Confidential mandate
OT Segmentation and Safe Remote-Access Choices — Cyber Risk Adviser
Planned Hiring / New
OT Segmentation and Safe Remote-Access Choices mandate in Mumbai, India · Critical Infrastructure Technology
Advise nine months of industrial cyber-risk choices, challenging segmentation and remote-access assumptions through a technical risk cadence while retaining plant safety, production change and security execution authority with authorised internal owners.
The mandate
Industrial security sponsors repeatedly ask which segmentation and remote-access changes reduce risk without undermining safe maintenance or production support. The adviser will challenge those tradeoffs using the supplied operating context. The purpose is a defensible choice between risk alternatives, not a generic reference architecture or a standing authority to approve plant changes.
Four monthly days cover an architecture challenge, safe-access evidence workshop, risk committee attendance and preparation. Committee participation is included; complete ad-hoc questions receive an initial assessment within four business days. Mumbai is the base for hybrid sessions, with any industrial observation governed by customer or plant access permissions and scheduled within the agreed allocation.
The term extends from 19 October 2026 to 18 July 2027. The industrial risk chair evaluates renewal using the quality of challenged decisions and the internal team's ability to maintain the risk comparison. Detailed implementation design, active assessment or live incident support requires a separately scoped engagement, not unrestricted extension of the advisory calendar.
For segmentation and safe-access advice, there is no line authority and no executive responsibility. Plant owners retain production and safety decisions; security executives retain risk acceptance and authorised engineering teams implement approved changes. Advice must identify evidence limitations and specialist reliance, especially where the consequences of restricting connectivity cannot be established from security documentation alone.
Non-competing advisory work may coexist if confidentiality and time are protected. A remote-access supplier, industrial integrator bidder or competing operator involved in the same design creates a conflict requiring disclosure. Vendor commissions, deployment revenue and offensive testing are excluded, allowing the adviser to recommend a staged or deferred change without a commercial interest in immediate implementation.
What you will own
- Challenge segmentation proposals against authorised operating dependencies, identifying where an apparently cleaner boundary would remove maintenance, recovery or safety-relevant communication without an agreed alternative capability.
- Probe remote-access cases for purpose, approver, time limitation and evidence retention, distinguishing legitimate support from persistent connectivity that lacks a continuing accountable business justification.
- Test claimed industrial risk reduction against visibility and recovery assumptions, refusing certainty where the supplied architecture or operational evidence cannot support the proposed conclusion.
- Shape staged-change options with hold conditions and specialist validation, preserving the distinction between advisory risk preference and production engineering approval before implementation proceeds.
- Press sponsors to explain fallback and support arrangements when connectivity is restricted, ensuring the committee sees residual operational risk rather than only the cyber-security benefit.
- Review the committee's recorded response and reconsideration triggers, retaining plant and security acceptance boundaries after a preferred segmentation or safe-access route is adopted.
Candidate qualifications
- Show senior OT/ICS architecture or industrial cyber-risk advice with a decision personally influenced. Provide a case where support dependencies changed the recommended segmentation or access route. Candidates must understand industrial consequences without claiming plant-operating authority, and must identify the engineering or safety expertise retained by the sponsoring organisation.
- Demonstrate practical knowledge of recognised OT security principles, industrial asset visibility and safe remote-access governance. Explain an evidence gap that prevented a firm risk conclusion. Certifications and framework fluency are useful, but practical contextual judgement matters more than presenting a standard architecture without testing its operating and recovery assumptions.
- Evidence independent advisory work in which a preferred security change was staged, deferred or rejected. Show the alternatives, residual risks and management response retained in the record. The adviser must remain useful without directing implementation and cannot sell a compliance guarantee, formal safety opinion or unrestricted testing permission through this bounded retainer.
- Establish senior industrial cyber-risk judgement through a segmentation or access recommendation whose maintenance and recovery dependencies were validated with engineering, alongside a reliable four-day monthly allocation. Disclose vendor, integrator and same-design interests, including commissions or implementation remuneration. Independence is essential because a defensible recommendation may preserve an existing access route temporarily while safer dependencies are established.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 7 October 2026. Mandate reference PCT-ADV-2026-IND-30.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.