Confidential mandate
Director of Cybersecurity — Interim, Energy Technology GCC
Urgent / Replacement
A privileged-access breach has displaced cybersecurity leadership, creating a nine-month interim directorship to contain exposure, separate operational technology and certify sustainable controls across critical systems.
The mandate
Compromised administrator credentials were used to access engineering data and a test operational-technology environment. The security director was dismissed when dormant privileged accounts and missing log retention emerged during containment.
The interim must start within ten days for a fixed nine-month assignment through forensic closure and control certification. An internal deputy will take the role after completing two independent incident-command and assurance exercises.
Handover requires all compromise pathways closed, privileged access recertified, OT and corporate trust boundaries independently tested, critical logs retained and searchable, and the deputy able to command a severe simulated event without assistance.
The director may isolate systems, revoke access, direct forensics and approve emergency controls below ₹60 lakh. Notification decisions, production-asset shutdown and spend above ₹2 crore require global authority; the role cannot conceal or amend forensic evidence.
Broad cloud migration, physical asset maintenance and product-feature security are excluded except where directly implicated. Resources must remain on breach closure and repeatable identity, monitoring and response control.
Why this seat is open
The breach showed that local cyber reporting overstated basic control health. Immediate leadership change was necessary to preserve confidence in the investigation. A nine-month interim can close causal exposure and qualify the deputy without turning incident response into a permanent parallel hierarchy.
What you will own
- Preserve forensic evidence and reconstruct identity, endpoint, network and data events across the compromise window.
- Decide containment boundaries with operations leaders using explicit safety, continuity and adversary-persistence evidence.
- Remove dormant privilege and establish vaulting, time-bound elevation, session recording and owner recertification.
- Test segmentation between corporate engineering and operational-technology environments with safe agreed protocols.
- Restore log coverage and retention for critical assets, proving search and alert behaviour through replay.
- Run severe incident exercises that test command, notification, legal preservation and asset-safety decisions.
- Qualify the internal deputy against observed command performance and transfer the residual-risk register.
Candidate qualifications
- Eighteen-plus years in cybersecurity with incident-command responsibility in energy, industrial or critical infrastructure.
- Led containment and recovery from privileged credential compromise involving engineering or operational technology.
- Deep expertise in identity security, segmentation, detection engineering, forensic preservation and crisis governance.
- Ability to make containment choices jointly with safety-critical operations rather than applying enterprise IT assumptions blindly.
- Experience reporting material incidents and residual exposure to boards, counsel and regulated stakeholders.
- Demonstrated development of an internal security leader through realistic command simulations.
Non-negotiables
- Available in Hyderabad within ten days and for round-the-clock escalation during containment.
- No relationship with the incident-response vendor or implicated identity providers.
- Prepared to preserve adverse evidence and support statutory notification decisions transparently.
- Accepts a fixed nine-month handover to the qualified internal deputy.
- 49 words maximum. What is your earliest arrival in Hyderabad, and can you join the incident rota immediately?
- 49 words maximum. Which privileged-access compromise did you contain, and how did you prove persistence was removed?
- 49 words maximum. Describe an OT containment decision where safety constrained the fastest cyber response.
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.