Confidential mandate

Cyber-Resilient Workforce Behaviour Recovery Leader — Digital Commerce

Urgent / New

Cyber-Resilient Workforce Behaviour Recovery Leader mandate in Tel Aviv, Israel · Digital Commerce Platforms

A Tel Aviv commerce platform needs a ten-month recovery leader after training completion failed to change high-risk security behaviour, restoring role-specific readiness through three attack simulations.

The mandate

Annual security training and simulated phishing produce strong completion and reporting rates, yet incident reviews find unsafe privilege sharing, unverified support escalation and poor decisions during account takeover and data-exfiltration events. Generic content does not reflect role-specific attack paths, and employees fear blame after reporting mistakes. The readiness leader departed before a high-risk seasonal trading period.

The ten-month assignment begins within two weeks and covers behavioural risk mapping, three attack simulations, two reinforcement cycles and permanent-leader induction. A threat change, tool rollout, privilege change, incident lesson, vendor access, role transfer or control failure becomes a governed capability event. Six weeks are protected for handover; no extension will cover security operations.

Exit requires role-threat maps, critical behaviours, realistic practice, manager reinforcement, reporting and recovery routes, non-punitive learning, evidence standards and three simulations within tolerance. The successor must command an unseen blended attack involving executive impersonation, support escalation and privileged access without using the interim’s scenario team or scripted prompts.

The interim may suspend ineffective learning, require high-risk role practice, protect simulation windows, redirect ₪180 million of authorised readiness investment, replace temporary faculty and restrict deployment where approved skill evidence is absent. Security owns technical controls and incident command; managers deploy people; authorised investigators handle events; employee relations owns individual consequence.

Security architecture, penetration testing, threat investigation, disciplinary action, surveillance, vendor procurement and production incident command are outside scope. The leader may simulate authorised attacks and strengthen behaviour but cannot inspect private employee activity or determine culpability. Metrics will not reward concealment, punitive reporting or repeated low-value phishing exercises detached from actual role risk.

Why this seat is open

The company measured exposure to content while real incidents tested identity verification, privilege discipline, escalation and recovery under pressure. The leader’s departure left seasonal risk without a coherent practice model. Temporary authority must create observed readiness through varied simulations and qualify a permanent owner against a blended attack.

What you will own

  • Map role-specific threat paths, decision points and critical observable behaviours across engineering, support, finance and executive populations.
  • Distinguish knowledge, reported intent, simulation behaviour, supervised practice and live control adherence.
  • Build scenarios for impersonation, credential theft, privilege misuse, vendor compromise and data handling.
  • Establish safe reporting, immediate containment, manager response, non-punitive learning and repeated-error escalation.
  • Connect incident lessons, role changes, tool releases and control failures to renewed practice requirements.
  • Command three attack simulations plus delayed reporting, degraded communication and simultaneous business pressure.
  • Transfer readiness authority after the successor independently leads an unseen blended attack and formal evidence review.

Candidate qualifications

  • Held cyber workforce readiness authority in digital commerce, banking or another high-threat technology environment.
  • Converted threat and incident patterns into role-specific behaviours, practice and observable readiness evidence.
  • Designed credible simulations beyond generic phishing across privileged, support, finance and executive populations.
  • Built reporting and learning conditions that reduced concealment without excusing repeated unsafe behaviour.
  • Preserved boundaries among workforce capability, security controls, incident command, investigation and employment action.
  • Handed recovered cyber readiness to permanent leadership through repeated complex multi-vector attack and degraded-communication scenarios.

Non-negotiables

  • Available within two weeks for Tel Aviv leadership and all three controlled attack simulations.
  • Direct role-based cyber behaviour recovery is required; generic awareness campaign leadership is insufficient.
  • Will disclose security-training, simulation, platform, investigation and cyber-insurance relationships.
  • Will not conduct penetration tests, investigate employees, command incidents, surveil activity or decide discipline.
  1. 49 words maximum. Describe a cyber incident where completed awareness training failed to predict employee behaviour.
  2. 49 words maximum. How did you create non-punitive learning without normalising repeated unsafe choices?
  3. 49 words maximum. Which blended attack must the permanent leader command before handover?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.