Confidential mandate
Global Head Technology Risk Transformation — Third-Party Assurance Continuity
Planned Hiring / New
Global Head Technology Risk Transformation mandate in Pune, India · Banking Third-Party Technology
Establish global technology-risk transformation leadership across the third-party lifecycle, connecting assessment evidence, service dependencies and remediation through an eighteen-month opening agenda so assurance remains current after contract award rather than ending with a completed onboarding questionnaire.
The mandate
Onboarding assessments in a banking group are complete, but the relationship between those assessments and the technology services actually consumed is weakening over time. Suppliers add subcontractors, support arrangements change and remediation dates pass without a consistent decision about reassessment. The new global head will lead transformation of this third-party assurance lifecycle. The first eighteen months will connect evidence and triggers from onboarding through service change and exit; open-ended employment continues with responsibility for programme improvement, regional adoption and the reliability of the operating model.
Your teams will map supplier relationships to services, accountable technology owners and the evidence supporting assurance conclusions. A single vendor can support several services with different dependency and recovery requirements; a satisfactory corporate questionnaire cannot automatically clear every use. Conversely, repeated requests for the same evidence can consume capacity without addressing a material change. You will define a transformation approach that makes reassessment proportionate to service consequence and approved policy, preserving a visible route for gaps that require specialist judgement or formal risk acceptance.
Sixty-five colleagues report through regional and functional leads. You own the transformation roadmap, change acceptance and the performance framework for assurance continuity. Technology owners remain responsible for their services, procurement for commercial relationships, and risk executives for policy and acceptance decisions. Security, resilience and privacy specialists assess their own domains. The sponsor approves material control-model changes. You may require remediation evidence before declaring a programme change complete, but cannot cancel a supplier contract or accept unresolved exposure on behalf of a business executive to simplify adoption.
At the opening programme's conclusion, a material supplier or service change should trigger a clear evidence review and owner decision rather than disappear between procurement and technology records. Remediation closure must show what changed and whether the affected service owner accepted the result. Pune is the working base, with structured global collaboration and planned workshops rather than continuous supplier travel. The enduring function will develop managers capable of distinguishing a documentation refresh from a consequential assurance issue and keep the model useful as the bank changes platforms and service relationships.
What you will own
- Establish the supplier-to-service dependency baseline with technology owners, exposing relationships where an onboarding conclusion is being applied beyond the service or evidence population it actually assessed.
- Decide transformation priorities using critical service dependencies, stale evidence and unresolved remediation, distinguishing material assurance gaps from repeated administrative requests that do not improve the understanding of exposure.
- Design reassessment triggers for service, subcontractor and contractual changes under approved policy, documenting the owner responsible for judging whether new evidence or formal escalation is required.
- Build remediation-continuity controls that retain affected services, specialist findings and closure evidence, preventing completion of a supplier task from being treated automatically as acceptance of the underlying exposure.
- Set adoption measures that show whether service owners act on consequential changes, testing live cases instead of recording a revised procedure or training completion as proof of operational improvement.
- Recommend regional operating-model changes to the sponsor with capacity and control implications, preserving local obligations while removing duplicate evidence requests that consume expertise without addressing a distinct decision.
- Develop programme managers through contested third-party cases, coaching them to obtain the right professional assessment and authorised decision rather than infer supplier acceptability from an apparently complete questionnaire.
Candidate qualifications
- Present a third-party assurance problem in which a supplier-level assessment did not adequately cover the service being consumed. Explain the dependency, the evidence limitation and the ownership change you established. Your contribution should show technology-risk or GRC transformation judgement and a practical route to reassessment, not merely the collection of additional questionnaires from an uncooperative vendor.
- A 22–28-year banking technology or financial-services transformation career should include substantial GRC, IT-risk, audit or third-party risk delivery. Show VP-level or comparable multi-programme leadership and managers you developed across functional boundaries. MetricStream or equivalent GRC implementation experience is valuable where it supports evidence continuity; the role does not depend on a particular platform replacing informed service-level judgement.
- Demonstrate methods for change triggers, remediation evidence and policy traceability that specialist and operational teams could use together. Describe a closure decision you challenged because the vendor's task completion did not establish control effectiveness for the bank. You must recognise the distinct authority of security, resilience, privacy and risk-acceptance owners, and communicate residual uncertainty without implying that transformation staff can certify every domain.
- Evidence sustained adoption across regions where procurement and technology records were inconsistent. Explain how you prioritised scarce reviewers, reduced duplicate requests and tested the operating model through live changes. Clear executive communication and mature handling of supplier-sensitive information are essential, as is the ability to preserve a difficult unresolved decision when programme sponsors prefer a simpler completion narrative.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 12 October 2026. Mandate reference CVU-PER-2026-IND-133.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.