Confidential mandate
Jurisdictional Cloud Control-Plane Separation Leader
Urgent / Unplanned
Jurisdictional Cloud Control-Plane Separation Leader mandate in Reykjavik, Iceland · Public Digital Infrastructure
A national digital-service operator needs a sixteen-month executive after an assurance review exposed foreign control-plane dependencies that could invalidate sovereignty commitments across its citizen platforms.
The mandate
A national assurance review found that a cloud estate advertised as jurisdictionally self-contained still depends on overseas identity issuance, fleet policy, certificate recovery, telemetry administration and vendor support paths. The permanent platform director stepped aside when the committee paused three citizen-service migrations, leaving engineering teams to defend incompatible interpretations of sovereignty while live services continue to carry statutory availability obligations.
The interim must take the Reykjavik seat within two weeks and hold it for sixteen months. A search for a permanent sovereign-platform executive will begin after the first independently witnessed control-plane isolation exercise, expected in month nine, and the appointee will work alongside the interim for the final six weeks rather than inherit documentation without operational context.
Handover is complete only when privileged control actions can be originated, authorised, executed and evidenced inside the approved jurisdiction; two full loss-of-upstream exercises have preserved priority citizen journeys; recovery keys and break-glass identities have passed dual-control tests; and the successor has chaired a production change, a regulator review and a supplier exception decision. Merely relocating application data will not satisfy the exit test.
The interim may freeze migrations, set platform guardrails, stop non-compliant access, reassign internal specialists and commit up to ISK 900 million within the approved separation portfolio. Material architecture exceptions, supplier termination, permanent appointments and spend above ISK 250 million per decision require committee approval. The seat may direct engineering execution but cannot reinterpret statute, waive national-security controls or certify its own evidence.
Citizen-product redesign, agency data-quality remediation, general desktop modernisation and replacement of compliant application components are explicitly out of scope. The mandate covers the shared control plane, privileged operations, cryptographic custody, service continuity, observability boundaries and the operating evidence required to sustain jurisdictional control.
Why this seat is open
The review converted a long-running architectural concern into an immediate assurance failure, and the director’s departure removed the one role able to arbitrate platform dependencies. Paused migrations are now consuming programme capacity while existing services remain exposed to the same upstream concentration. The committee needs time-bounded executive authority that can separate the control plane without turning sovereignty into an availability incident.
What you will own
- Map every privileged control path across identity, orchestration, keys, certificates, network policy, support tooling, telemetry and software distribution, naming the jurisdiction and accountable operator at each hop.
- Decide which dependencies are eliminated, locally replicated, contractually constrained or accepted temporarily, and maintain the evidence and expiry date behind every exception.
- Establish an isolation architecture that preserves safe administration when overseas identity, vendor support, licence, update or telemetry services become unreachable or prohibited.
- Command two witnessed continuity exercises covering control-plane disconnection, compromised support credentials, certificate recovery and simultaneous failure of a domestic facility.
- Rebuild supplier operating procedures around cleared personnel, session approval, immutable evidence, software provenance, emergency access and revocation within the required legal perimeter.
- Present monthly committee decisions on residual concentration, service risk, cost, migration sequence and controls that remain dependent on policy interpretation.
- Transfer the architecture ledger, exercised runbooks, supplier obligations, control exceptions and unfinished risk choices through successor-led production and oversight forums.
Candidate qualifications
- Held executive accountability for a regulated or government cloud platform whose control plane, not merely stored data, carried jurisdictional restrictions.
- Separated identity, cryptographic, orchestration or support dependencies from a global provider while maintaining production service levels and recoverability.
- Led adversarial continuity exercises that removed upstream administration and proved local teams could diagnose, change and recover the estate safely.
- Negotiated technical operating boundaries with hyperscale, managed-service and security suppliers without confusing contractual promises with verified engineering control.
- Presented sovereignty exceptions to statutory, national-security or public-sector assurance bodies and preserved an independent trail for subsequent examination.
- Completed a complex infrastructure handover in which the permanent successor exercised decision rights before the temporary executive departed.
Non-negotiables
- Can relocate to Reykjavik within two weeks and travel to the named Icelandic sites and Nordic partners during critical tests.
- Will accept exclusive executive responsibility and continuous incident availability for priority citizen services throughout the fixed term.
- Brings control-plane separation evidence from live regulated infrastructure; data-residency policy work alone is insufficient.
- Must disclose current relationships with cloud, identity, cryptography, network and managed-service providers before privileged access is granted.
- 49 words maximum. State your earliest Reykjavik start and the most restrictive sovereignty boundary you have operated under.
- 49 words maximum. Describe a control-plane dependency that remained foreign after application data had been localised, and how you exposed it.
- 49 words maximum. Which evidence would you require before declaring a cloud administrable during total loss of its overseas parent services?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.