Confidential mandate

Financial Services Cyber Defence Monitoring — Interim Director

Urgent / Replacement

Financial Services Cyber Defence Monitoring mandate in Mumbai, India · Financial Services

Bridge twelve months of cyber defence-monitoring leadership in financial services, restoring detection prioritisation, incident evidence and escalation decisions during operational transition.

The mandate

The interim will hold the cybersecurity functional seat in a financial-services context, concentrating on threat visibility and response evidence. This role is not an implied CISO appointment or permission to substitute security judgement for business decisions about customer-impacting action.

From 19 October 2026, the assignment covers twelve months and includes a permanent director search in parallel. Mumbai is the primary base, with onsite incident and governance availability and remote engineering preparation. The opening phase identifies critical visibility gaps; the final quarter requires the successor to lead detection prioritisation and a controlled incident exercise.

Handover means material detection coverage has a source-backed rationale, escalations have accountable recipients and incident evidence can be reconstructed without personal recollection. The successor must operate a simulated high-severity case, distinguish uncertainty from confirmed impact and demonstrate that logging and evidence retention support the agreed investigation method. Unresolved telemetry gaps remain visible with approved compensating measures.

The director may reprioritise existing detection work, direct SOC staff and approve budgeted security operations requests up to ₹20 lakh. Pre-authorised containment can be invoked only within a signed response matrix; actions affecting customer services, public disclosure or material business continuity require retained CISO and business approval. Permanent hiring and enterprise risk-appetite changes are not delegated.

The assignment excludes offensive testing without separate authorisation, core-platform replacement and privacy-law opinions. Specialists retain legal and regulatory interpretation. Five-day availability is priced by the day, with emergency response escalation and recovery time agreed explicitly rather than assumed unlimited. No annual salary equivalent or automatic permanent conversion is part of the interim arrangement.

What you will own

  • Establish the detection coverage register linking priority threats, required telemetry and accountable owners, exposing blind spots before presenting aggregate alert or use-case counts as assurance.
  • Decide the SOC improvement queue using financial-services exposure and evidence quality, rejecting detections whose apparent coverage cannot be demonstrated through relevant source and test events.
  • Direct incident evidence handling through controlled timelines, retention rules and access permissions, keeping confirmed facts distinct from hypotheses in executive escalation and investigation materials.
  • Approve containment within the authorised response matrix, escalating customer-impacting or business-disruptive choices to retained decision-makers rather than extending security authority during an urgent incident.
  • Challenge security engineering dependencies with operational tests, identifying telemetry and logging failures that make a detection unreliable despite its documented configuration or intended risk coverage.
  • Rehearse CISO and business escalation through a controlled case, observing response timing, uncertainty communication and approval boundaries rather than judging readiness from attendance or policy acknowledgement.
  • Transfer the director's operating decisions through successor-led coverage reviews, an incident simulation and an accepted register of unresolved visibility risks and compensating measures.

Candidate qualifications

  • Demonstrate director-level cyber defence-monitoring or equivalent functional leadership in financial services or a similarly controlled environment. Provide an incident or detection decision personally owned, identifying retained business and CISO approval. Trace the decision through telemetry confidence, analyst evidence and the response matrix, showing when monitoring leadership could act and when business-impact or containment approval had to remain with authorised executives.
  • Show practical SOC, incident-response and security engineering understanding through a redacted evidence chain or detection test that changed your judgement. Explain telemetry limitations, false confidence and the source of confirmed impact. Candidates must distinguish useful monitoring from genuine coverage, and avoid claiming that alert volume alone proves control effectiveness or regulatory compliance.
  • Evidence cybersecurity governance and risk communication supported by relevant professional certification or equivalent practice. Describe a containment choice requiring business approval and how uncertainty was recorded. Knowledge of recognised control frameworks is relevant only when applied to operational decisions; specialist legal, privacy and regulatory opinions remain with authorised professionals.
  • Provide a tested handover or readiness exercise in which another leader reconstructed evidence and used the response matrix. Explain an unresolved gap transferred honestly and a compensating measure approved by the proper owner. Show controlled telemetry access, documented incident escalation and a successor's independent distinction between a monitoring finding and an action requiring the CISO's approval.

Application

Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.

There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 8 October 2026. Mandate reference PCT-INT-2026-IND-28.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.