Confidential mandate
Manufacturing Infrastructure Security and Recovery-Evidence Consultant
Planned Hiring / New
Manufacturing Infrastructure Security and Recovery-Evidence Consultant mandate in Bengaluru, India · Manufacturing
Manufacturing information services need a defensible security-posture and recovery evidence package; this six-month consulting engagement maps dependencies, tests control claims and transfers accepted artifacts without redesigning plant safety systems or operating incident response.
The mandate
The defined problem is an unverified relationship between manufacturing information-service controls and the recovery capability claimed for critical workflows. Policies and backup records exist, but they do not demonstrate that required identities, configurations and application dependencies can be restored together. The consultant will deliver an Infrastructure Security Posture and Recovery-Evidence Pack using a controlled, agreed test perimeter.
The six-month project begins on 19 October 2026 at four days a week. Bengaluru workshops establish service dependencies and safety boundaries, followed by scheduled India site evidence reviews and remote documentation work. The deliverable includes a dependency catalogue, control-evidence matrix, prioritised gap disposition and witnessed recovery proof for selected information services. Production-system testing requires the separate operational approval route.
Milestone one on 18 December 2026 provides an accepted service-dependency inventory and a baseline of substantiated versus unproven control claims. Milestone two, due 18 February 2027, is a tested control matrix, recovery-test design and corrected evidence for prioritised gaps. Milestone three on 18 April 2027 contains witnessed recovery results, approved residual issues and retained-team replay of the evidence refresh.
The security sponsor and infrastructure head accept the pack jointly, with manufacturing application owners confirming operational relevance. Selected recovery tests must meet approved timing and completeness criteria, preserve access restrictions and identify dependencies not exercised. Acceptance cannot be based on a backup-success report alone. Any residual untested production condition must be explicitly recorded and accepted by its authorised operational owner.
The sponsor supplies inventories, configuration and access records, isolated test capacity and named reviewers. The consultant will not replace the CISO, run incident response, certify product security or alter safety-critical plant systems. Remediation implementation beyond agreed evidence corrections needs a change order. The engagement closes on accepted proof and transfer, not a promise that all future manufacturing interruptions are eliminated.
What you will own
- Catalogue critical information-service dependencies, linking applications, identity, configuration and recovery prerequisites to the manufacturing workflows they support rather than to a generic asset list.
- Evaluate control claims against observable records and tests, marking evidence limitations separately from confirmed deficiencies so prioritisation remains defensible and proportionate.
- Design approved recovery scenarios in isolated or otherwise authorised environments, documenting safety restrictions and dependencies deliberately excluded from the test perimeter.
- Execute witnessed tests of selected services, recording restored functionality, access boundaries and timing against criteria signed by infrastructure and application owners.
- Produce a gap-disposition register separating evidence corrections, required remediation and residual conditions needing executive or operational risk acceptance before project closure.
- Transfer the dependency catalogue and evidence-refresh method through a retained-team replay, ensuring owners can update proof after a configuration or service dependency changes.
Candidate qualifications
- Demonstrate senior information-security or infrastructure assurance delivery supported by verifiable career and project evidence. Present a recovery or posture engagement you personally led, the dependency that invalidated an initial claim and the test evidence accepted by operational owners. A security-chief title alone is not proof of this hands-on assurance method.
- Show competence in identity, infrastructure configuration, backup and service recovery controls relevant to manufacturing information systems. Explain how you distinguished restored data from restored operational capability and preserved access security during testing. Candidates must recognise that production safety and specialised OT engineering require independent qualified authority.
- Bring structured assurance judgement that separates absent evidence, ineffective control and an untested condition. Provide a gap prioritisation example with the economic or operational reason for its ranking, and describe how you avoided presenting a limited test as comprehensive resilience certification.
- Prove fixed-scope delivery with controlled test approval, secure data handling and retained-owner transfer. Evidence should include accepted criteria, witnessed outcomes and a refresh test after a changed dependency. The role requires rigorous documentation and practical testing, not ownership of ongoing incident response or authority to redesign every manufacturing security control.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 14 October 2026. Mandate reference PCT-CON-2026-IND-48.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.