Confidential mandate
Detection Use Cases and Incident Evidence Acceptance — Consulting Director
Planned Hiring / New
Detection Use Cases and Incident Evidence Acceptance mandate in Mumbai, India · Financial Services Cybersecurity
Deliver a six-month financial-services detection and incident-evidence programme, defining testable use cases, investigation artefacts and authorised purple-team acceptance while leaving production containment and executive risk decisions with internal owners.
The mandate
Detection use cases and incident evidence procedures are documented separately, so a successful alert test does not prove an investigation can reconstruct the event. The consultant will design and validate their connection. This finite programme concerns approved defensive evidence and explicitly authorised exercise activity, not unrestricted offensive access or operation of live incidents.
The deliverable is a Detection and Incident Evidence Acceptance Pack containing threat hypotheses, telemetry requirements, test cases, evidence timelines and a purple-team results register. Each use case must state the authorised test scope and the decision it supports. Evidence collection must be sufficient for internal investigation without implying forensic certification or a legal conclusion.
Work begins on 19 October 2026. The first milestone on 18 December 2026 delivers the telemetry baseline and approved test plan; the second on 18 February 2027 produces tested use cases and evidence-chain findings; final acceptance on 18 April 2027 covers authorised reruns, internal operator rehearsal and the complete pack. The project fee is paid 25%, 35% and 40% on accepted outputs.
The cyber defence head and security engineering sponsor accept work only when approved events produce the expected detection, evidence is traceable and limitations are explicit. Exercise findings must include failed cases, not only successful demonstrations. Final acceptance requires internal analysts to reconstruct a new authorised scenario and route uncertainty through the retained response matrix without consultant interpretation.
The sponsor provides written exercise authorisation, approved telemetry access, designated SOC and engineering staff and safe test windows. Customer and production-sensitive data is minimised. Live containment, unauthorised penetration testing, systems procurement and legal or regulatory opinions are excluded; any broader test requires new written permission and repriced scope before execution.
What you will own
- Establish the threat-to-evidence baseline with approved telemetry sources, identifying where a use case cannot support its intended investigation or response decision before tests are scheduled.
- Define detection acceptance cases with written authorisation, safe boundaries and expected source events, preventing a demonstration from drifting into unapproved offensive activity or production disruption.
- Construct incident evidence templates that preserve timestamps, confidence and access history, keeping investigator hypotheses separate from confirmed observations and retained business impact assessments.
- Execute authorised purple-team validation through agreed windows and reviewers, recording failed detections, missing evidence and the conditions that invalidate a claimed successful result.
- Reconcile engineering and SOC findings into a prioritised remediation register, distinguishing source-data limitations from detection logic defects and response-governance issues requiring internal executive decisions.
- Validate internal analyst readiness through a fresh approved scenario, testing reconstruction and escalation without consultant prompts or undisclosed manual preparation of the evidence trail.
- Deliver the accepted pack, rerun results and maintenance triggers, with unresolved production changes and specialist opinions explicitly outside the completed programme's acceptance claim.
Candidate qualifications
- Demonstrate responsible detection engineering, SOC or incident-evidence programme leadership at director or comparable functional scope. Provide a redacted acceptance case that failed and changed the design. Candidates must identify authorisation, personal method and internal decision boundaries; a security title or certification without practical tested evidence is insufficient.
- Show technical competence connecting telemetry, detection logic, incident timelines and confidence assessment. Explain how clock, source or retention limitations affected a result. The consultant must distinguish internal investigative usefulness from formal forensic certification and avoid claiming legal admissibility or regulatory sufficiency beyond the authorised specialist review supplied by the sponsor.
- Provide authorised purple-team or equivalent defensive validation experience, including scope control, safety windows and reviewer sign-off. Describe a requested test refused because permission or operational safeguards were inadequate. No production access, offensive authority or permission to affect customer services is inferred from the consulting appointment.
- Establish project delivery discipline with dated milestones, reproducible reruns and an internal operator handover. Demonstrate director-level review of a detection case whose evidence or escalation test initially failed, including the accepted correction. Disclose security-provider, product-resale and same-incident interests, and show how sensitive data and test results were separated across concurrent work so remediation advice remains commercially independent.
Application
Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.
There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 10 October 2026. Mandate reference PCT-CON-2026-IND-28.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.