Confidential mandate

Chief Information Security Officer — Manufacturing Continuity

Urgent / Replacement

CISO mandate in Bengaluru, India · Electronics Manufacturing

A twelve-month bridge CISO will establish documented security decisions and transfer a tested governance cycle to the permanent security chief in a manufacturing environment.

The mandate

Manufacturing information-security decisions require executive ownership as exception backlogs grow. Infrastructure teams can operate controls, but exceptions affecting sensitive engineering information, supplier access and recovery readiness lack an accountable executive risk route. The bridge must hold the CISO seat in substance, with verified security leadership authority rather than an assumption that a technical title proves readiness.

The twelve-month term starts on 19 October 2026 in Bengaluru, with five-day availability and planned visits to Indian manufacturing operations. A permanent CISO search runs concurrently, with the successor expected to participate in the final governance and recovery reviews. The bridge is fixed term and does not include an informal promise of permanent conversion.

Handover requires a risk register with explicit acceptance authority, tested escalation paths and a security assurance calendar linked to actual operational dependencies. Material exceptions must have owners, compensating controls and expiry dates; recovery evidence must distinguish demonstrated capability from an untested plan. The permanent appointee must chair a risk review and receive unresolved supplier, infrastructure and information-protection issues with their decision histories.

The CISO may set information-security standards, prioritise approved assurance work and direct the security team within budget. Production shutdown, changes to safety-critical systems, permanent restructuring and spend above ₹35 lakh outside plan require authorised executive approval. The bridge can demand risk escalation but cannot independently alter manufacturing controls whose safety authority belongs to engineering and operations.

The appointment excludes plant safety leadership, a full operational-technology redesign and product certification. It covers the protection and recoverability of manufacturing information services, executive security judgement and a disciplined way to handle business exceptions. The leader must expose where security and production objectives conflict, propose bounded options and leave a repeatable governance process rather than a personality-driven veto.

What you will own

  • Approve information-security exception decisions within delegated appetite, requiring compensating controls, expiry dates and escalation where manufacturing risk exceeds the bridge holder's authority.
  • Set a security assurance calendar around sensitive engineering data, supplier connectivity and recoverability, distinguishing critical dependencies from generic control-count completion.
  • Direct incident escalation rehearsals that test executive decision timing and evidence preservation without authorising unsafe changes to production or engineering systems.
  • Challenge recovery claims against witnessed restoration and access evidence, recording remaining dependencies and the executive owner of accepted residual manufacturing exposure.
  • Authorize security-team priorities within approved budgets, presenting out-of-plan investment and material operational tradeoffs through the existing executive and risk committee route.
  • Transfer risk decisions, assurance evidence and exception ownership to the permanent CISO through a successor-led review and a replayed escalation scenario.

Candidate qualifications

  • Demonstrate actual CISO or equivalent executive information-security responsibility supported by career chronology, delegated authorities and independently verifiable outcomes. Explain one manufacturing-related risk decision you personally held, the operational consequence and the approval boundary. Candidates must establish total career and leadership scope through evidence rather than rely on a security-chief title.
  • Show capability in information-security governance, infrastructure protection and enterprise incident escalation relevant to manufacturing. Provide a case where a business exception required compensating controls and a time-limited risk decision, identifying what you could approve and what required executive or operational authority.
  • Bring experience protecting sensitive engineering or supplier-linked information while maintaining reliable operations. Evidence should include a recovery or assurance test that changed management's understanding of exposure. The appointment does not presume specialist plant-safety or every OT-domain competence; candidates must recognise the limits of their expertise and involve qualified engineering owners.
  • Prove leadership of security specialists and constructive engagement with production, infrastructure and executive stakeholders. Describe how you transferred a risk register or governance cycle, preserved decision histories and avoided personal dependence. Availability, delegated CISO scope and experience depth will be checked before appointment; certifications alone cannot substitute for accountable security judgement.

Application

Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.

There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 12 October 2026. Mandate reference PCT-INT-2026-IND-48.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.