Confidential mandate
Digital Identity and Zero-Trust Board Adviser
Planned Hiring / New
Digital Identity and Zero-Trust Board Adviser mandate in Dubai, United Arab Emirates · Integrated Travel and Business Services
A regional services group seeks a board-level identity adviser to resolve federation, privileged-access and zero-trust investment choices across a fragmented workforce and customer estate during an eight-month term.
The mandate
The board keeps revisiting whether one identity control plane can safely serve acquired businesses, seasonal workers, privileged operators, partners and customer channels without forcing every platform into the same implementation. Investment proposals alternate between wholesale consolidation and tactical federation, leaving risk reduction, customer friction and migration accountability unresolved.
The adviser will contribute three days monthly: a committee or chair session, a design-and-risk challenge with executives, and prepared review time. Three scheduled Technology and Risk Committee meetings are included, while ad-hoc queries receive a substantive response within three working days; incident command is explicitly excluded.
The appointment runs for eight months through approval of the next identity investment tranche. A two-month extension may be authorised only by the committee chair after written assessment of unfinished board questions, and renewal is neither automatic nor tied to implementation delays.
This is an influence-only seat with no line authority, signing power or executive accountability. The CISO owns control posture, the CIO owns architecture delivery and business executives own customer impact; the adviser may challenge their evidence but cannot select vendors, direct staff or approve access exceptions.
Other non-competing cyber advisory work may continue if disclosed. Current work for a regional travel-services competitor, a shortlisted identity vendor, a material implementation partner or an investor pursuing one of the group's assets creates a conflict requiring recusal or withdrawal.
Why the board wants this voice
Committee members can interrogate cyber incidents and budgets but lack deep identity transformation experience across workforce and customer boundaries. Management's current debate has become product-led, obscuring the operating decisions that determine access risk. The board wants an independent practitioner who can expose false architectural certainty and make investment gates intelligible.
What you will own
- Press the board to define identity outcomes separately for employees, privileged operators, partners, devices and customer journeys.
- Test the federation and consolidation cases against breach paths, service continuity, data residency, user friction and acquisition portability.
- Challenge privileged-access proposals on account discovery, session control, emergency access, credential rotation and measurable adoption.
- Shape zero-trust sequencing around enforceable identity, device and workload signals rather than a vendor-labelled programme.
- Probe whether business ownership, joiner-mover-leaver controls and exception expiry can sustain the proposed technical architecture.
- Review investment gates for evidence of legacy retirement, control effectiveness, operating capacity and reversible migration waves.
- Give the committee a closing independent memorandum on decisions reached, accepted residual risk and questions requiring continuing oversight.
Candidate qualifications
- Held group CISO, identity executive or enterprise security architecture responsibility across a complex multi-business or multi-country organisation.
- Governed workforce, privileged and customer identity domains through acquisition integration or platform federation at significant scale.
- Designed zero-trust investment sequencing tied to tested controls and service outcomes rather than product deployment counts.
- Challenged board-level cyber programmes on data residency, customer friction, operational ownership and recovery consequences.
- Evaluated identity and privileged-access suppliers without dependence on resale, implementation or referral economics.
- Served as a board or risk-committee adviser and can evidence influence achieved without assuming management authority.
Non-negotiables
- Can attend three in-person committee meetings in Dubai and two disclosed regional architecture reviews during the eight-month term.
- Will declare vendor, integrator, investor and competitor relationships before access to strategy papers and update that disclosure promptly.
- Accepts no operational command, staff direction, procurement vote or authority to approve identity-risk exceptions.
- Can protect three days each month and answer genuine board questions within three UAE working days.
- 49 words maximum. Which current identity, cyber, travel-services or investment commitments could create a conflict for this board?
- 49 words maximum. Describe one zero-trust investment assumption you overturned and the operating evidence that changed the board's view.
- 49 words maximum. Can you commit three days monthly, three Dubai committee meetings and two regional reviews across eight months?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.