Confidential mandate
Software Supply-Chain Assurance Adviser — Connected Devices
Planned Hiring / New
Software Supply-Chain Assurance Adviser mandate in Stockholm, Sweden · Connected Devices
A Stockholm connected-device board seeks independent counsel to test open-source, build-service and supplier trust, shaping defensible global product-release and investment thresholds over a ten-month term.
The mandate
The board cannot judge whether product releases remain trustworthy when open-source dependencies, hosted build services and supplier modules change faster than annual assurance. Current dashboards count SBOM entries but do not show exploitable reach, provenance, maintainer concentration or update constraints. Its standing question is which supply-chain failures can silently cross the build boundary and what evidence should suspend a release or installed product line.
The adviser commits four days monthly, remotely, with quarterly Stockholm and scheduled Tallinn and Berlin reviews. A monthly challenge session examines one live release, supplier exception or build-service change with product and security leaders. Material vulnerability questions receive an initial response within two working days and a reasoned recommendation within four, without the adviser becoming an on-call incident responder.
The term runs ten months and may renew once for three months by recorded committee decision after reviewing influence, conflicts and management adoption. Renewal must identify a remaining board question and cannot simply preserve access to specialist knowledge. Product backlog, incomplete SBOM coverage or delayed supplier contracting is not a renewal reason.
The appointment carries no line authority, release approval or signing-key access. Executives retain product, security and disclosure decisions. The adviser may recommend withholding a release, revoking an artefact or notifying customers but cannot direct engineers, approve exceptions, negotiate supplier terms or represent the company to authorities.
Conflicts include component suppliers, build platforms, scanning vendors and competitors. Relevant clients, investments and referral benefits require continuing disclosure. Standards roles, vulnerability-broker relationships and access to non-public ecosystem incidents must also be declared where they could bias vendor or remediation advice.
Why the board wants this voice
Engineering sees delivery constraints while security sees component exposure. Directors lack independent experience of build compromise and supplier failure. The adviser will test whether trust claims survive realistic attack and recovery.
What you will own
- Challenge dependency governance through source provenance, practical reachability, execution privilege, maintainer concentration and field-update feasibility.
- Test build-service trust, runner isolation, secret access, dependency retrieval and artefact attestation under malicious-change scenarios.
- Press suppliers on source, binary, vulnerability and end-of-support evidence.
- Shape release exceptions with enforced expiry, measurable compensating controls, accountable sponsorship and customer impact.
- Review signing, package, update-channel and distribution controls for compromise, revocation, customer detection, quarantine and rollback.
- Probe response scenarios involving malicious maintainer or poisoned update.
- Equip the board with exploitable exposure, provenance failure, supplier responsiveness, unsupported products and remediation indicators beyond raw vulnerability counts.
Candidate qualifications
- Governed software supply-chain security for deployed connected or embedded products with long support obligations.
- Can evidence executive response to a compromised dependency, build system, maintainer account or supplier artefact in production.
- Operationalised SBOM, provenance, maintainer confidence and reachability evidence in documented product-release decisions.
- Challenged hosted build, runner isolation, secret access and signing trust at executive decision level.
- Advised boards without economic ties to reviewed tooling.
- Balanced field-update constraints with customer safety, vulnerability disclosure and end-of-support obligations across product generations.
Non-negotiables
- Can attend all remote and scheduled European sessions.
- Will disclose vendor, supplier and competitor relationships.
- Accepts no release authority or production credentials.
- Has board-level product trust judgment beyond compliance reporting.
- 49 words maximum. Which current vendor relationship could conflict with this appointment?
- 49 words maximum. Describe a dependency whose practical reachability changed its release priority.
- 49 words maximum. What evidence would make you distrust a supplier's signed binary?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.