Confidential mandate
Telecom Signalling Abuse Defence Leader — Mobile Network
Urgent / Replacement
Telecom Signalling Abuse Defence Leader mandate in Nairobi, Kenya · Mobile Telecommunications
After coordinated roaming fraud and subscriber-location probing, a Nairobi operator needs executive signalling-defence leadership to contain abuse, redesign interconnect controls and transfer sustained command within eleven months.
The mandate
The signalling-security head left during investigation of coordinated roaming fraud, silent subscriber-location queries and one-time-password interception attempts spanning several international partners. Firewall teams tuned rules independently from fraud analysts, roaming commercial managers resisted partner restrictions, and privacy investigators cannot connect anomalous messages to customer harm. The interim leader must establish one command model without destabilising emergency roaming, remittance traffic or legitimate low-volume partners.
The eleven-month window starts with sixty days of attack-path containment, partner scoring and historic exposure reconstruction. Months three through seven rebuild SS7 and Diameter policy, connect signalling telemetry to fraud decisions and exercise partner isolation. The final four months prove 5G service-based-interface readiness, appoint a permanent leader and sustain control performance through two major travel peaks. A two-month extension may be approved only for successor notice or an unresolved regulator-directed action.
Handover is achieved when priority abuse cases have rehearsed response paths, partner exceptions carry commercial and risk owners, detection-to-restriction time meets thresholds for twelve consecutive weeks, and privacy can trace material probes to an assessed population. The successor must lead a live interconnect escalation, explain residual blind spots to the risk committee and own the next roaming review. Open fraud losses must be honestly transferred rather than rebased out of the success measure.
The leader may direct signalling-rule priorities, convene network and fraud response, quarantine a roaming relation for up to twenty-four hours, approve laboratory simulations and commit KES 350 million within the authorised remediation envelope. Permanent partner termination, customer reimbursement, lawful-intercept configuration, tariff decisions and core-network replacement remain with named executives. Emergency restrictions affecting national-service obligations require Chief Network Officer concurrence.
Outside scope are taking ownership of the wider fraud profit-and-loss account, attributing activity to a state, redesigning the full 5G core, negotiating wholesale roaming prices or acting as Data Protection Officer. The mandate covers abuse evidence and defensive decision flow across signalling trust boundaries. Criminal referrals, sanctions conclusions and customer notification remain accountable legal, privacy and regulatory decisions supported by the leader’s facts.
Why this seat is open
Signalling abuse crosses network engineering, partner economics, fraud loss and individual privacy faster than the current functions can coordinate. Aggressive filtering can interrupt legitimate roaming, while weak exceptions permit scalable account takeover and surveillance. A temporary executive with network credibility can make bounded restrictions now and leave an operating command that survives commercial pressure.
What you will own
- Reconstruct abuse pathways across SS7, Diameter, roaming hubs, SMS routing, subscriber data, fraud events and partner identities.
- Direct urgent filtering and rate controls using message context, subscriber state, partner history and false-positive impact.
- Unite network, fraud, privacy and commercial teams around severity, containment authority, evidence preservation and customer-harm decisions.
- Establish partner trust tiers, exception expiry, reciprocal testing, escalation contacts and defensible criteria for temporary isolation.
- Connect signalling events to account takeover, location probing, OTP interception, SIM activity and monetisation indicators.
- Exercise compromised-partner, travel-peak and multi-protocol scenarios including transition risks between legacy signalling and 5G interfaces.
- Hand over dashboards, playbooks, commercial risk decisions, regulator commitments, detection backlog and a witnessed executive response.
Candidate qualifications
- Led signalling security, roaming assurance or mobile-core fraud defence for a large multi-partner telecommunications network.
- Can evidence containment of SS7 or Diameter abuse while preserving legitimate roaming and emergency-service obligations.
- Understands signalling firewalls, roaming hubs, subscriber context, fraud correlation and privacy implications of location requests.
- Has challenged a commercially important interconnect partner using reproducible evidence and proportionate restriction criteria.
- Integrated network operations, fraud, privacy, wholesale commercial and regulatory teams during a live customer-impacting event.
- Developed a successor able to defend technical rules and commercial exceptions before executive or regulatory stakeholders.
Non-negotiables
- Will lead from the Nairobi operations centre and attend all published regional partner sessions.
- Has personally made a high-consequence signalling restriction decision under incomplete evidence and service pressure.
- Accepts no unilateral authority over lawful intercept, permanent partner termination, customer redress or public attribution.
- Will disclose operator, roaming-hub, firewall-vendor and fraud-platform relationships before appointment.
- 49 words maximum. Which signalling pattern justified your most consequential partner restriction, and what protected legitimate traffic?
- 49 words maximum. How did you connect protocol evidence to a defensible estimate of customer harm?
- 49 words maximum. What must a permanent leader demonstrate before inheriting your roaming-abuse command?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.