Confidential mandate
Industrial GCC Cyber Controls Director — Consulting
Planned Hiring / New
A global industrial GCC commissions a five-month cyber-control model spanning product engineering, operational technology access, privileged development and cross-border incident accountability during rapid headcount expansion.
The mandate
The defined problem is that enterprise security controls do not cover the GCC's combination of source code, remote plant access, engineering test environments and globally split incident decisions. Exceptions are multiplying without one risk model.
The deliverable is a control baseline, threat and data-flow model, target control architecture, exception method, cross-border response playbook, implementation backlog and independently exercised assurance pack.
Milestone one is due 15 October 2026 with baseline and priority scenarios; milestone two on 15 December with control design and funded backlog; milestone three on 15 February 2027 with two exercises, closed design gaps and accepted assurance pack.
The GCC Risk Council accepts when all privileged pathways are mapped, twelve threat scenarios have preventive and recovery owners, two exercises meet agreed response objectives, and internal audit confirms traceable control evidence.
The client provides asset, identity and data-flow records, code and OT access patterns, exception registers, incidents and secure test facilities. Global and India CISOs nominate decision-makers for fortnightly design sessions.
Why this is external work
Enterprise security, product teams and plants each control only part of the exposure. Independent specialists can test cross-border responsibilities without inheriting a local policy position. The exercise and design capability is temporary and separate from managed security operations.
What you will own
- Map identities, code, product data and OT pathways for milestone one.
- Model threat scenarios that cross GCC, product and plant boundaries.
- Reconcile enterprise standards with engineering and operational constraints.
- Design control patterns for privileged development and remote OT access.
- Build the exception method, response playbook and milestone-two backlog.
- Facilitate one cyber and one operational-recovery exercise.
- Close design gaps and submit audit-ready evidence at milestone three.
Candidate qualifications
- 18–22 years in industrial cybersecurity, product security or enterprise risk.
- Direct design experience across engineering environments and operational technology.
- Evidence of governing remote privileged access to plants or connected products.
- Experience facilitating cross-border cyber and recovery exercises.
- Ability to create auditable evidence without imposing unworkable controls.
- Independence from managed security providers serving the GCC.
Non-negotiables
- No managed-security resale or implementation commission.
- Sensitive architecture remains inside client-controlled repositories.
- Director leads both exercises onsite in Gurugram.
- Internal audit receives full traceability from scenario to control evidence.
- 49 words maximum. Which industrial cyber-control model did you design across engineering and OT, and what exercise exposed its largest gap?
- 49 words maximum. How would you map globally split incident authority during milestone one?
- 49 words maximum. Which identity, code and OT artefacts must the client make available immediately?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.