Confidential mandate

Interim Chief Trust Officer — Managed Security Assurance

Urgent / Unplanned

A customer audit has exposed shared-admin weaknesses, requiring an interim trust chief to repair access assurance, regain regulated clients and transfer a defensible control system.

The mandate

A regulated customer discovered that support engineers could share elevated credentials across tenant environments, contradicting contractual assurance, and suspended new service onboarding. The assurance head resigned after the audit response failed, leaving security operations and customer teams with competing interpretations of closure.

The interim is required within two weeks for nine months. Permanent recruitment begins after the largest affected client accepts remediation, with extension possible for one month if external certification timing delays the transition.

Handover requires all administrative access to be individually attributable and time-bound, the top ten regulated clients to accept updated evidence, external certification to close without a major finding, and the successor to lead one customer audit. Ninety days of access-control operation must be demonstrated.

The interim may revoke privileges, stop customer onboarding, impose assurance standards and spend ₹6 crore inside the approved remediation. Material contract concessions, customer compensation above ₹3 crore, platform replacement, permanent director hiring and risk acceptance for shared credentials require CEO or board approval.

The mandate excludes SOC detection operations, client incident response and commercial ownership of renewals. The trust function must verify control and customer evidence without taking over delivery teams whose work it challenges.

Why this seat is open

The failed response damaged the independence and credibility of the existing assurance chain. Operational security leaders cannot certify controls they administer, while account teams are incentivised to reopen onboarding. An interim trust chief can restore objective evidence before a permanent appointment.

What you will own

  • Inventory every administrative path and decide which privileges are revoked, redesigned or subject to temporary compensating control.
  • Establish individual, time-bound and recorded access requirements across employees, vendors, automation and emergency use.
  • Build customer assurance packs linking contractual statements to tested controls, owners, samples and exception treatment.
  • Approve reopening of regulated-client onboarding only after each required control passes sustained operating evidence.
  • Direct external certification readiness and reject closure where samples omit real production administration.
  • Lead the ten highest-risk customer assurance sessions with candid residual-risk and remediation dates.
  • Transfer the access register, customer commitments, certification findings, accepted risks and assurance calendar to the successor.

Candidate qualifications

  • Held Chief Trust Officer, CISO, assurance head or security GRC director authority in a managed technology provider.
  • Recovered customer trust after a control statement was contradicted by production evidence.
  • Designed privileged-access governance across multi-tenant services and third-party administrators.
  • Led regulated-enterprise customer audits and external security certification to accepted closure.
  • Maintained assurance independence while working with revenue and delivery executives under renewal pressure.
  • Understands contractual security evidence, privacy obligations and outsourced-service control reports.

Non-negotiables

  • Can assume Chennai accountability within fourteen days.
  • No current affiliation with the certification body or affected customer audit firm.
  • Will not reopen onboarding on remediation plans without operating evidence.
  • Must have personally signed external control or customer assurance representations.
  1. 49 words maximum. State your earliest start and disclose any customer, auditor or certification-body conflict.
  2. 49 words maximum. Describe a customer assurance statement you corrected after production evidence contradicted it.
  3. 49 words maximum. What proof would you require before allowing privileged vendor access?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.