Confidential mandate

Enterprise Secrets Governance Architecture Director — Digital Banking

Planned Hiring / New

Enterprise Secrets Governance Architecture Director mandate in Hong Kong · Digital Banking

A Hong Kong digital bank needs an independent director to replace fragmented secrets handling with an accepted ownership, issuance and recovery architecture across four months.

The mandate

Application passwords, API keys, signing material and database credentials are spread across repositories, pipelines, configuration stores and three vault products. Inventory scans find strings but cannot identify business ownership, active use or the consequence of rotation. The defined problem is to create one governable secrets architecture that reduces persistence and blast radius without forcing a risky simultaneous migration.

The deliverables are a verified secret-class inventory, ownership model, approved issuance patterns, vault and workload boundaries, automated rotation designs, exception workflow, emergency recovery procedure and migration roadmap. Artefacts must distinguish secrets from public identifiers and cryptographic keys, identify systems unable to rotate safely and connect every exception to a named service outcome and expiry.

Milestone one on 9 October 2026 delivers the reconciled inventory and exposure tiers. Milestone two on 6 November provides approved target patterns and ownership decisions; milestone three on 11 December completes rotations for two critical service chains and one legacy application; final acceptance on 15 January 2027 requires recovery tests, migration waves, engineering training and transferred governance.

The CISO, platform director, SRE head and technology-risk lead accept delivery when sampled secrets trace to owners and consumers, rotation completes without unknown outage, revoked credentials fail as expected and emergency recovery preserves dual control. Client engineers must onboard a new service and retire an exception unaided, while residual plaintext and non-rotatable secrets remain visible with approved treatment.

The client provides repository scanning, vault metadata, pipeline configuration, service maps, test environments and authorised owners, resolving access questions within two working days. The consultant cannot handle production secret values, approve application downtime, select a commercial vault or accept technology risk; segregated test credentials must support all demonstrations and authorised staff execute production changes.

Why this is external work

Each platform team is invested in its own vault and measures success by stored-object counts rather than reduced exposure. Application owners fear rotation because dependencies remain undocumented. An independent specialist can impose comparable patterns and acceptance tests while avoiding a premature platform contest or open-ended credential-cleanup programme.

What you will own

  • Classify passwords, tokens, API credentials, signing material and encryption keys by purpose, consumer, persistence and compromise impact.
  • Reconcile scanner results to runtime use, repository history, vault metadata and accountable service ownership.
  • Define issuance, retrieval, caching, rotation, revocation and recovery patterns for human, workload and pipeline consumers.
  • Design vault trust boundaries, administrative separation, regional recovery and audit evidence without creating a universal dependency.
  • Pilot automatic rotation through critical service chains, testing rollback, stale consumer detection and downstream authentication failure.
  • Establish exceptions with technical constraint, compensating restriction, monitoring, business sponsor, expiry and funded retirement action.
  • Transfer architecture decisions, tested patterns, migration waves and exposure indicators through client-operated onboarding and retirement.

Candidate qualifications

  • Designed enterprise secrets governance across cloud-native, pipeline and legacy application estates in regulated financial services.
  • Can evidence high-risk credential rotation where undocumented consumers and availability constraints were discovered during execution.
  • Distinguished secrets, certificates and cryptographic keys while integrating their ownership and incident-response dependencies.
  • Built safe automated rotation, stale-consumer detection, revocation and break-glass recovery with measured production outcomes.
  • Governed multiple vault technologies without allowing product preference to substitute for service and trust requirements.
  • Delivered operator-owned architecture and exception retirement after a finite consulting engagement without accessing production secret values.

Non-negotiables

  • Available for every Hong Kong, Shenzhen and Singapore milestone and production-change review.
  • Independent of vault, cloud, identity and DevSecOps vendors that may be evaluated.
  • Will not request, retain or display production secret values during the engagement.
  • Has director or principal-level secrets architecture authority beyond scanning or vault administration.
  1. 49 words maximum. Which evidence distinguishes an active secret from an alarming but unused scanner finding?
  2. 49 words maximum. Describe a rotation that exposed an undocumented consumer and how you recovered safely.
  3. 49 words maximum. What test proves emergency secrets recovery preserves separation of duties?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.