Confidential mandate

Satellite Command-Key Recovery Leader — Earth Observation

Urgent / Replacement

Satellite Command-Key Recovery Leader mandate in Abu Dhabi, United Arab Emirates · Earth Observation

Following a failed ground-station key ceremony, an Abu Dhabi operator needs executive command-cryptography leadership to restore satellite control assurance and hand over tested custody within eight months.

The mandate

The cryptographic assurance director was removed after a backup ground station could not complete an emergency command-key activation using the sealed procedure. Inventory records disagree with hardware security module state, two retired operators still appear in ceremony documentation, and the flight team has avoided testing recovery against an on-orbit asset. The interim leader must re-establish command trust without creating a control outage or exposing sensitive mission material unnecessarily.

Eight months are available to secure current custody, reconcile key lineage, rebuild ceremonies, validate primary-to-backup control transfer and recruit a permanent leader. The first forty-five days cover evidence preservation and safe-state decisions; months two through five repair custody and exercise non-flight environments; months six and seven conduct authorised on-orbit proofs. The final month is dedicated to successor-led ceremonies, exception transfer and board assurance.

Handover is complete when dual-control records reconcile to cryptographic state, the backup station completes two independent command recoveries, emergency access works without shared knowledge, and the successor chairs a witnessed ceremony from initiation through destruction evidence. Every inherited exception must name a mission consequence, compensating safeguard and expiry owner. Documentation alone is insufficient if operators cannot execute it under time pressure.

The leader may suspend a compromised credential, set ceremony roles, approve controlled simulations, schedule command windows with mission approval, quarantine unexplained media and commit AED 8 million within the recovery envelope. Any live satellite command, orbit-affecting manoeuvre, payload activation or permanent architecture change still requires the authorised mission decision chain. National cryptographic approvals and export-controlled disclosures remain with designated officials.

Excluded are designing the next satellite platform, replacing all ground infrastructure, conducting intelligence attribution, acting as launch authority or serving as sole custodian of operational key material. The role governs the integrity of recovery and command authorisation, not spacecraft mission priorities. Suspected insider behaviour will be referred to an independent investigation with access separated from laboratory remediation.

Why this seat is open

A command-recovery procedure that has never worked under realistic conditions is a paper safeguard, regardless of how secure its vault appears. The current gaps span people, cryptographic state and mission timing, so they cannot be delegated to a hardware vendor alone. Temporary executive authority allows urgent custody decisions while preserving the flight team’s final control over spacecraft behaviour.

What you will own

  • Reconcile key-generation, transport, activation, escrow, rotation, revocation and destruction evidence against actual module and station state.
  • Restore named dual-control roles, separation of duties, identity proofing, witness independence and time-bounded emergency access.
  • Design rehearsals progressing from cryptographic test rigs through backup-station control to authorised low-consequence on-orbit commands.
  • Establish safe rollback when a key load, trust transition, time source or station handoff produces ambiguous telemetry.
  • Resolve legacy custodians, unexplained media, stale certificates and undocumented vendor access through defensible disposition decisions.
  • Integrate flight dynamics, mission control, security and continuity around command windows, abort criteria and evidence preservation.
  • Hand over ceremony packs, exception register, custody roster, recovery metrics and successor-led proof witnessed by accountable executives.

Candidate qualifications

  • Led cryptographic or command assurance for satellite, aviation, defence, energy-control or another mission-critical operational environment.
  • Can evidence recovery from a failed key ceremony without losing operational control or weakening custody through expedient shortcuts.
  • Understands hardware security modules, key lifecycle, dual control, offline transfer, time dependencies and ground-station operations.
  • Has designed progressive tests where an incorrect trust transition could affect a live physical or mission system.
  • Worked within export, national-security or regulated cryptographic constraints while preserving sufficient independent assurance evidence.
  • Built successor competence through witnessed execution, not merely manuals, classroom training or vendor certification.

Non-negotiables

  • Will operate from the Abu Dhabi mission centre and attend all scheduled backup-station exercises.
  • Has personally governed operational key recovery under a strict mission or safety decision chain.
  • Accepts no unilateral authority to issue spacecraft commands, alter orbit, activate payloads or approve national cryptography.
  • Will pass enhanced vetting and disclose relationships with relevant ground, payload and cryptographic suppliers.
  1. 49 words maximum. Which failed key ceremony exposed the most dangerous gap between documentation and operational state?
  2. 49 words maximum. How would you prove backup command recovery while constraining on-orbit consequence?
  3. 49 words maximum. What must the successor execute personally before you release cryptographic custody?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.