Confidential mandate
Sovereign Cloud Exit & Portability Leader — Industrial Automation
Urgent / Replacement
Sovereign Cloud Exit & Portability Leader mandate in Berlin, Germany · Industrial Automation
An industrial automation group requires an interim cloud leader to make sovereign-hosting exit plans executable, reduce hyperscaler concentration and transfer a tested portability regime to a permanent successor.
The mandate
A board-observed resilience exercise failed when backup recovery required the same hyperscaler identity plane as the production estate, contradicting an earlier portability attestation. The infrastructure executive left after a second review found that customer sovereignty commitments, workload inventories and contractual exit rights described three incompatible versions of the group’s actual position.
The successor must enter the Berlin seat within three weeks and lead a twelve-month recovery across engineering, procurement and regional operations. A permanent search starts after the first live exit rehearsal in month six, with eight weeks reserved for overlap; the board may extend only if a named handover test remains incomplete for reasons outside the interim’s control.
The assignment ends when every material workload has a verified residency and dependency record, two tier-zero services have been recovered outside their primary provider within agreed recovery objectives, and all critical contracts have executable data-return, transition-assistance and deletion provisions. The permanent leader must witness the final exercise and sign the portability control book.
The interim may stop deployment into non-compliant regions, reprioritise the approved €35 million resilience portfolio, set cloud-engineering standards, appoint temporary workstream leads and approve purchase orders below €2 million. Provider termination, policy changes to sovereign-data classifications, capital above €5 million and permanent appointments need board or executive approval; national-security representations remain with Legal.
ERP modernisation, end-user computing and redesign of factory-control applications are excluded. The interim may require those teams to expose dependencies but is not accountable for feature migration, commercial software selection or the remediation of unrelated technical debt.
Why this seat is open
The failed exercise showed that the group had purchased contractual portability without engineering an operational exit. Because the former executive signed the disputed attestation, an internal caretaker would lack independence over the evidence review. The board wants one leader to convert sovereignty promises into repeatable recovery capability before selecting a long-term platform chief.
What you will own
- Reconcile cloud inventories, configuration records, customer covenants and procurement schedules into one board-approved workload and sovereignty register.
- Classify each dependency by residency exposure, identity coupling, proprietary service reliance, recovery criticality and realistic substitute path.
- Decide which workloads remain, become dual-operable, move to a European sovereign service or require a board-accepted concentration exception.
- Engineer two live tier-zero exits that restore data, identity, keys, observability and business transactions without privileged access to the primary provider.
- Renegotiate transition assistance, egress economics, configuration export, secure deletion and evidence rights for every critical hosting agreement approaching renewal.
- Establish portability gates for new architectures, including open interfaces, recoverable keys, infrastructure definitions, dependency bills and rehearsed fallback ownership.
- Hand over the control book, investment sequence, contract decisions, exercise evidence, leadership assessment and unresolved sovereignty exceptions to the permanent appointee.
Candidate qualifications
- Held enterprise cloud, infrastructure or technology-resilience authority for a European industrial, critical-infrastructure or similarly complex multi-country organisation.
- Executed a production workload exit from a hyperscaler or proprietary platform and can evidence recovery outcomes beyond a tabletop or contractual plan.
- Governed identity, encryption-key, observability, data-residency and network dependencies as one portability problem rather than isolated technical streams.
- Renegotiated major cloud agreements covering transition assistance, data return, deletion assurance, egress cost and operational cooperation during exit.
- Directed platform engineers and regional infrastructure teams through live service recovery while manufacturing or customer operations remained active.
- Transferred a board-visible resilience programme to a permanent successor with independently tested controls and explicit residual concentration decisions.
Non-negotiables
- Available to work from Berlin at least four days each week and travel monthly to Frankfurt, Munich and the designated secondary hosting region.
- Has led an executed provider or platform exit; strategy papers, sourcing exercises and architecture assessments alone do not meet the requirement.
- No active sales, referral or advisory arrangement with any hyperscaler, sovereign-cloud bidder or portability tool under consideration.
- Will not represent an untested migration, backup or contract clause as proof of operational exit capability.
- 49 words maximum. Confirm your earliest Berlin start date and any obligation that could prevent full-time executive service.
- 49 words maximum. Describe one live cloud exit you led, including the identity dependency that was hardest to remove and the achieved recovery time.
- 49 words maximum. Which evidence would make you reject a claimed sovereign-cloud portability control despite compliant contract language?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.