Confidential mandate
OT-Cyber Capability Sponsor-Governance Adviser
Planned Hiring / New
OT-Cyber Capability Sponsor-Governance Adviser mandate in Copenhagen, Denmark · Renewable Power Operations
A renewable-energy operator needs a ten-month board adviser to challenge headquarters sponsors transferring OT-security engineering to India while plant authority, asset context and supplier access remain unresolved.
The mandate
Headquarters sponsors propose moving vulnerability analysis, secure-remote-access engineering and OT architecture review into an India GCC, but their plan counts roles rather than plant context or decision boundaries. Site operators fear distant engineers will recommend changes without understanding safety states; suppliers still control diagnostic detail. Directors want challenge before transfer volume creates a cyber function trusted by neither operations nor India leaders.
The adviser’s calendar combines a two-day monthly evidence lab with four board safety-and-technology sessions over ten months. Each lab follows one generation asset class from inventory through risk disposition, supplier action and plant approval. Two visits to operating sites and two reviews with India capability leaders are included; short questions are consolidated into the next evidence lab unless the chair declares a safety-critical exception.
The brief expires after the committee’s month-ten decision on capability waves and sponsor accountability. Directors may commission a later plant-assurance review only through a new resolution defining changed conflicts and evidence; no renewal is embedded here. If the transfer is paused, the remaining cadence shifts to source-capability remediation rather than extending the appointment.
This is a challenge role with no line authority and no executive responsibility for cyber operations, plant safety, supplier contracts, hiring or remediation. Site accountable managers approve operational changes, management appoints India leaders and the board sets risk appetite. The adviser can recommend that a wave stop, but cannot issue plant instructions, accept risk or release remote access.
Past or present work for equipment manufacturers, OT-security providers, remote-maintenance vendors, competing generators or firms recruiting the proposed India team creates a potential conflict. Relevant engagements, equity interests and paid introductions must be disclosed by asset class before access is granted. The committee chair determines exclusions, and success fees connected to transfer size or supplier selection are not permitted.
Why the board wants this voice
Source sponsors are measured on transfer progress, while plant leaders bear operational consequence and can veto quietly. India leaders lack access to the asset evidence needed to challenge either side. Independent OT operating experience can help directors distinguish legitimate safety retention from convenient resistance and prevent a capability built around incomplete tasks.
What you will own
- Press sponsors to define complete OT-security outcomes, plant inputs, engineering outputs, decisions and accountable asset interfaces.
- Test whether India teams receive current inventories, network context, threat evidence, supplier diagnostics and safe laboratory environments.
- Challenge remote-access, vulnerability and architecture workflows that end in unowned recommendations or indefinite site escalation.
- Examine separation between technical analysis, engineering proposal, safety review, operational approval and independent cyber challenge.
- Probe supplier incentives, intellectual-property limits and support clauses that prevent the captive team from building judgment.
- Shape board evidence across exercised decisions, plant trust, remediation ageing, talent depth and safe source-team release.
- Frame wave-by-wave sponsor findings, plant objections, capability gaps and transfers that require redesign before approval.
Candidate qualifications
- Governed cross-border OT-security capability for power generation, process industry or another safety-critical asset estate.
- Distinguished plant operating authority from cyber engineering ownership without turning safety review into permanent source dependence.
- Exposed transfer plans that omitted asset-state knowledge, supplier diagnostics, test environments or implementable remediation outputs.
- Challenged equipment vendors and remote-maintenance providers while protecting support continuity across legacy control environments.
- Built credible India OT-security leaders through site exposure, exercised risk disposition and accountable engineering recommendations.
- Advised safety or risk committees independently of cyber vendors, recruiters, engineering contractors and affected equipment suppliers.
Non-negotiables
- Can complete two operating-site visits, two India leadership reviews and all four Copenhagen committee sessions.
- Will declare generator, equipment, OT-security, remote-access, recruitment and engineering-service interests by asset class.
- Brings operational OT capability transfer evidence; enterprise IT security governance without plant accountability is insufficient.
- Accepts that plant change, safety, risk, contract and appointment authority remains outside the advisory seat.
- 49 words maximum. Describe an OT-security task that looked transferable until missing plant-state knowledge made it unsafe.
- 49 words maximum. Which equipment or remote-access relationship could require your recusal from a capability review?
- 49 words maximum. What evidence separates prudent site approval from a source team retaining routine cyber authority?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.