Confidential mandate

Sovereign-Cloud Exit Resilience Leader — Public Digital Services

Urgent / Unplanned

Sovereign-Cloud Exit Resilience Leader mandate in Riyadh, Saudi Arabia · Public Digital Services

After a failed portability exercise exposed critical provider dependence, a public-services operator needs executive cloud-exit leadership to prove sovereign continuity and hand over within twelve months.

The mandate

A mandated cloud portability exercise restored data objects but failed to recreate identity policy, managed-service configuration, cryptographic access and priority citizen journeys inside the recovery window. The cloud-resilience head was removed after declaring the exercise successful on infrastructure metrics. The operator now lacks executive authority to distinguish genuine sovereign exit capability from backups that remain operationally dependent on the incumbent provider.

The interim must begin within three weeks for twelve months, working between Riyadh, Jeddah and quarterly provider sessions in Dubai. The first two months require weekly service-by-service exit decisions and renegotiation of evidence from platform owners. A permanent search starts after the first complete citizen-service recovery in month seven, followed by six weeks of overlap; extension is possible only for successor notice.

Handover requires independently restorable identity, key access, data, application configuration, observability and operating knowledge for the agreed priority services. One full service must run for thirty days on an approved alternative environment, data residency and administrator access must be evidenced, provider failure and hostile-exit scenarios must be exercised, and the successor must chair a sovereign-dependency review.

The leader may set exit standards, stop migrations that deepen unapproved lock-in, demand portable artefacts, redirect the sanctioned SAR 65 million programme and invoke contracted test rights. Committee approval is required for production cutover, provider termination, permanent hiring and acceptance of a non-portable critical dependency. Service owners retain functional and citizen-impact decisions within the resilience gates.

General cloud cost optimisation, application feature modernisation and replacement of every provider-native service are excluded. Procurement owns commercial negotiations and legal owns sovereign interpretation, although their commitments must support tested exit. The remit builds executable continuity for priority services rather than an ideological multi-cloud programme or a paper exit plan.

Why this seat is open

The failed exercise exposed a definition of recovery that ignored identity, keys, operations and usable citizen journeys. Prior leadership reported technical restoration without surfacing continuing provider control. Temporary executive authority is needed to reset evidence, execute a real exit rehearsal and prepare permanent sovereign-cloud ownership.

What you will own

  • Classify service dependencies across data, identity, keys, managed platforms, network, observability, support and operator knowledge.
  • Define exit tiers by public-service criticality, residency obligation, maximum interruption and acceptable provider reliance.
  • Decide which native dependencies are replaced, duplicated, contractually protected or accepted through documented committee authority.
  • Build portable configuration, data-export, key-recovery and identity-bootstrap artefacts with owners, versions and restoration tests.
  • Direct a thirty-day alternative-environment pilot, measuring service outcome, integrity, performance, security and operational effort.
  • Exercise cooperative, degraded and hostile provider-exit scenarios with procurement, legal, service owners and crisis management.
  • Transfer dependency registers, tested artefacts, provider obligations and investment waves through successor-led sovereign reviews.

Candidate qualifications

  • Held executive cloud-resilience, sovereignty or exit authority for regulated public, financial or critical digital services.
  • Can evidence a provider-exit or portability exercise that restored complete business service rather than infrastructure and data alone.
  • Governed identity bootstrap, cryptographic key control, configuration portability and observability across an alternative environment.
  • Made defensible decisions to retain selected native services while reducing concentration and contractual exit risk elsewhere.
  • Worked with government, legal, procurement and engineering stakeholders on residency, administrative access and continuity evidence.
  • Handed a tested multi-quarter cloud-exit capability and unresolved dependence record to permanent accountable leadership.

Non-negotiables

  • Available within three weeks for the Riyadh, Jeddah and Dubai operating cadence.
  • Independent of incumbent and prospective cloud providers, systems integrators and sovereign-cloud advisers.
  • Will not label exported data or infrastructure recreation as an operationally complete service exit.
  • Has director or CIO-1 authority over live cloud dependency and continuity decisions.
  1. 49 words maximum. State your availability and one complete cloud-service exit you personally accepted.
  2. 49 words maximum. Which managed dependency most often survives unnoticed in a portability exercise?
  3. 49 words maximum. Describe a provider-native service you deliberately retained and the protection you required.

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.