Confidential mandate

SaaS Product-Security Recovery Leader — Workforce Automation

Urgent / Replacement

SaaS Product-Security Recovery Leader mandate in Dublin, Ireland · Workforce Automation SaaS

After a tenant-isolation defect reached production, a workforce SaaS business needs executive product-security leadership to close systemic weaknesses and hand over a trusted release model within nine months.

The mandate

A production authorisation defect exposed one tenant's workflow metadata to another, revealing inconsistent isolation tests and service-owner assumptions. Similar services implement tenant context in different layers, and observability tools can copy identifiers outside the original boundary. The product-security leader resigned after customer disclosure began, leaving remediation, release exceptions and customer evidence without executive engineering authority.

The interim starts within three weeks for nine fixed months across Dublin, London and Kraków. The first six weeks require twice-weekly platform decisions and direct participation in priority customer assurance. Permanent recruitment begins after systemic isolation tests pass in month four; five weeks of overlap follow, with no extension for backlog, customer negotiation or search delay.

Handover requires root-cause closure, automated tenant-boundary tests, governed security design review, risk-based release gates, resolved customer commitments and a successor-led quarterly product-risk cycle. Each critical service must have an isolation invariant, accountable owner and negative test, while two production releases must complete without unsupported exception or cross-tenant regression.

The leader may stop releases, mandate remediation, redirect security engineers and approve testing within €3 million. This includes rejecting a threat model or customer attestation whose system scope is incomplete. Customer suspension, permanent hires, architecture replacement and legal admissions require executive approval; product executives own feature priority within security gates and must record accepted schedule effects.

Corporate infrastructure, pricing and broad engineering reorganisation are excluded. Identity and logging teams participate only where their services carry tenant context or product evidence. The remit restores product trust from design through production response without turning the interim into a general engineering or customer-success executive.

Why this seat is open

The tenant incident exposed fragmented ownership across platform and feature teams. The departing leader had not established enforceable release evidence. Temporary authority is needed through remediation, customer proof and succession.

What you will own

  • Reconstruct the authorisation flaw, affected objects, exposure window, observability spill, customer consequence and failed control assumptions.
  • Define tenant-isolation invariants across identity, data, queues, caches, asynchronous jobs and observability services with accountable owners.
  • Embed negative and cross-tenant tests into service build and deployment pipelines.
  • Establish threat modelling and security-design evidence for high-risk platform changes with named reviewers and closure criteria.
  • Decide release exceptions through exploitability, customer exposure, monitoring coverage, compensating control, sponsorship and expiry.
  • Reconcile customer commitments with tested remediation and retained assurance evidence.
  • Transfer architecture risks, negative-test libraries, customer commitments and release governance through two successor-led reviews.

Candidate qualifications

  • Held product-security authority in a multi-tenant enterprise SaaS platform serving security-sensitive institutional customers.
  • Led response to authorisation or tenant-isolation failure in production, including exposure analysis and enterprise-customer assurance.
  • Can evidence automated positive, negative and cross-tenant boundary tests across distributed service architectures.
  • Governed secure design and release exceptions with engineering executives, including documented stop-ship decisions.
  • Faced enterprise customers with precise exposure, remediation, retest and continuing-assurance evidence after a product incident.
  • Handed a recovered product-security function, customer commitments and exception governance to permanent leadership.

Non-negotiables

  • Available within three weeks for the stated European cadence.
  • Independent of testing and application-security vendors engaged.
  • Will stop releases when tenant evidence is inadequate.
  • Has director or CISO-1 product engineering authority.
  1. 49 words maximum. State your availability and one tenant-boundary incident you personally governed.
  2. 49 words maximum. Which negative test best exposes cross-tenant authorisation drift?
  3. 49 words maximum. Describe a release you stopped despite customer deadline pressure.

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.