Confidential mandate

Ocean-Data Trust Architecture Director — Offshore Energy Alliance

Planned Hiring / New

Ocean-Data Trust Architecture Director mandate in Oslo, Norway · Offshore Energy Data Collaboration

A Norwegian offshore-energy alliance commissions a six-month sovereign data-space design to enable shared ocean intelligence without dissolving member rights, producing an accepted operating constitution and tested exchange controls.

The mandate

Operators, service companies and research institutions hold complementary seabed, metocean, acoustic and asset-condition data, yet proposed sharing repeatedly stalls over derivative rights and exposure of commercially sensitive operating patterns. A technical sandbox moved files successfully but did not prove that a contributor could constrain later use, withdraw a compromised dataset or understand what another member’s model inferred from its contribution.

The commissioned deliverable is an Ocean-Data Trust Architecture for three exchanges: marine habitat monitoring, offshore-maintenance planning and regional hazard awareness. It must combine identity, usage-policy expression, semantic contracts, provenance, confidential processing options, audit evidence, dispute handling, economics and member exit. The package will state plainly where sovereignty depends on enforceable technology, contractual remedy or continued institutional trust.

Milestone one at week five provides rights mapping, threat models and use-case value evidence. Week eleven concludes milestone two with architecture alternatives and a selected trust boundary. In week nineteen, milestone three delivers working exchanges and adversarial policy tests. The operating constitution, assurance pack, member economics and council decision form milestone four at week twenty-six.

Acceptance requires six independent members to approve the role and rights matrix, security teams to reconstruct every test access and derived output, and Legal to translate policy labels into enforceable schedules. An unseen withdrawal and unauthorised-derivation scenario must produce the agreed suspension and evidence. Finance must validate shared-service costs, and the council must resolve rather than defer every material governance choice.

The client alliance will provide data classifications, sample assets, licence and partnership terms, sandbox logs, model-use descriptions and named representatives with decision authority. Members will supply domain experts and security engineers inside segregated environments. The secretariat will retain decisions, while each contributor remains responsible for authorising release, export classification and safety use of its data.

Why this is external work

Every member’s preferred architecture reflects its bargaining position and installed technology, while the sandbox supplier benefits from becoming the permanent trust operator. The alliance lacks independent expertise spanning industrial semantics, confidential computation and multi-party rights. External authorship gives the council an implementation-ready design without presuming central custody or protecting the pilot’s original commercial choices.

What you will own

  • Map contributor rights, recipient obligations, permitted derivations, retention, onward use and withdrawal consequences across all three ocean-data exchanges.
  • Define federated identity, policy decision, semantic validation, provenance, confidential processing, evidence retention and participant suspension capabilities.
  • Distinguish restrictions technically enforceable before use from obligations requiring audit, contract, remedy or deliberately bounded member trust.
  • Run adversarial scenarios involving compromised credentials, inferred operating patterns, model memorisation, dataset correction and contributor exit.
  • Calculate shared and member-specific cost across onboarding, connectors, policy administration, assurance, dispute handling and specialist secure computation.
  • Recommend the trust-operator structure, decision rights, liability options and migration sequence with minority-member protections made explicit.
  • Transfer test scripts, policy patterns, decision records and a repeatable member-onboarding exercise to the alliance secretariat and nominated architects.

Candidate qualifications

  • Designed a production sovereign-data or multi-party industrial exchange where contributors retained meaningful control after initial transfer.
  • Negotiated derived-data, model-output, withdrawal and audit rights across operators, suppliers and research institutions with unequal commercial leverage.
  • Applied federated identity, policy engines, secure enclaves or privacy-enhancing computation without overstating what technology could guarantee.
  • Built semantic and provenance controls for marine, energy, geospatial or scientific data whose interpretation affected physical operations.
  • Tested governance under misuse, contributor exit and compromised evidence rather than limiting assurance to successful happy-path exchange.
  • Delivered an operating constitution and economics adopted by independent organisations after the commissioned design team departed.

Non-negotiables

  • The named director must lead member negotiations in Oslo and participate in North Sea operational workshops throughout the engagement.
  • No equity, reseller arrangement or delivery commission may exist with cloud, connector, confidential-compute or data-space platform bidders.
  • Member export, safety and data-release authority cannot be centralised implicitly through the reference architecture.
  • Acceptance requires enforceable operating decisions and adversarial tests, not standards alignment or a visually complete demonstration.
  1. 49 words maximum. Describe one data-space control that appeared sovereign but ultimately depended on contract or participant trust.
  2. 49 words maximum. How would you test withdrawal when another member has already derived a model feature from contributed ocean data?
  3. 49 words maximum. Which inputs would you require to price onboarding and assurance fairly across large operators and research members?

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.