Confidential mandate
Offshore-Energy Remote-Access Security Director — Subsea Operations
Planned Hiring / New
Offshore-Energy Remote-Access Security Director mandate in Oslo, Norway · Offshore Energy Operations
A North Sea operator needs an independent director to redesign remote vendor access across offshore production and subsea support, proving secure maintenance and emergency recovery within five months.
The mandate
OEMs reach offshore control and diagnostic systems through inconsistent VPNs, shared accounts and emergency workarounds. Some connections traverse corporate identity while others terminate on vendor appliances that offshore teams cannot inspect, and support contracts assume connectivity unavailable during severe weather. The defined problem is to create attributable, constrained maintenance access that remains usable during degraded offshore communications without weakening production or safety command.
Deliverables are an access inventory, trust-zone design, identity pattern, session controls, emergency mode, supplier obligations, pilot and operating runbook. Each pathway must identify equipment, permitted commands, approving offshore role, communications dependency, recording location, emergency revocation and the maintenance consequence if access is withheld.
Milestone one on 30 October 2026 accepts dependencies and risk-ranked pathways; milestone two on 4 December delivers approved design and contract requirements; milestone three on 22 January 2027 concludes two OEM pilots; final delivery on 26 February requires offshore failure exercise, remediation and handover. Each accepted milestone releases one project-fee tranche.
Acceptance requires named identities, recorded sessions, approved command paths, workable link-loss fallback and offshore operators completing emergency revocation without consultant help. One pilot must simulate a compromised OEM identity and another must lose the primary communications link; both must preserve safe local control, diagnostic evidence and an auditable decision trail.
The client supplies topology, access logs, vendor contracts, test environments and offshore windows, with authorised installation managers and OEM engineers available for rehearsals. The consultant cannot command production, approve safety risk or amend supplier contracts; client operations executes every access and isolation change.
Why this is external work
Equipment teams depend on the vendors whose access they must challenge. Corporate identity patterns ignore offshore communications and safety. Independent design can reconcile security with maintainability.
What you will own
- Inventory every interactive, machine-to-machine and emergency vendor pathway with equipment scope, communications route, credential type and business ownership.
- Map permitted maintenance commands to specific equipment, production consequence, safety dependency, approving offshore role and retained evidence.
- Design named identity, managed-device trust, brokered connectivity, command restriction and tamper-evident session recording for routine support.
- Define degraded-link and break-glass modes with bounded commands, local confirmation, short expiry and post-event reconciliation.
- Translate controls into supplier contracts, field-engineer procedures, support response times and consequences for unauthorised connection attempts.
- Pilot normal maintenance, compromised-vendor identity and communications-loss scenarios against measurable access, safety and recovery criteria.
- Transfer configurations, session evidence, exception history, supplier obligations and revocation drills through offshore operator-led exercises.
Candidate qualifications
- Designed remote access for offshore or comparable safety-critical OT with constrained communications, specialist OEM dependence and local command authority.
- Can evidence removal of shared or persistent vendor pathways without impairing fault diagnosis, warranty support or emergency maintenance.
- Integrated named identity, managed-device trust, jump services, command restriction, recording and industrial segmentation in live operations.
- Tested emergency access under degraded or lost communications, including local approval, session evidence and later credential revocation.
- Worked with OEMs, offshore operators, telecom engineers, process safety and procurement to resolve conflicting access requirements.
- Delivered client-operated controls after field acceptance, with offshore personnel independently executing normal and compromised-vendor scenarios.
Non-negotiables
- Eligible and available for offshore installation access.
- Independent of incumbent OEM and access-platform suppliers.
- Will respect offshore command and safety authorities.
- Has director or principal OT security implementation authority.
- 49 words maximum. Which offshore remote pathway would you inventory before reviewing policy?
- 49 words maximum. Describe a degraded-link access test that changed your architecture.
- 49 words maximum. What proves emergency revocation is operationally accepted?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.