Confidential mandate
Identity-Fabric Recovery Leader — Cross-Border Payments
Urgent / Unplanned
Identity-Fabric Recovery Leader mandate in Frankfurt, Germany · Cross-Border Payments
After a privileged-account compromise exposed fragmented directories, a payments group needs executive authority to rebuild workforce and workload identity trust and hand over stable controls within eleven months.
The mandate
A compromised administrator account moved through legacy directories into cloud settlement tooling, revealing orphaned privileges, inconsistent joiner-mover-leaver data and unmanaged workload identities. Investigators also found emergency credentials copied into automation and certification campaigns that excluded inherited applications. The identity head left during investigation, while platform teams dispute which directory remains authoritative and who may accept interruption during privilege removal.
The interim starts within three weeks for eleven months, combining Frankfurt leadership with Warsaw and Dublin reviews. The first month carries daily authority over tier-zero containment and twice-weekly settlement-service risk decisions. Permanent recruitment starts after privileged containment in month four, with six weeks' transition; extension is possible only where the selected successor's notice crosses the planned handover date.
Handover requires tier-zero isolation, governed privileged workflows, reconciled workforce identity, inventoried machine credentials, two access-certification cycles and a successor-led risk review. Break-glass use must have passed an observed exercise, every critical application must name an entitlement decision owner and expired exceptions must remain closed. Tool deployment without verified entitlement and reachable-privilege reduction will not qualify.
The leader may revoke access, freeze integrations, set identity standards and reprioritise the approved €12 million portfolio. This authority includes stopping automated provisioning whose source data or rollback cannot be trusted. Board approval covers customer-impacting suspension, permanent directors and material platform replacement; application owners retain business entitlement decisions but must evidence them within the interim's certification rules.
Customer authentication redesign, HR-system replacement and general cloud migration are excluded. Those programmes must expose dependencies where they consume workforce or service identity, yet their roadmaps remain with accountable executives. The assignment repairs enterprise identity control across people, privilege and workloads rather than absorbing every access-related technology change.
Why this seat is open
The compromise exposed authority gaps rather than one faulty account. Previous leadership departed before a target fabric could be agreed. The board needs finite executive command through containment, simplification and proven transfer.
What you will own
- Reconstruct privilege movement across directories, federation, vaults, cloud roles and settlement applications using time-bound reachability evidence and administrator-session history.
- Decide the authoritative sources and trust boundaries for workforce and workload identity.
- Isolate tier-zero administration with hardened workstations, separate credentials and monitored break-glass use.
- Eliminate orphaned and excessive entitlement through application-owner evidence and risk-ranked campaigns.
- Replace unmanaged secrets with governed issuance, rotation, revocation and ownership.
- Measure identity exposure through reachable privilege, credential persistence and control effectiveness rather than misleading account totals.
- Transfer architecture, exception history, certification results and talent decisions through two successor-led control cycles.
Candidate qualifications
- Held enterprise IAM or identity-security authority in regulated, multi-directory environments with critical payment or transaction services.
- Led recovery from privileged compromise spanning on-premise and cloud identity.
- Can evidence tier-zero isolation and measurable reachable-privilege reduction across directory, vault and cloud administration paths.
- Governed human, service, workload and emergency identities under one model, including ownership and rotation for machine credentials.
- Challenged application executives on entitlement ownership, role design, recertification evidence and unacceptable operational exceptions.
- Handed a repaired identity estate to permanent leadership after control testing.
Non-negotiables
- Available within three weeks for the stated European working pattern.
- Independent of incumbent IAM, PAM and systems-integration vendors.
- Will revoke unsafe access despite operational inconvenience.
- Has director or CISO-1 identity decision rights.
- 49 words maximum. State your earliest start and one privileged compromise you contained.
- 49 words maximum. Which graph or evidence best reveals reachable privilege across directories?
- 49 words maximum. Describe an identity integration you froze despite business objection.
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.