Confidential mandate
Interim Director, Cybersecurity Engineering GCC — Control Build
Urgent / Replacement
A client-control commitment has outpaced a new security centre's capability, requiring an interim director to build engineering ownership, prove secure delivery and establish permanent leadership.
The mandate
A regulated client committed to security-control delivery from the new India centre before local architecture and engineering leadership were hired. The original build director resigned after scope and talent assumptions changed, leaving global teams to manage fragmented requisitions and an approaching audit.
The interim must start within three weeks for ten months. A permanent director search begins after the first two control products enter supported operation, with extension possible for one month if the client audit moves.
Handover is complete when 350 planned roles are staffed to the agreed profile, identity and cloud-security products operate with local build-and-run ownership, the client audit accepts control evidence, and the successor has approved one production release.
The interim may sequence hiring, set engineering standards, choose delivery tooling and allocate ₹12 crore of mobilisation spend. Changes to the client control commitment, permanent leadership hires, headcount above plan, security risk acceptance rated high and supplier contracts above ₹10 crore require global CISO or board approval.
SOC operations, enterprise security policy and unrelated application-security backlogs are outside scope. The centre builds and runs the specified security products but does not assume the global CISO's risk ownership.
Why this seat is open
The initial leader left when the centre's promise shifted from staffing to control ownership. Global architects can supply designs but cannot establish local accountability and talent. A temporary director can meet the immediate client evidence window while recruiting the right steady-state leader.
What you will own
- Recast the workforce plan around identity, cloud security, product assurance, platform and production-support ownership.
- Decide hiring sequence and technical assessments for architects, engineering managers and senior security engineers.
- Accept transferred security products only after code, backlog, runbooks, access, monitoring and risk ownership are explicit.
- Establish secure-development and release gates with retained threat, test, exception and approval evidence.
- Govern the client audit response for controls delivered by the India centre.
- Demonstrate local build-and-run ownership for identity and cloud-security products across two release cycles.
- Transfer product charters, team capability, client obligations, accepted risks and the next release calendar to the permanent director.
Candidate qualifications
- Led cybersecurity engineering, security platform or product-security organisations at director level.
- Built an India security engineering centre with accountable product and production ownership.
- Delivered identity or cloud-security controls subject to regulated-client assurance.
- Recruited and assessed senior security architects and engineering managers in volume.
- Established secure release evidence without substituting compliance documents for technical proof.
- Worked effectively across global CISO, product engineering and India-site governance.
Non-negotiables
- Available in Pune within three weeks.
- No current relationship with the client auditor, staffing vendors or security suppliers.
- Will not accept control ownership without operational access and decision rights.
- Must have directed security engineers, not only GRC or SOC analysts.
- 49 words maximum. Confirm availability and disclose any auditor, vendor or client conflict.
- 49 words maximum. Describe a security product you transferred to an India team and its run responsibility.
- 49 words maximum. Which artefact proves a security control is engineered rather than merely documented?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.