Confidential mandate
SOC Risk Priorities and Response Decision Rights — Cyber Adviser
Planned Hiring / New
SOC Risk Priorities and Response Decision Rights mandate in Mumbai, India · Financial Services Technology
Advise nine months of financial-services SOC risk decisions, challenging detection investment and response authority through a defined security governance cadence while preserving CISO, business and incident-executive accountability for operational action.
The mandate
The security risk committee needs to decide which SOC improvements genuinely reduce exposure and who may act when their detections indicate a serious event. The standing question connects investment priority with response authority: visibility without an authorised decision path may create little practical resilience. Advice will test that connection without running the SOC or investigating live incidents.
A four-day monthly allocation covers coverage challenge, response-rights discussion, committee attendance and preparation. Security committee participation is included; complete ad-hoc risk questions receive initial advice within three business days. Mumbai meetings are hybrid, and incident-sensitive information is shared only through approved access channels rather than informal messaging.
The advisory window begins on 19 October 2026 and expires on 18 July 2027, when the security committee chair evaluates continuation. Renewal depends on the usefulness of challenged choices and whether internal owners maintain the decision method. A live incident, forensic investigation or regulatory request is separately scoped and does not turn the retainer into unlimited emergency response.
For SOC prioritisation and response governance, the adviser has no line authority and carries no executive responsibility. CISO, business owners and authorised incident executives retain operational decisions. Recommendations must distinguish a security observation, a confidence assessment and a proposed business action, keeping the retained approval visible even when committee discussion favours the recommendation.
Concurrent non-competing engagements are allowed if the monthly allocation remains reliable. A managed-security bidder, detection-product commission arrangement or advice to a party involved in the same incident creates a conflict requiring disclosure. Product resale, forensic certification and incident operations are excluded so that the adviser can challenge investment and authority choices independently.
What you will own
- Challenge SOC investment proposals by tracing the threat hypothesis, telemetry dependency and intended decision consequence, rather than accepting tool acquisition or use-case deployment as evidence of reduced exposure.
- Probe response matrices for customer-impacting choices, asking whether the named approver has genuine business authority and can act within the required uncertainty and escalation window.
- Test coverage claims against evidence of relevant source events and detection reliability, identifying where gaps require compensating measures instead of confidence inferred from aggregate alert statistics.
- Shape committee questions around containment reversibility, recovery and business interruption, keeping technical security recommendations distinct from retained executive decisions about operational consequences.
- Press sponsors to explain detection maintenance and review costs alongside implementation benefits, preventing an apparently economical investment from creating unowned continuing operational obligations.
- Review the committee's response to challenge and residual visibility gaps, preserving assumptions and reconsideration triggers after a preferred security investment or governance change is approved.
Candidate qualifications
- Show senior SOC governance, cyber-risk or defence-monitoring experience with evidence of investment or response choices personally influenced. Describe one improvement rejected because its decision value was weak. Candidates must operate through practical challenge without relying on the ability to direct analysts, purchase tools or claim CISO authority.
- Demonstrate technical understanding of detection coverage, telemetry reliability and incident confidence through a redacted case. Explain where an implemented control created false assurance and how the limitation was communicated. Framework knowledge and professional cyber certification are relevant, but only when connected to operating evidence and retained business decision rights.
- Provide advisory discipline in a controlled environment through a disputed containment or coverage recommendation and the committee's documented response. Explain how confidence changed when telemetry was incomplete and which business approval remained outstanding. The committee needs bounded cyber judgement that accurately preserves uncertainty, not a forensic opinion, regulatory guarantee or product-oriented proposal presented as independent risk advice.
- Establish senior SOC leadership through a risk-priority recommendation supported by detection coverage, investigation capacity and response dependencies, while maintaining a realistic four-day monthly commitment. Disclose managed-security, vendor and same-incident interests, including contingent remuneration. Demonstrate how concurrent work was separated and why commercial incentives would not prevent you from advising against a favoured security product or service.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 9 October 2026. Mandate reference PCT-ADV-2026-IND-28.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.