Confidential mandate
Clearing and Payments Cyber-Risk Appetite Adviser
Planned Hiring / New
Clearing and Payments Cyber-Risk Appetite Adviser mandate in Gandhinagar, India · Financial Market Infrastructure
A financial-services risk committee needs independent security challenge of clearing and payment-service risk appetite; a twelve-month adviser will test assurance sufficiency and resilience tradeoffs while executives retain service decisions and regulatory accountability.
The mandate
The committee's standing question is what cyber exposure can be accepted for critical clearing and payment services when resilience evidence is incomplete and service interruption has wider consequences. A low count of open findings does not necessarily mean the dependency risk is understood. The adviser will challenge appetite and assurance sufficiency, helping the committee connect technical evidence to a defensible service-risk choice.
Four monthly days support critical-service assurance review, interviews with security and market-operation owners and the written appetite challenge. The retainer includes the board risk session. Clearing and payment-service evidence must be supplied a week before that discussion so exclusions can be tested; an off-cycle risk query is acknowledged within one business day and receives a reasoned view within three if the required records are present. The adviser is not providing live incident command or continuous regulatory liaison.
The twelve-month appetite-review term begins on 19 October 2026. Renewal is a risk committee chair decision based on unresolved service-risk questions and the adviser's independence. Gandhinagar is the India location, combining remote preparation and planned workshops. The adviser should strengthen the committee's ability to interrogate assurance after the term, not become an unofficial standing approver of every security exception.
Critical-service advice entails no line authority over security, technology or market operations. The adviser bears no executive responsibility for risk acceptance, service suspension or regulatory compliance. The committee and appointed officers retain their decisions. Recommendations must distinguish the risk that has been tested from the condition merely assumed, and describe the evidence needed before appetite can be credibly increased.
Concurrent advisory work is allowed outside competing market services and reviewed critical providers. Advising a provider whose assurance is under review, holding a material investment interest or preparing the same appetite paper under a separate fee creates a conflict. Before clearing or payment-service papers are released, the adviser and chair agree provider-specific disclosures, restricted subjects and any necessary recusal. The adviser must not reuse confidential resilience assumptions to support another provider's assurance or commercial bid.
What you will own
- Test cyber-risk appetite proposals against critical-service dependencies and demonstrated controls, identifying where a numerical tolerance has no clear operational or evidential meaning.
- Question assurance papers on scope, exclusions and independence before the committee treats a completed assessment as evidence that market-service resilience is acceptable.
- Shape risk options showing the consequences of restricting access, accepting an exception or investing in recovery capability, with operational and regulatory decision dependencies visible.
- Press security and resilience owners to distinguish tested restoration from assumptions about counterparties, identity services or data integrity not exercised in the scenario.
- Challenge exception expiry and residual-risk governance so accepted conditions receive revisit triggers rather than becoming permanent through repeated administrative renewal.
- Recommend committee evidence questions and escalation criteria that preserve executive service and compliance accountability while improving the quality of cyber-risk acceptance decisions.
Candidate qualifications
- Evidence twenty-two-plus years in security or technology with senior CISO, enterprise risk or equivalent financial-services leadership. Present a risk appetite or assurance recommendation you challenged, the evidence limitation identified and the decision influenced. Chief-title familiarity must be supported by actual committee judgement and verifiable career scope.
- Show deep security governance and resilience understanding for critical financial services, including assurance scope, service dependencies and executive escalation. Explain a case where completed testing did not justify the risk conclusion management wanted, and describe the additional evidence or restricted acceptance you recommended.
- Bring experience translating technical exposure into board-usable options without overstating certainty or assuming operational trading, clearing or regulatory powers. Provide a paper that distinguished evidence, assumption and residual risk, identifying which specialists or appointed officers supplied conclusions outside your competence.
- Prove independent advisory conduct through a provider, investment or concurrent-assurance conflict handled in practice. Disclose current financial-service and critical-provider relationships and explain your capacity for the specified monthly review. The role requires rigorous challenge and clear responsibility boundaries, not authority to suspend service, accept executive risk or issue a regulatory compliance opinion.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 10 October 2026. Mandate reference PCT-ADV-2026-IND-55.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.