Confidential mandate
Cyber Fusion and Splunk Detection Engineering Leader
Urgent / Replacement
Cyber Fusion and Splunk Detection Engineering Leader mandate in Singapore · Cross-Border Payments Technology
After a material intrusion was escalated late, a regional payments platform needs an executive cyber-operations leader to rebuild Splunk detection engineering, unify response authority and complete a controlled ten-month succession.
The mandate
The regional head of cyber operations was dismissed after an intrusion crossed identity, endpoint and payment telemetry for eleven hours before receiving severity-one treatment. Shift teams preserved service, but detection ownership is fragmented, Splunk content lacks dependable testing lineage and country responders still negotiate authority during live events.
An interim leader must take the Singapore seat within two weeks for a ten-month fixed term. A permanent regional appointment will be selected by month seven, allowing a six-week overlap; the temporary executive remains accountable until the successor has commanded a supervised regional exercise.
Handover is achieved when critical payment journeys have evidence-backed detection coverage, priority correlation searches run through versioned test-and-release controls, two cross-border simulations meet agreed containment thresholds, and the incoming leader has accepted the residual blind-spot register. Closing tickets or increasing alert volume will not qualify as completion.
The interim may declare regional incidents, isolate compromised services within pre-approved customer-continuity limits, change on-call design, retire ineffective detections and redirect the existing tooling budget. Board consent is required for platform replacement, spend above SGD 3 million or permanent leadership hires; the assignment cannot alter payment-risk appetite or customer restitution policy.
Identity-platform reimplementation, enterprise network redesign and privacy-policy ownership remain outside scope. The focus is the fusion centre's operating model, Splunk detection lifecycle, threat-led coverage and decisive coordination across the three regional hubs.
Why this seat is open
A forensic review found that the missed escalation reflected operating design, not one analyst's error. The former leader's departure left the CISO carrying live-response decisions while also answering regulators and customers. The board has chosen a finite recovery window before installing a permanent regional head into a tested command system.
What you will own
- Redraw severity and command thresholds so every regional shift knows who may isolate a service, notify a market and escalate customer impact.
- Establish detection-as-code controls for Splunk content, including peer review, synthetic tests, version history, promotion evidence and rollback ownership.
- Rank payment attack paths against telemetry coverage and approve a funded closure plan for the blind spots carrying the highest plausible loss.
- Replace volume-led SOC reporting with measures for detection latency, useful fidelity, containment speed, evidence integrity and recurring control failure.
- Command two multi-jurisdiction simulations involving fraud, technology, communications, legal and country executives, then enforce closure of failed actions.
- Decide the future split between internal analysts, managed providers and specialist responders using capability evidence, not contractual convenience.
- Hand the successor an exercised playbook, certified on-call roster, content backlog, supplier scorecard and personally explained risk acceptance log.
Candidate qualifications
- Held regional cyber-operations, incident-response or security-engineering authority in a regulated payments, banking or critical digital-services environment.
- Personally commanded a material intrusion spanning identity and endpoint telemetry and can evidence the containment decisions taken under service pressure.
- Rebuilt Splunk detection engineering through source control, automated testing, content promotion and measurable ATT&CK-informed coverage.
- Managed follow-the-sun analysts and responders across at least three jurisdictions with explicit legal, privacy and notification boundaries.
- Restructured a hybrid SOC involving employees and managed providers while preserving live monitoring and forensic continuity.
- Presented operational cyber risk and residual detection gaps directly to a board committee, regulator or critical-service authority.
Non-negotiables
- Available to assume incident command in Singapore within fourteen days and remain on site throughout the first eight weeks.
- Will travel monthly to Kuala Lumpur or Sydney and participate in out-of-hours severity-one command when rostered.
- Has hands-on governance depth in Splunk detection content, not only general cyber programme leadership.
- Carries no concurrent executive incident-response assignment or undisclosed interest in the incumbent managed-security provider.
- 49 words maximum. State your notice position and the earliest date you can take twenty-four-hour regional escalation accountability in Singapore.
- 49 words maximum. Describe one Splunk detection you withdrew or rebuilt, the evidence showing it failed, and the operational result after release.
- 49 words maximum. During your most complex cross-border incident, which decision could only you make and how quickly did you make it?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.