Confidential mandate
Chief Information Security Officer — Market-Infrastructure Bridge
Urgent / Replacement
CISO mandate in Gandhinagar, India · Financial Market Infrastructure
A financial-market-infrastructure CISO role requires a twelve-month term to establish accountable governance and transfer a tested assurance cycle to the permanent security chief while operational and regulatory authorities remain intact.
The mandate
The financial-market infrastructure requires a CISO to lead its security exception and recovery-governance agenda. Operations maintain service and technology teams execute controls, but executive decisions on residual exposure and assurance priorities require a consistent security owner. The role holds the information-security seat, establishing actual decision authority rather than inferring operational trading or clearing powers from the title.
The proposed start is 19 October 2026 for twelve months, based in Gandhinagar with planned India technology and operating reviews. A permanent CISO search proceeds concurrently, with the successor involved in the final risk and recovery cycles. Extension requires a written executive and board decision defining the outstanding transfer condition; the appointment is not an informal permanent conversion route.
Handover requires a security-risk register with explicit acceptance authority, an assurance calendar tied to critical service dependencies and a tested executive escalation path. Recovery and exception claims must show their evidence and limits, including conditions not exercised. The incoming CISO must chair a risk review and replay a service-disruption scenario without relying on the interim's private judgement or undocumented relationships.
The CISO may set security standards, prioritise budgeted assurance work and direct the delegated security team. Market-service suspension, changes to settlement processes, regulatory submissions, permanent restructuring and spend above ₹40 lakh outside plan require authorised operational, regulatory or executive approval. Security escalation cannot become unilateral authority to change financial-market operating rules or accept legal compliance conclusions.
The bridge excludes trading strategy, clearing-risk quantification and routine technology delivery leadership. It covers executive information-security judgement and clear evidence of resilience for market-facing services. The leader must distinguish technical control completion from demonstrated risk reduction and help executives make timely, bounded choices without overstating the assurance available from a limited test.
What you will own
- Approve security exception decisions within delegated appetite, requiring expiry, compensating controls and explicit escalation where critical financial-service exposure exceeds the CISO's authority.
- Set assurance priorities around service dependencies and information assets, distinguishing control evidence that supports resilience from generic completion metrics with little decision value.
- Direct executive escalation rehearsals for security-driven disruption, preserving market-operation and regulatory decision routes rather than allowing a technical incident process to bypass them.
- Challenge recovery claims against witnessed restoration, access and dependency evidence, recording untested conditions and the authorised owner of accepted residual market-service risk.
- Authorize security-team capacity and operating procedures within approved budgets, escalating material investments and service tradeoffs through the existing executive and board route.
- Transfer the security governance cycle through a successor-led review and scenario replay, including unresolved exceptions, evidence limits and formal acceptance boundaries.
Candidate qualifications
- Demonstrate twenty-two or more years in technology or security with genuine CISO or equivalent executive information-security responsibility in financial services. Provide a verifiable chronology and one risk decision you personally held, identifying your delegated authority, the service consequence and the resulting executive action rather than relying on a chief title.
- Show strong security governance, enterprise incident escalation and assurance judgement relevant to critical financial services. Describe an exception whose acceptance depended on compensating controls and operational constraints, and explain how you preserved regulatory and market-operation responsibility. The role does not assume expertise in clearing-risk models or trading strategy.
- Bring evidence of resilience or recovery oversight where the test changed the executive understanding of service exposure. Explain the dependency or access condition that limited the assurance, the additional evidence required and how you avoided presenting a bounded exercise as proof against every future disruption.
- Prove leadership of security specialists and effective engagement with executives, technology and operating owners. Describe a successor or governance transfer, including the decision history another CISO could reproduce. Actual authority, career depth and current commitments will be verified; certifications or financial-sector employment alone do not establish readiness for executive security ownership.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 9 October 2026. Mandate reference PCT-INT-2026-IND-55.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.