Confidential mandate
Interim Chief Information Security Officer — Wealth Platform Breach
Urgent / Replacement
A privileged-access breach has displaced the security chief, requiring an interim CISO to contain exposure, prove client-asset resilience and install a board-tested cyber control model.
The mandate
Compromised privileged credentials enabled unauthorised access to a production support environment, and the CISO departed after the board questioned delayed escalation. Client assets were not moved, but log gaps and third-party administration paths prevent a complete assurance statement.
The interim must join within ten days for a ten-month assignment spanning forensic closure, control rebuild and two red-team cycles. The permanent CISO search begins once incident facts are agreed; extension is possible only for regulatory clearance or successor notice.
Handover is achieved when incident scope is independently accepted, privileged identities are vaulted and recertified, high-risk third-party paths are removed or controlled, two adversarial tests meet the board threshold, and the successor has led one incident simulation. Residual findings must carry owners and funded dates.
The interim may isolate systems, revoke access, stop releases on security grounds and allocate ₹10 crore within the incident reserve. Public statements, breach notification, customer compensation above ₹5 crore, supplier termination above ₹15 crore and permanent security hires require Legal, CEO or board approval according to the decision matrix.
Trading strategy, general technology architecture and replacement of the wealth product are outside scope. Fraud investigations into individual clients and employee disciplinary actions remain with their designated functions.
Why this seat is open
The prior escalation failure undermined confidence in the existing security leadership chain. Internal candidates own controls now being forensically tested and cannot sign independent closure. An interim CISO gives the board immediate executive command while a permanent appointment proceeds on verified facts.
What you will own
- Establish the authoritative incident timeline and approve forensic conclusions against preserved logs, cloud evidence and third-party records.
- Revoke, reissue and recertify every privileged path using role, duration, session recording and break-glass criteria.
- Decide which product releases and supplier connections remain blocked until compensating controls are proven.
- Rebuild cyber reporting around exploitable paths, detection coverage, containment speed and client-asset consequence.
- Commission two independent red-team exercises and reject closure where tests rely on excluded production conditions.
- Direct a board simulation covering detection, asset protection, regulatory decisions, client communication and supplier failure.
- Hand over the incident archive, risk acceptances, control coverage, vendor claims, team assessment and next test calendar.
Candidate qualifications
- Held CISO or enterprise security director authority in wealth, capital markets, banking or another regulated digital platform.
- Commanded a privileged-access or cloud breach from containment through board and regulatory closure.
- Designed identity controls covering administrators, vendors, service accounts and emergency access.
- Exercised independent release-stop authority while balancing client availability and market obligations.
- Directed forensic, red-team and security-engineering providers without surrendering executive accountability.
- Understands Indian securities, cyber incident and outsourced-technology governance expectations.
Non-negotiables
- Able to assume Pune incident command within ten calendar days.
- No current relationship with the forensic firm, cloud provider or managed security supplier.
- Will disclose all material incidents managed and any notification challenged by a regulator.
- Must be willing to stop production access despite revenue or market pressure.
- 49 words maximum. Confirm your earliest start and any current client creating a wealth-sector conflict.
- 49 words maximum. Describe a privileged-access breach you closed and the evidence used to bound its scope.
- 49 words maximum. Which condition would prevent you from declaring containment complete?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.