Confidential mandate

Critical Infrastructure OT Visibility and Response Readiness — Consulting Head

Planned Hiring / New

Critical Infrastructure OT Visibility and Response Readiness mandate in Mumbai, India · Critical Infrastructure

Create a six-month industrial visibility and response-readiness architecture package, tracing asset evidence, safe access and escalation dependencies through authorised assessment artefacts and sponsor acceptance without changing production systems or operating plant controls.

The mandate

Industrial asset visibility does not currently establish how an unusual event would be investigated or escalated safely. The consulting project will connect approved visibility evidence with response-readiness architecture. The defined scope is design and validation, not production deployment, active probing without permission or direct operation of industrial control equipment.

The deliverable is an OT Visibility and Response Readiness Architecture Book with asset-evidence confidence, connectivity dependencies, safe-access patterns, investigation requirements and response decision interfaces. It must state what is observed, inferred or unknown for each critical design question. Architecture options will preserve the plant owner's authority and the limits of the available engineering evidence.

The six-month programme commences on 19 October 2026. Milestone one on 18 December 2026 provides the authorised visibility baseline; milestone two on 18 February 2027 delivers architecture options and a controlled response walkthrough; milestone three on 18 April 2027 completes revised design, fresh-scenario validation and the accepted book. Payments are 25%, 35% and 40% against accepted outputs.

Acceptance is shared by the industrial security head and plant engineering sponsor. They must trace sampled asset claims to approved evidence, identify safe investigation paths and route a simulated event to the retained production decision-maker. Final acceptance requires an internal team to apply the architecture to a new authorised scenario without assuming that missing visibility proves absence of exposure.

The sponsor provides written assessment permissions, approved asset and network evidence, engineering context and named plant and security reviewers. Passive methods are preferred unless a separately authorised test is safe. Equipment changes, vendor procurement, live incident operation and formal safety or compliance opinions are excluded; expanded access or active tests require new permission and signed change control.

What you will own

  • Establish the authorised asset-evidence baseline with confidence and source limitations, distinguishing observed connectivity from inference before the architecture treats any industrial dependency as confirmed or complete.
  • Map safe investigation and access paths with engineering owners, retaining maintenance and recovery conditions that must survive any proposed security architecture or response-readiness design.
  • Construct architecture alternatives around visibility, segmentation and response dependencies, showing where specialist validation or production approval remains necessary rather than presenting a single unqualified target state.
  • Define response evidence and escalation interfaces that keep security confidence separate from plant impact, preserving the authorised owner of customer, safety or production-affecting action.
  • Rehearse the design through a controlled industrial event scenario, recording gaps in asset knowledge, investigation access and decision authority without executing unauthorised production changes.
  • Validate internal users on a fresh approved scenario, observing whether they preserve uncertainty and route unresolved engineering questions instead of overextending the architecture's evidence claim.
  • Deliver the accepted book, confidence register and maintenance guide with production implementation dependencies explicitly outside the completed design and readiness project's acceptance boundary.

Candidate qualifications

  • Demonstrate responsible OT visibility, security architecture or response-readiness delivery in industrial or critical-infrastructure environments. Provide a redacted design case showing a confidence limitation and its decision consequence. Candidates must identify permission, engineering reliance and their personal method; general enterprise security architecture alone does not establish industrial readiness competence.
  • Show practical understanding of OT asset visibility, safe access, network dependencies and recognised industrial security principles. Explain how passive evidence shaped a recommendation and when active testing was refused or separately authorised. The consultant must not infer equipment-operating authority, safety certification or a compliance guarantee from an architecture engagement.
  • Provide project evidence with tested artefacts, controlled scenarios and joint security-engineering acceptance. Describe a response assumption that failed during rehearsal and the design change made. The deliverable must remain usable by internal teams and accurately distinguish observed facts from unknown dependencies, rather than concealing uncertainty in a visually complete network diagram.
  • Establish senior OT architecture delivery through jointly reviewed asset-confidence and response evidence, with controlled access to confidential industrial records and explicit assessment scope. Disclose vendor, integrator and implementation-linked interests. Show a completed handover where production decisions remained with the proper owner and new access requirements were priced and authorised before work, not retrospectively justified by the consulting deadline.

Application

Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.

There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 8 October 2026. Mandate reference PCT-CON-2026-IND-30.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.