Position: C-SCRM & Post-Quantum Cryptography Subject Matter Expert (Anticipated Position)
Location: Remote / Virtual
Employment: Full-Time or Contract
Clearance: Active Top Secret with SCI eligibility required
*Note: This position has not yet been funded. We are currently soliciting resumes from interested candidates in anticipation of a contract award.
Background: Navanti Group is seeking a senior Cybersecurity Supply Chain Risk Management (C-SCRM) and Post-Quantum Cryptography (PQC) Subject Matter Expert to support a federal customer in strengthening enterprise supply-chain risk management and preparing acquisition processes for emerging cryptographic requirements.
The SME will support government stakeholders to improve C-SCRM strategy, vendor-risk assessment processes, risk-scoring methodologies, documentation, implementation guidance, and post-quantum cryptography readiness.
Responsibilities: - Develop and refine an enterprise C-SCRM strategy and implementation plan
- Assess existing supplier and vendor risk-management processes and recommend improvements
- Develop standardized C-SCRM risk frameworks, methodologies, guides, and operating procedures
- Review and improve vendor-risk questionnaires, scoring criteria, and assessment methodologies
- Conduct analysis of post-quantum cryptography readiness within a federal acquisition environment
- Develop a PQC readiness roadmap aligned with NIST and applicable federal cybersecurity guidance
- Advise government stakeholders on cryptographic algorithms, modernization requirements, and emerging PQC risks
- Support development of repeatable processes for identifying, assessing, documenting, and mitigating cybersecurity supply-chain risks
- Translate complex cybersecurity, supplier, and technology risks into practical acquisition and risk-management decisions
- Support project management, quality management, status reporting, and transition activities
Required Qualifications: - Minimum 3 years of experience establishing or managing a risk-management program that includes C-SCRM
- Demonstrated experience with cybersecurity supply-chain risk management, supplier/vendor risk, and third-party risk assessment
- Minimum 3 years of experience working with cryptographic algorithms
- Experience developing cybersecurity or risk-management strategies, frameworks, assessment methodologies, scoring models, SOPs, or implementation guidance
- Experience supporting the types of activities described above, including C-SCRM strategy, vendor-risk assessments, documentation, questionnaires, scoring, and implementation guidance
- One or more senior cybersecurity/risk certifications such as CISSP, CISM, CRISC, or equivalent
- Strong written and verbal communication skills and the ability to advise senior government stakeholders
Desired Skills and Experience: - Direct experience with post-quantum cryptography and federal PQC transition requirements
- Knowledge of NIST SP 800-161 and related federal C-SCRM guidance
- Experience supporting federal acquisition, procurement, or GSA environments
- Experience developing supplier-risk scoring methodologies or technology/vendor assessment frameworks
- Experience translating technical cybersecurity risk into acquisition or executive decision-support products
Ideal Candidate: The strongest candidate will combine hands-on C-SCRM program experience with deep cybersecurity risk-management expertise and meaningful cryptographic experience. This is not simply a general cybersecurity role. The successful candidate must be able to independently advise a federal customer on both supply-chain risk management and cryptographic modernization.
#CJ