery. Re-spin cost, delayed customer launches and loss of future sockets may exceed recoverable amounts. The board should see this downside before accepting a compressed tape-out or capacity commitment.
Risk culture will reward early technical challenge. Programme leaders should not improve their status by deferring bad news until sign-off. The CRO will review near misses and decision timing, protect independent escalation and ensure retrospectives address incentives as well as process.
The former CRO resigned during a governance redesign. Interim assurance protects current releases, but a permanent leader is needed before new commitments. The onsite Chennai role has unrestricted committee access.
What you will own
- Establish risk appetite and evidence gates for design-win conversion.
- Aggregate technical, customer, supply, security and people dependencies.
- Govern exceptions, acceptance, expiry and contingency.
- Test third-party and programme recovery routes.
- Challenge sample, yield, capacity and timeline promises.
- Lead crisis exercises and close severe findings.
- Report independent programme risk to the board committee.
- Build semiconductor risk capability without duplicating engineering.
The first 12 months
In the first 45 days, review the largest design wins, map weak dependencies and identify promises unsupported by current evidence. Set interim risk acceptance and bring severe cumulative exposure to the board.
By month six, implement conversion risk gates, test priority supplier and programme contingencies and exercise a failed tape-out or qualification scenario. Close major governance gaps and appoint critical risk leaders.
At twelve months, place 100% of material customer commitments under independent risk evidence, reduce overdue high-risk exceptions by 75% and verify recovery for 90% of critical dependencies. No major customer or capacity commitment should fail because a known unaccepted risk was omitted from governance. Board forecasts should reconcile to risk-adjusted milestones.
What the board will measure
- Design wins described by conversion evidence rather than headline value.
- Combined dependencies visible across functional reporting.
- Exceptions expiring through action rather than repeated extension.
- Supplier and recovery claims physically tested.
- Commercial commitments challenged before irreversibility.
- Independent risk trusted without becoming shadow engineering.
The person
You bring 22–28 years in semiconductor risk, engineering assurance, programme leadership or resilience, including advanced-node exposure. You have challenged a customer or tape-out commitment and influenced a board decision.
Your prior scope should include 500 employees and partners or ₹3,000 crore programme value. Evidence must include cumulative risk, a failed contingency test and a commitment paused before customer harm. Direct committee reporting is essential.
Compensation and terms
Fixed compensation is ₹2.2–3.0 crore plus performance variable linked to conversion risk, tested resilience, board confidence and leadership. The permanent Chennai post is onsite and reports to the Group Chief Executive and relevant board committee. Prompt transition is required.
Confidentiality
The organisation, customers, design wins, nodes, suppliers and risk reports remain confidential. Detail follows fit, conflicts and signed confidentiality. Applicants must not contact customers, vendors or employees to identify the enterprise.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.