Confidential mandate
GCC Cyber-Operations Launch Leader — Global Engineering Services
Urgent / Replacement
GCC Cyber-Operations Launch Leader mandate in Bengaluru, India · Global Engineering Services
After its launch head withdrew, an engineering group needs executive leadership to build a Bengaluru cyber-operations GCC, prove global service outcomes and transfer a stable centre within fifteen months.
The mandate
The selected launch executive withdrew after the centre expanded from alert handling to detection engineering, incident coordination and vulnerability operations. Hiring vendors are mobilised, but global service owners have not agreed outcomes, transfers or decision rights. Requisitions reuse generic analyst profiles, access lead times exceed training plans and headquarters teams disagree about which incident decisions may move to India.
The interim starts within three weeks for fifteen months, based four days in Bengaluru with monthly London and Houston reviews. The first quarter centres on service design, leadership hiring and production-readiness rather than raw joining volume. Permanent search begins after 100 hires and two accepted services; six weeks of overlap follow, with extension possible only when the chosen successor's notice crosses the transition date.
Handover requires 140 productive staff, five accepted global services, measured quality and attrition within threshold, exercised major-incident integration and a successor-led quarterly service review. Each service must have named global accountability, trained deputies, stable privileged access, evidence of stakeholder acceptance and a six-month demand forecast tied to funded work.
The leader may approve hiring within bands, select vendors, set service gates and stop transfers lacking knowledge or access. This includes rejecting a cohort whose assessment evidence does not predict the service skill required. Permanent executives, equity exceptions, new locations and spend above ₹5 crore require committee approval; global CISOs retain incident risk decisions and severity declarations.
Real estate, entity setup and enterprise security strategy are excluded. Facilities and legal teams remain accountable for workplace, entity and employment readiness, although their dependencies enter launch gates. The remit builds a credible cyber operating centre, not a labour-arbitrage queue or a parallel global CISO function.
Why this seat is open
The role changed materially after candidate acceptance and the appointee withdrew. Global teams continue to send uncalibrated demand. Temporary authority must define services, build capability and prepare Indian succession.
What you will own
- Convert global demand into service charters with outcomes, inputs, authority, staffing assumptions and measurable acceptance.
- Build role and skill architecture for analysts, responders, detection engineers, vulnerability specialists and service leaders across career levels.
- Set evidence-based selection, training, privileged-access and production-readiness gates for each cyber discipline.
- Sequence service transfers around documented knowledge, tooling readiness, privileged access, shadow operation, global acceptance and escalation maturity.
- Establish quality, timeliness, recurrence, rework, escalation and stakeholder-acceptance measures for each global service and shift.
- Exercise the centre's role in a cross-time-zone major incident.
- Transfer workforce, service, vendor, stakeholder and risk decisions through two successor-led governance cycles.
Candidate qualifications
- Built or scaled an India cyber GCC beyond 100 specialist employees across more than one cyber discipline.
- Can evidence formal global acceptance of detection, response or security-engineering services against documented service outcomes.
- Designed role-based assessment, simulation, supervised practice and production-readiness for scarce cyber talent entering privileged operations.
- Governed service transition across privileged access, knowledge, tooling, escalation and retained global incident authority.
- Challenged headquarters demand that lacked accountable outcomes.
- Handed launch authority to a permanent India leader with stable performance.
Non-negotiables
- Available within three weeks for the stated global cadence.
- No interest in recruiting, staffing or training vendors considered.
- Will reject volume targets unsupported by service quality.
- Has director or CISO-1 cyber GCC build authority.
- 49 words maximum. State your availability and largest cyber GCC build under your authority.
- 49 words maximum. Which evidence proves a transferred security service is genuinely accepted?
- 49 words maximum. Describe one global demand stream you refused to migrate.
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.