Confidential mandate
Anycast and Authoritative DNS Recovery Leader
Urgent / Unplanned
Anycast and Authoritative DNS Recovery Leader mandate in Sydney, Australia · Global Travel Marketplace
A global travel marketplace needs a ten-month executive after a route leak and unsafe DNS-signing response made healthy booking services unreachable in several customer regions.
The mandate
A provider route leak drew Anycast traffic into saturated edges while an emergency authoritative-DNS change introduced inconsistent signed responses across resolvers. Booking applications remained healthy in origin regions, masking the customer impact until contact centres escalated. The internet-edge director was dismissed after review found untested provider withdrawals, fragile signing custody and no shared command between network, DNS and application reliability teams.
The interim must start in Sydney within two weeks and lead for ten months. The permanent search opens after route withdrawal and key-transition controls complete their first witnessed global exercise, expected during month five. The successor will overlap for five weeks and must command one traffic evacuation, one DNS signing ceremony and the final cross-provider incident simulation before transfer.
Handover requires routing policy and origin authority to be versioned and independently monitored; resolver-visible DNS consistency to remain inside defined propagation envelopes; key rollover and provider isolation to pass two global drills; customer impact to be observable by market and journey; and every emergency control to have tested rollback, named ownership and successor acceptance. Green origin health will not count as service recovery.
The interim may withdraw advertisements, isolate an edge provider, stop DNS changes, rotate emergency roles, set global traffic priorities and approve up to AUD 16 million within the agreed recovery. New network contracts, permanent hires, domain portfolio changes, customer compensation and single commitments above AUD 4 million require council approval. The seat cannot relax domain-security policy or suppress mandatory incident reporting.
Application performance engineering, travel-supply integrations, consumer product redesign and general corporate-network transformation are expressly excluded. The mandate covers public routing, authoritative DNS, signing custody, edge-provider failover, customer-path observability, incident command and the organisation that operates those shared dependencies.
Why this seat is open
The incident crossed two teams that each restored its own component while customers still could not resolve or reach the service. Dismissal of the director left provider concentration and signing authority without a credible executive owner. Temporary leadership is needed to exercise failures at internet scale and transfer permanent command before the next seasonal booking peak.
What you will own
- Reconstruct route propagation, traffic attraction, resolver behaviour, DNS answers, signing changes, edge saturation and customer failures by geography.
- Define authoritative ownership for prefixes, route objects, origin validation, zones, keys, delegation, emergency change and provider withdrawal.
- Decide Anycast topology, advertisement policy, health inputs, dampening, capacity headroom and market-specific degradation rules.
- Rebuild signing ceremonies, rollover timing, negative-cache handling, propagation checks and break-glass access with independent evidence.
- Install outside-in signals for resolution, reachability, route path, answer consistency, certificate validity and booking-journey success.
- Command exercises involving route leaks, hijack indicators, provider black holes, bad DNS signatures, stale delegation and control-system loss.
- Transfer maps, keys, provider obligations, exercise results, exceptions and command authorities through successor-led global changes.
Candidate qualifications
- Held senior operational authority for Anycast, authoritative DNS or internet-edge services supporting a global consumer or transaction platform.
- Commanded an incident involving BGP propagation, route leak, DNS signing, resolver inconsistency or interacting failures across those layers.
- Designed provider evacuation and key lifecycle controls that could be executed safely under incomplete global visibility.
- Built outside-in observability linking routes and DNS answers to real customer journeys across markets.
- Negotiated resilience obligations with transit, DNS and edge providers while retaining credible independent measurement.
- Transferred privileged internet-edge command to a permanent leader through witnessed changes and incident simulations.
Non-negotiables
- Can begin in Sydney within two weeks and travel monthly to a named global network or command hub.
- Will accept exclusive executive responsibility and join continuous escalation for routing, DNS and edge events.
- Brings hands-on authority over public BGP and authoritative DNS; application SRE or enterprise networking alone is insufficient.
- Must disclose current interests involving transit, DNS, CDN, DDoS, registrar and internet-measurement providers.
- 49 words maximum. State your earliest Sydney start and the largest resolver or routing population affected under your command.
- 49 words maximum. Describe an incident where healthy origins concealed a DNS or Anycast failure experienced by customers.
- 49 words maximum. Which outside-in signal would make you withdraw a provider route before internal dashboards turn red?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.