Confidential mandate

Threat-Intelligence Fusion Leader — Aerospace Defence Systems

Urgent / Unplanned

Threat-Intelligence Fusion Leader mandate in Tel Aviv, Israel · Aerospace Defence Systems

Following a missed supplier intrusion, an aerospace group needs executive intelligence authority to fuse classified, commercial and internal signals into operational defence decisions and hand over within eight months.

The mandate

A strategic supplier compromise was visible separately in commercial intelligence, authentication anomalies and programme reporting but never fused into an escalation. Analysts had tagged the actor infrastructure, identity teams saw improbable access and programme security recorded unusual document interest, yet no requirement connected those observations. The intelligence director departed after the breach reached sensitive engineering collaboration and executive warnings proved retrospective.

The interim begins within two weeks for eight fixed months across Tel Aviv and programme sites, with daily early briefings during supplier containment and a weekly prioritisation forum thereafter. Permanent selection starts after the first intelligence-led defence cycle in month four; four weeks of transfer are planned, with no extension if source access, clearance or recruitment moves more slowly than expected.

Handover requires priority requirements tied to named programmes and assets, governed source handling, fused supplier and enterprise analysis, intelligence-triggered detection or access decisions and a successor-led executive warning cycle. Three earlier assessments must also be reviewed for missed indicators, and each high-confidence warning must have a recorded recipient, decision and feedback path.

The leader may set collection priorities, restrict dissemination, escalate suppliers and redirect analytic capacity. The remit includes withdrawing an assessment whose sourcing or confidence language cannot withstand challenge. Offensive activity, classified release, supplier termination, permanent hiring and public attribution remain authorised executive or state decisions, and intelligence cannot silently become operational command.

Geopolitical forecasting, physical intelligence and product roadmap ownership are excluded. Programme security continues to own handling and need-to-know decisions outside cyber reporting. The remit turns cyber intelligence into timely defensive choices without claiming certainty it cannot support or expanding into a general strategic-intelligence office.

Why this seat is open

The missed intrusion exposed organisational separation between analysts and defenders. Prior leadership reported indicators without owning warning outcomes. Temporary authority must rebuild fusion, credibility and succession.

What you will own

  • Define intelligence requirements from crown-jewel programmes, supplier dependencies, likely collection objectives, warning thresholds and accountable defensive decisions.
  • Establish source grading, confidence language and dissemination controls across sensitive holdings.
  • Fuse identity, endpoint, supplier, vulnerability and external reporting into decision-ready assessments.
  • Trigger targeted hunts, detection changes, access restrictions and supplier assurance from assessed threats.
  • Create warning thresholds that distinguish weak signals, collection gaps and urgent operational escalation under stated confidence.
  • Review analytic misses and rejected hypotheses without hindsight distortion.
  • Transfer requirements, source restrictions, analytic misses, decision history and briefing cadence through two successor-led warning cycles.

Candidate qualifications

  • Led cyber threat intelligence in aerospace, defence or another sensitive technology environment under formal source-handling constraints.
  • Can evidence fusion of classified or restricted and commercial sources into defensive action.
  • Governed confidence, source protection, dissemination and executive warning under uncertainty, including withdrawal or correction of assessments.
  • Connected supplier intelligence to identity, detection, access restriction and programme-security decisions with retained feedback evidence.
  • Briefed boards or senior authorities on attribution, intent and likely impact without overstating incomplete evidence.
  • Built a successor-operated intelligence cycle after a material miss.

Non-negotiables

  • Eligible for required Israeli security and export-control access.
  • Available within two weeks for full onsite leadership.
  • Will respect classification, source and attribution authorities.
  • Has director-level intelligence decision responsibility beyond feed management.
  1. 49 words maximum. State your availability and the most consequential warning you personally escalated.
  2. 49 words maximum. Which fused signals exposed a supplier compromise that one source could not?
  3. 49 words maximum. Describe an attribution judgment you deliberately kept below executive certainty.

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.