Confidential mandate
EVP – Risk and Resilience — Digital-Services Division
Planned Hiring / New
EVP – Risk and Resilience mandate in Sydney, Australia · Telecommunications
A Sydney digital-services division is creating a resilience role to protect managed-service customers as end-of-support network, cloud and security platforms are migrated or closed.
The mandate
The division supports enterprise customers through managed network, cloud and security services assembled across several technology generations and acquisitions. A number of platforms are reaching vendor end of support, no longer meet target security architecture or cannot scale economically. Retirement is necessary, but customer services depend on configurations, integrations, data and operational knowledge that are not fully represented in contract or asset records. A migration that succeeds technically can still fail a customer's business process or regulatory obligation.
The EVP – Risk and Resilience will establish independent service assurance across the retirement portfolio. The remit includes enterprise risk, operational resilience, critical service mapping, migration-risk governance, crisis management, third-party resilience and executive assurance. Technology and service teams own migration and operation; cyber, privacy and legal specialists retain their authority; account leaders own customer engagement. The EVP must connect them around the customer's essential outcome and ensure residual exposure is accepted before irreversible change.
This planned new appointment is not intended to create an additional sign-off for every technical release. The board wants proportional evidence, early escalation and tested recovery for the services whose failure would be material. The executive must know when a bounded migration risk is reasonable and when end-of-support urgency is being used to conceal incomplete understanding.
Scope and operating context
Based onsite in Sydney, the role influences approximately 2,025 employees and material partners across Australia and a wider international region. The service ecosystem includes managed network operations, cloud platforms, security operations, customer service management, engineering, vendors and implementation partners. A central resilience team will work through owners embedded in each service domain.
Customer estates vary in age and criticality. A legacy service may support routine branch access, a hospital workflow, industrial telemetry, identity or security monitoring. Contracts may describe availability but not the business process dependent on it. The EVP will create a customer-service view without assuming access to information clients cannot or should not share.
Vendor and knowledge concentration are material. Specialist components may no longer have manufacturer support, and a small number of engineers may understand bespoke configurations. Retirement can increase short-term dependence on those people and suppliers. The risk plan must address retention, access, spares, rollback and documentation before the window closes.
First-year agenda
The first one hundred days will map the retirement portfolio by essential customer service. The EVP will review end-of-support dates, vulnerabilities, customer dependencies, configuration and data, migration readiness, contracts, recovery, specialist capability and previous incidents. Several representative migrations will be reconstructed to identify where technical completion diverged from customer stability.
The executive will then introduce consequence-based migration assurance. Higher-criticality services will require validated inventory, dependency mapping, customer approval where appropriate, rollback or alternative recovery, monitoring, communication and post-change stabilisation. Lower-risk changes can operate within standard guardrails. Evidence requirements and acceptance authority will be explicit.
Customer engagement will be integrated into readiness. Account and service leaders must explain the change, customer action, testing, outage, data treatment and residual risk in language suited to the customer. Where a client declines or delays migration, the division will document the remaining security, support and commercial position and agree a bounded path rather than allow silent indefinite exception.
Compound scenarios will test the operating model. Exercises may combine a migration defect with vendor unavailability, rollback failure, cyber exploitation or customer incident. They will examine command, evidence, technical and account decisions, regulatory coordination and customer remedy. Findings must lead to funded action or explicit authorised acceptance.
Third-party and skill resilience will receive early attention. Critical vendors will be assessed for support, access, recovery and exit; scarce internal knowledge will be documented and paired. Retention interventions should be targeted and time-bound, accompanied by capability transfer. By year-end, priority migrations should have stronger evidence and the highest-risk unsupported dependencies should be reduced.
Leadership responsibilities
The EVP will chair migration-risk and resilience forums and provide the executive committee and board with an independent view of exposure. Reporting will state customer service, evidence confidence, available options, consequence and decision owner. Technical traffic-light reports without customer context will be challenged.
During material disruption, the role will maintain crisis coordination across technology, cyber, service, account, legal and communication teams. Functional experts retain authority, while the EVP ensures decisions align and customers receive verified information. Post-event learning will change migration design or service controls.
The central team will build ownership in the line. Service executives should know their dependencies, recovery and acceptance thresholds. Assurance will sample and test rather than produce duplicate plans. Repeated failure will lead to leadership, investment or design action.
Measures of success
The board will review critical services mapped, migrations completed with evidence, customer-impacting incidents, rollback, post-change defects, unsupported assets, overdue high-consequence actions and actual recovery. Customer measures include service stability, escalations, communication and contract consequence.
Third-party and capability outcomes include critical-vendor assurance, specialist coverage, documentation and tested alternatives. Risk acceptance will be assessed for authority, time bound and mitigation. Retirement volume alone will not count if service risk is transferred or hidden.
Candidate profile
Candidates should bring 22–28 years of risk, resilience, technology or managed-service leadership in telecommunications, cloud, cyber, financial services or another critical digital environment. They must have governed major platform retirement or customer migration across countries and led live service incidents.
The board will seek examples of stopping or conditioning a migration, managing a customer that could not move on schedule and reducing dependence on an unsupported vendor or small expert group. Candidates should understand service mapping, cyber exposure, recovery, contracts and customer communication.
The successful EVP will be independent, technically literate and calm. They must challenge engineers without pretending to replace them, communicate uncertainty to customers and boards and make proportionate decisions under end-of-support pressure. Experience with regulated enterprise customers is valuable.
Compensation and appointment terms
The expected base range is AUD 440,000–590,000, with annual incentive and long-term participation linked to customer resilience and enterprise value. Final terms will reflect relevant service criticality, migration scale and current arrangements. Relocation or treatment of forfeited compensation will be considered through a documented individual process.
Confidentiality
The division is unnamed because customer dependencies, unsupported technology and migration risks are sensitive. Detailed service and customer information will be disclosed only after identity, conflict and confidentiality checks. Applications must not contain client architectures, vulnerabilities, incident records or proprietary recovery plans from other organisations.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.