Confidential mandate
Marketplace Fraud Graph-AI Recovery Leader
Urgent / Replacement
Marketplace Fraud Graph-AI Recovery Leader mandate in Istanbul, Türkiye · Cross-Border Digital Marketplaces
After a graph-model release blocked legitimate merchants while missing coordinated mule accounts, a marketplace needs a nine-month executive to recover fraud intelligence, appeals and controlled network decisions.
The mandate
The trust-intelligence director was dismissed after a graph feature and threshold release linked unrelated merchants through recycled device and logistics identifiers, generating broad suspensions while a coordinated mule network adapted around stable features. Appeals surged, losses continued and teams cannot reproduce which graph snapshot, labels and overrides governed individual actions.
The interim must assume the Istanbul seat within sixteen days for nine months. A permanent search launches after two merchant cohorts complete the rebuilt release-and-appeals cycle, expected in month five, with five weeks reserved for the successor to observe a network case review and chair the final regional trust council.
Handover is complete when every adverse action traces to versioned graph, model, policy and human evidence; priority fraud typologies remain inside agreed loss and detection corridors for two cycles; legitimate merchant reinstatement and recurrence meet signed thresholds; two adversarial graph drills pass; and the successor accepts the residual feature and network-risk ledger.
The executive may stop models or features, change thresholds inside risk appetite, quarantine labels, redesign case routing, appoint temporary recovery leads and shift up to TRY 900 million within the authorised trust budget. Market withdrawal, customer restitution policy, permanent hires, payment-partner termination and spend above TRY 250 million per decision require council approval; appeals cannot be disabled to protect metrics.
Core payment processing, logistics-network redesign, credit underwriting and merchant acquisition are explicitly out of scope. The seat owns fraud graph data, detection and action policy, investigations interface, appeal evidence, release control and regional command without taking legal judgment or commercial account ownership.
Why this seat is open
The failed release showed that network-level detection had acquired account-closing consequences without equivalent lineage and challenge. Removing the prior leader created an urgent gap across science, operations and merchant trust during continued attacker adaptation. Temporary authority is needed to restore both loss control and defensible treatment before permanent leadership takes the platform.
What you will own
- Reconstruct the release from raw entities and edges through graph snapshot, features, labels, model score, policy threshold, investigator action and appeal outcome.
- Decide which identifiers, relationships and derived features remain usable after testing stability, collision, manipulability and disproportionate merchant impact.
- Rebuild labels around confirmed typology, investigation confidence, time leakage, appeal reversal and adversarial contamination.
- Set action tiers for observation, friction, reserve, suspension and escalation with evidence, human review, expiry and reinstatement conditions.
- Establish release gates joining back-tests, temporal holdouts, red-team networks, loss economics, merchant impact, explainability and rollback.
- Command simulations in which mule rings manipulate devices, addresses, fulfilment and account links while legitimate merchant clusters share infrastructure.
- Transfer the graph registry, typology map, action decisions, appeal evidence, supplier posture and talent assessment through a successor-led cycle.
Candidate qualifications
- Held executive or enterprise-director accountability for graph-based fraud, abuse, identity or financial-crime intelligence at platform scale.
- Recovered a model release that created harmful false positives while sophisticated actors adapted around known signals.
- Built temporal graph validation and label controls that prevented future information, appeal outcomes or unstable identity links from contaminating evidence.
- Linked fraud model decisions to operational actions, merchant economics, appeals and realised loss rather than reporting ranking metrics alone.
- Directed adversarial testing of coordinated account networks and can explain which graph feature attackers manipulated.
- Handed a recovered trust platform to permanent leadership with traceable models, decisions and challenge rights.
Non-negotiables
- Can begin in Istanbul within sixteen days, work on site initially and travel monthly to a regional fraud or merchant hub.
- Will preserve adverse-action and appeal evidence even where it exposes an overstated historical fraud result.
- Brings direct graph-fraud operating authority; generic risk analytics, cyber graphs or marketplace operations alone is insufficient.
- Must disclose current marketplace, payment, identity, fraud-vendor and merchant relationships before investigation access.
- 49 words maximum. State your earliest Istanbul start and any commitment incompatible with nine months of executive authority.
- 49 words maximum. Describe a graph feature that harmed legitimate accounts and the evidence used to repair the action policy.
- 49 words maximum. Which appeal or loss signal would make you roll back a high-performing fraud model?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.