Confidential mandate

Director, Offensive-Security Product and Practice — Leadership Bridge

Urgent / Replacement

Director, Offensive-Security Product and Practice mandate in Bengaluru, India · Cybersecurity Products and Services

A nine-month bridge director role restores practice accountability for offensive-security delivery, safeguards assurance integrity and transfers a tested product and delivery cycle to the permanent director.

The mandate

Delivery capacity and security-product priorities are being reconciled. Teams can execute assessments, but commercial promises, testing authorisation and product backlog choices need a consistent practice owner. The bridge must hold director-level product and P&L decisions without confusing offensive expertise with permission to test outside agreed boundaries.

The proposed term starts on 19 October 2026 for nine months in Bengaluru, with five-day availability and scheduled India practice and customer-governance reviews. A permanent director search runs concurrently. The successor participates in the final delivery and product cycles, and any extension requires a written practice-transfer condition rather than a promise to remain until every sales opportunity is closed.

Handover requires an accepted practice economics view, a controlled product roadmap and delivery procedures that link testing scope to written authorisation. Two assessment cycles must demonstrate quality review and reproducible evidence, including how findings become useful defensive action. The successor must lead a roadmap and capacity review and receive unresolved scope, quality and product-risk issues with their ownership and decisions.

The director may sequence product and practice work, approve budgeted delivery staffing and enforce assessment quality within existing delegation. New product investment, permanent restructuring, contract commitments above ₹15 lakh outside plan and deviations from authorised test scope require executive approval. No title grants authority to exploit a third-party system; customer and asset-owner consent remains a prerequisite for each engagement.

The bridge excludes enterprise CISO risk acceptance for customers, unrestricted live offensive operations and a complete commercial strategy overhaul. It includes practical practice leadership spanning product innovation, red or purple-team quality and credible commercial delivery. The leader must protect the independence of security findings when sales pressure favours a reassuring result, leaving a practice that can sustain both economics and assurance integrity.

What you will own

  • Approve a practice capacity and economics view linking authorised delivery commitments, specialist effort and quality review before commercial promises are treated as readily deliverable revenue.
  • Set product-roadmap priorities using customer evidence and security value, escalating new investment rather than letting assessment anecdotes alone determine the next feature commitment.
  • Resolve testing scope and quality exceptions through written authorisation and executive routes, refusing delivery changes that exceed asset-owner consent or agreed safety boundaries.
  • Direct red and purple-team review standards connecting evidence, exploit conditions and defensive usefulness without presenting a single finding as proof of comprehensive security.
  • Challenge commercial incentives that could weaken assessment independence, preserving finding quality and transparent limitations even when a reassuring result would make renewal easier.
  • Transfer the practice decision cycle through a successor-led roadmap and delivery review, including unresolved authorisation, product-risk and capacity issues with explicit ownership.

Candidate qualifications

  • Demonstrate at least ten years in cybersecurity with genuine director or head-of-practice responsibility across offensive-security delivery and product or commercial priorities. Describe the decisions you personally held, the practice outcome and your delegated limits. Provide a capacity or quality escalation showing how you preserved written test consent while deciding commercial priorities within the practice's approved staffing and investment envelope.
  • Show substantial authorised red or purple-team experience and the ability to translate testing evidence into defensive action. Provide a case where scope or safety constraints changed your method, explaining asset-owner approval, evidence quality and how the final result remained useful without unauthorised expansion.
  • Bring security-product and practice economics judgement, including prioritisation, delivery capacity and quality costs. Describe a feature or commercial promise you deferred because evidence or specialist capacity was insufficient, and show the effect on customer value and practice performance. AI or DevSecOps experience should be supported by actual outcomes rather than broad innovation claims.
  • Prove leadership of security specialists and successful transfer of a practice or product review. Explain how you preserved independent findings under commercial pressure, handled current customer conflicts and enabled another director to reproduce decisions. Professional certifications support capability but do not substitute for authorisation discipline, accountable practice authority and the proposed nine-month availability.

Application

Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.

There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 10 October 2026. Mandate reference PCT-INT-2026-IND-58.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.