Confidential mandate

Service-Mesh Trust-Domain Recovery Leader

Urgent / Unplanned

Service-Mesh Trust-Domain Recovery Leader mandate in London, United Kingdom · Digital Wealth Infrastructure

A digital-wealth platform needs a nine-month executive after emergency certificate rotation partitioned services, triggered unsafe bypasses and revealed unowned trust boundaries across its mesh estate.

The mandate

An emergency root rotation split the production service mesh into incompatible trust domains, causing payment and portfolio services to fail closed while several teams restored traffic through unmanaged plaintext and broad policy exceptions. The platform leader left during remediation. Investigation has since found inconsistent workload identities, hidden cross-cluster dependencies, sidecar version drift and certificate ownership divided among security, SRE and application teams.

The interim must join in London within ten business days and hold the role for nine months. Recruitment for a permanent platform-trust leader begins when the first common identity and rotation standard runs across two production clusters, expected in month four. The final month is reserved for the successor to chair a certificate change, an application exception review and a mesh-control failure exercise.

Handover requires every regulated service to have an accountable trust domain, reproducible identity issuance, tested rotation and revocation, bounded exception path and observable encryption posture; all emergency bypasses must be removed or formally time-boxed; two control-plane loss scenarios must complete within service objectives; and the successor must accept the dependency and residual-risk ledgers.

The interim may stop platform releases, revoke unsafe exceptions, set identity standards, sequence migrations, reassign existing engineers and approve up to GBP 9 million within the recovery allocation. Changes to customer authentication, permanent recruitment, product roadmaps, mesh-provider contracts and spend above GBP 2 million per decision require sponsor or committee approval. The seat cannot waive regulated encryption controls.

Application feature delivery, customer identity redesign, general cloud migration and replacement of unrelated network security tooling are explicitly out of scope. This assignment covers service-to-service identity, mesh policy, certificate lifecycle, cross-cluster trust, developer adoption, failure behaviour and the operating ownership needed to keep those controls reliable.

Why this seat is open

The rotation event turned a security maintenance action into a customer outage and then encouraged recovery choices that weakened the intended control. Leadership departure left teams debating product defects, certificate defects and platform ownership without an executive decision point. A time-limited leader must close the bypasses, make trust boundaries operable and leave permanent management with rehearsed control.

What you will own

  • Reconstruct certificate issuance, bundle propagation, identity matching, policy evaluation, retry and bypass decisions across the failed rotation.
  • Assign authoritative trust domains and workload identities to regulated services, shared platforms, batch jobs, third parties and administrative components.
  • Decide rotation, overlap, revocation and emergency-access rules with explicit blast radius, expiry, rollback and evidence requirements.
  • Remove or constrain plaintext paths, permissive policies, unmanaged certificates and sidecar exemptions according to measured customer and control risk.
  • Establish mesh reliability signals for identity issuance, certificate age, policy denial, encryption mode, configuration drift and control-plane dependency.
  • Command exercises involving expired roots, partial bundle propagation, compromised workload identity, unavailable control planes and cross-cluster isolation.
  • Transfer standards, service ownership, migration status, exceptions, supplier defects and exercise evidence through successor-led governance.

Candidate qualifications

  • Led production service-mesh or workload-identity platforms supporting regulated, high-volume or financially consequential services.
  • Recovered a certificate or trust-domain event involving partial propagation, failed rotation, policy bypass or incompatible control planes.
  • Designed identity, rotation and revocation across clusters and administrative boundaries without relying on permanent overlapping roots.
  • Drove application-team adoption by making secure defaults observable and operable rather than issuing architecture standards alone.
  • Ran resilience tests for identity and policy infrastructure, including control-plane loss and emergency exception expiry.
  • Completed an executive recovery handover in which a successor chaired a risky platform change before formal transfer.

Non-negotiables

  • Can start in London within ten business days and maintain continuous escalation availability during certificate changes.
  • Will work exclusively for the platform during the nine-month term and travel on the stated London, Edinburgh and Dublin pattern.
  • Brings live mesh identity and certificate operations; perimeter-network or public-key-policy expertise alone does not qualify.
  • Must disclose relationships with mesh, certificate, cloud and security-platform vendors before reviewing the incident record.
  1. 49 words maximum. State your earliest London start and the largest service-mesh trust failure you personally commanded.
  2. 49 words maximum. Describe a certificate-overlap strategy that looked safe but produced an unexpected trust path.
  3. 49 words maximum. Which observable signal would prove an emergency plaintext bypass has actually disappeared from production?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.