Confidential mandate

Recursive DNS Privacy and Resilience Board Adviser

Planned Hiring / New

Recursive DNS Privacy and Resilience Board Adviser mandate in Kuala Lumpur, Malaysia · Consumer Broadband Networks

A consumer broadband group needs a ten-month board adviser to resolve encrypted recursive DNS choices spanning subscriber privacy, threat controls, parental services and resolver concentration.

The mandate

The board repeatedly debates whether to operate encrypted recursive resolution itself, partner with a specialist or allow device and browser defaults to determine subscriber paths. Privacy teams want data minimisation, security teams rely on domain signals, parental services require accountable policy, and network leaders fear concentrating resolution outside regional recovery control. The standing question is which resolver posture protects choice and continuity without covert surveillance.

The adviser will contribute two working days monthly, lead a monthly resolver-policy challenge, attend four customer-and-technology committee meetings and complete four resolver, operations or consumer-forum reviews. A material privacy or outage question receives an initial view within one business day; routine papers receive comments within five. The retainer includes preparation and all stated attendance.

The appointment runs for ten months and closes with the board’s resolver and encrypted-DNS position. In month nine, the chair may propose a separate deployment-assurance role, but renewal requires a new resolution and refreshed conflict declaration; no automatic continuation exists. Unused time expires rather than carrying into network implementation.

The adviser holds no line authority and has no executive, network-operating, privacy-officer, lawful-access, customer-policy or supplier-selection responsibility. Management runs services and accountable officers interpret obligations; directors decide strategy. The adviser may challenge evidence, test trade-offs and shape safeguards, but cannot configure resolvers, approve data use, block domains or represent the operator to regulators.

No more than three unrelated roles may continue. Work for a public resolver, browser or device platform, security provider, broadband competitor, parental-control supplier, regulator-facing adviser or investor creates a conflict requiring disclosure and possible recusal. Referral fees, data monetisation interests and compensation tied to resolver selection are prohibited.

Why the board wants this voice

Directors hear technically valid but incomplete positions from privacy, security, network and customer teams, each focused on its own harm. The room lacks someone who has operated recursive resolution and encrypted-client choice through outages, abuse and public scrutiny. Independent infrastructure judgment is needed before a default silently determines where subscriber queries, policy and recovery authority reside.

What you will own

  • Press management to classify resolver data, retention, correlation, access, sharing and purpose by subscriber and service context.
  • Test encrypted resolver choices across client discovery, authentication, policy expression, fallback, captive portals, outage and customer control.
  • Challenge security and parental-service claims for necessity, false intervention, bypass, transparency, appeal and alternative evidence.
  • Examine concentration across resolver networks, certificate and identity services, browser defaults, transit, anycast sites and control platforms.
  • Shape resilience expectations for regional isolation, cache behaviour, stale serving, upstream failure, overload and safe customer fallback.
  • Probe commercial models for hidden data value, partner incentives, service bundling, switching friction and exit rights.
  • Frame the board’s final posture on operated and third-party resolvers, subscriber choice, safeguards and prohibited uses.

Candidate qualifications

  • Governed large recursive DNS services or encrypted resolver deployment for consumer, carrier or public infrastructure.
  • Balanced query privacy, security controls, parental policy and customer transparency using operating evidence.
  • Managed resolver outages, cache behaviour, upstream failure, client fallback and anycast concentration at scale.
  • Evaluated browser, device and public-resolver defaults without assuming network operator control or universal client compliance.
  • Challenged domain-signal use where retention, correlation or intervention exceeded its stated protective purpose.
  • Advised a board independently of resolver, browser, security, carrier and data-commercialisation interests.

Non-negotiables

  • Can attend four Kuala Lumpur committee meetings and complete the four regional resolver or consumer reviews.
  • Will disclose resolver, browser, device, security, broadband, regulatory and investment relationships.
  • Accepts that network, privacy, customer, lawful-access and supplier authority remains with accountable management.
  • Brings operated recursive or encrypted DNS evidence; authoritative DNS or general privacy policy alone is insufficient.
  1. 49 words maximum. Describe an encrypted-DNS design that improved privacy while creating an unacceptable recovery dependency.
  2. 49 words maximum. Which current resolver, browser, security or broadband relationship could require your recusal?
  3. 49 words maximum. Confirm the Kuala Lumpur cadence and name one subscriber control that must survive resolver fallback.

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.