Confidential mandate
EVP – Risk and Resilience — Institutional Platform
Urgent / New
EVP – Risk and Resilience mandate in Pune, India · Financial Services
Establish operational-resilience ownership as an institutional platform migrates clients and processing channels across cloud, service partners and redesigned control boundaries.
The mandate
An institutional platform is migrating client service and processing from legacy channels into a combination of digital workflows, cloud services and specialist third parties. The board is creating an EVP Risk and Resilience role to establish a whole-service view and stronger first-line ownership.
The executive will lead approximately 180 risk, resilience, continuity, supplier-assurance and crisis-management employees and partners. The accountable operational and asset perimeter is about ₹7,050 crore. It covers critical institutional services, not credit or market risk leadership. The role will set resilience frameworks and provide enterprise challenge while ensuring business and technology executives remain accountable for the services they operate.
Channel migration changes the failure modes. A process may be available technically while inaccessible to clients; a cloud component may recover inside its contract while an identity dependency prevents use; a vendor may meet a generic service level while a time-bound market obligation is missed. The EVP must translate these realities into impact tolerances, scenario tests and funded remediation that the board can understand.
Why this seat is open
The appointment is new and urgent. Board review of the migration programme found inconsistent first-line ownership and no executive with authority to connect operational resilience, third-party risk and crisis response. Existing control heads can sustain current oversight, but the next migration waves should not proceed without an agreed service map and independent readiness challenge. The search is therefore running alongside immediate interim safeguards.
What you will own
- Identify important business services and set evidence-based impact tolerances reflecting client, market, legal and financial harm.
- Map the people, process, technology, data, facility and supplier dependencies needed to deliver each service through disruption.
- Require first-line service owners to fund vulnerabilities and accept residual exposure explicitly; prevent the second line from becoming programme management.
- Design severe but plausible scenarios across cyber compromise, cloud-region failure, data corruption, telecom loss and third-party insolvency.
- Integrate vendor resilience into selection, contracting, concentration decisions, testing and credible exit planning.
- Establish crisis command, executive decision rights and communications for events that cross business, technology and client boundaries.
- Challenge migration readiness and exercise stop authority where recovery, data or manual-contingency evidence is insufficient.
- Develop the 180-person risk and resilience community, reducing duplicate assessment while improving specialist depth.
The first 12 months
In the first 60 days, select the services whose interruption would create the greatest harm and reconcile existing inventories. Review recent incidents and exercises for assumptions that were never tested. Meet client-service leaders and external dependency owners, not only risk contacts. Escalate migration waves that rely on an undocumented or unexercised recovery path.
By month four, the board should approve important-service definitions, tolerances and accountable first-line owners. Dependency maps must be specific enough to reveal common points of failure. Agree a prioritised remediation portfolio with cost, owner and interim protection; do not allow every gap to be labelled equally critical.
Months five to nine should include live or production-like tests of at least four materially different scenarios, including a third party and corrupted data. Observe client and market outcomes, decision latency and the feasibility of manual workarounds. Contract changes and technical remediation should follow test evidence.
At twelve months, 100% of important services should have approved tolerances, named executives, mapped tier-one dependencies and tested response plans. At least 85% should demonstrate operation within tolerance under their principal severe scenario; all exceptions should carry funded action and expiry. Critical supplier exit plans must be practical, and repeated severe findings from earlier exercises should be eliminated.
What the board will measure
- Demonstrated service recovery within impact tolerance, including access and data integrity, not system availability alone.
- Reduction in concentrated or unowned dependencies revealed by mapping and exercises.
- First-line remediation funding and closure without inappropriate transfer of ownership to risk.
- Decision quality and communication speed during cross-enterprise incidents.
- Supplier assurance that results in contract, architecture, contingency or exit action.
- Independent confidence that channel migration can continue without creating hidden fragility.
The person
You bring 22–28 years in operational risk, resilience, technology risk, institutional operations or a closely related discipline. You have held enterprise or major-division accountability for a perimeter of at least ₹4,150 crore and led 180 or more employees and partners. Experience in banking, payments, securities infrastructure, insurance or another regulated network is relevant.
You have defined important services, set tolerances and tested multi-party failure in reality—not only produced policy. You can show a migration delayed, design changed, vendor challenged or investment approved because of your evidence. Technical literacy is essential, but so is the judgement to distinguish a severe service risk from a control gap that can be managed routinely.
You preserve constructive tension with first-line executives. The role requires clear challenge, willingness to stop an inadequately protected change and discipline to return ownership once the evidence is accepted. Board communication should be concise, scenario-based and free of false reassurance.
Compensation and terms
The fixed range is ₹2.2–3.0 crore plus performance variable. Assessment will balance service resilience, migration assurance, first-line ownership, remediation closure and team capability. The role is permanent and onsite in Pune. While the appointment is urgent, a responsible release from the candidate’s present risk obligations will be respected.
Confidentiality
The client and its critical-service topology will remain undisclosed until suitability and conflict checks are complete and confidentiality is accepted. Service, scale and migration details are intentionally composite. Nothing in the brief should be used to identify, test or contact a possible organisation.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.