Confidential mandate

Market-Infrastructure Security Governance and Recovery-Test Consultant

Planned Hiring / New

Market-Infrastructure Security Governance and Recovery-Test Consultant mandate in Gandhinagar, India · Financial Market Infrastructure

Financial-market infrastructure needs a tested security-governance and recovery-test specification linking service dependencies to evidence and approval; this six-month consulting project delivers accepted artifacts and a controlled rehearsal without operating market services or certifying compliance.

The mandate

The defined issue is a recovery-test agenda that is not yet joined to security governance, evidence criteria and critical-service approval paths. The consultant will deliver a Security Governance and Recovery-Test Specification for selected financial-market information services. It must make clear what a test can prove, who approves it and which operational conditions remain outside the exercise.

The six-month engagement starts on 19 October 2026 at four days weekly in Gandhinagar, with remote analysis and scheduled India technology workshops. Deliverables include the critical-service dependency map, governance decision matrix, test scenarios, evidence protocol and controlled rehearsal report. Live market-service changes remain subject to separate operational approval; the assignment does not imply permission to test in production.

Milestone one on 18 December 2026 supplies the accepted dependency and approval baseline with gaps in existing recovery claims. Milestone two, due 18 February 2027, is the reviewed test specification and evidence protocol, validated in an authorised rehearsal environment. Milestone three on 18 April 2027 delivers a controlled scenario exercise, corrected governance artifacts and a retained-owner replay of test planning and evidence evaluation.

The security sponsor and service resilience owner jointly accept the work, with operational reviewers confirming service relevance. Acceptance requires scenarios to cover the agreed dependencies, evidence to support stated timing and integrity conclusions, and exclusions to remain visible. Retained owners must classify an unfamiliar exercise result correctly and route any residual issue to authorised decision makers. The output is not a guarantee of uninterrupted clearing or payment operations.

The sponsor supplies service diagrams, existing recovery records, an approved test environment and reviewers with time and authority to approve boundaries. The consultant does not direct market operations, submit regulatory returns, implement all remediation or replace the CISO. Additional services, live testing or legal assurance require change approval. The engagement ends with accepted specifications, rehearsal evidence and transfer, leaving execution and regulatory responsibility internally accountable.

What you will own

  • Map selected critical-service dependencies and approval routes, identifying where security, resilience and market-operation procedures describe incompatible responsibility or evidence requirements.
  • Construct a governance decision matrix distinguishing test approval, technical execution, residual-risk acceptance and regulatory escalation so exercise authority cannot be confused with service operating powers.
  • Design recovery scenarios with explicit integrity, access and timing evidence, documenting external dependencies and production conditions deliberately excluded from the agreed test perimeter.
  • Validate the specification in an authorised environment, correcting ambiguous success criteria before presenting a rehearsal as evidence of critical-service recovery capability.
  • Run a controlled scenario exercise and produce an evidence report separating demonstrated outcomes, untested assumptions and residual issues needing further executive or operational decisions.
  • Transfer the specification and evaluation method through retained-owner replay on an unfamiliar result, preserving approval boundaries and the limited assurance of the consulting output.

Candidate qualifications

  • Demonstrate twenty-two or more years in technology or security with substantive governance and resilience delivery for financial services. Present a test specification or governance artifact you personally developed, the approval or evidence gap it exposed and how operational owners accepted it. The role requires specialist authorship beyond chief-title oversight.
  • Show practical expertise in critical-service dependency, recovery, information integrity and access controls. Explain a case where a technically successful restoration did not establish service readiness, and describe the additional evidence or exclusion needed. Candidates must preserve market-operation and regulatory authority rather than infer it from test sponsorship.
  • Bring assurance discipline that distinguishes demonstrated results, assumptions and residual risk under a bounded exercise. Provide an example of acceptance criteria you revised because they could be met without proving the intended capability. The consultant must communicate limitations plainly and avoid presenting the specification as regulatory certification.
  • Prove fixed-fee delivery with controlled test approval, secure records and retained-owner transfer. Describe how you handled requests for live testing or additional services without expanding authority or weakening milestone evidence. Current commitments must support four-day weekly capacity and the agreed India workshop schedule, while ongoing CISO and service execution remain outside the project.

Application

Applications for this mandate are received in one way only: through the India Board Terminal's application process. It is automated end to end. Your Executive Passport travels to the mandate holder in its confidential form, your answers to the three questions below are read before anything else in your file, and every stage that follows is recorded on your applications page.

There is no address to write to and no intermediary to call. The mandate holder reads what the Terminal delivers and nothing else, which is what keeps the process the same for every applicant and keeps your name out of it until you release it. Applications close on 11 October 2026. Mandate reference PCT-CON-2026-IND-55.

More seats like this one

Every live mandate, by seat →

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.