C-SCRM & Post-Quantum Cryptography Subject Matter Expert (Anticipated Position)

Navanti Group

Arlington (VA)

On-site

USD 120,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Navanti Group seeks a senior Cybersecurity Supply Chain Risk Management (C-SCRM) and Post-Quantum Cryptography (PQC) Subject Matter Expert to support a federal customer in strengthening enterprise supply-chain risk management and preparing acquisition processes for emerging cryptographic requirements.

The SME will help government stakeholders improve C-SCRM strategy, vendor-risk assessments, risk-scoring methodologies, documentation, and PQC readiness, with responsibilities including developing

Qualifications

  • Minimum 3 years of experience establishing or managing a risk-management program that includes C-SCRM.
  • Demonstrated experience with cybersecurity supply-chain risk management, supplier/vendor risk, and third-party risk assessment.
  • Minimum 3 years of experience working with cryptographic algorithms.
  • Experience developing cybersecurity or risk-management strategies, frameworks, assessment methodologies, scoring models, SOPs, or implementation guidance.
  • Experience supporting C-SCRM strategy, vendor-risk assessments, documentation, questionnaires, scoring, and implementation guidance.
  • One or more senior cybersecurity/risk certifications such as CISSP, CISM, CRISC, or equivalent.
  • Strong written and verbal communication skills and the ability to advise senior government stakeholders.

Responsibilities

  • Develop and refine an enterprise C-SCRM strategy and implementation plan.
  • Assess existing supplier and vendor risk-management processes and recommend improvements.
  • Develop standardized C-SCRM risk frameworks, methodologies, guides, and operating procedures.
  • Review and improve vendor-risk questionnaires, scoring criteria, and assessment methodologies.
  • Conduct analysis of post-quantum cryptography readiness within a federal acquisition environment.
  • Develop a PQC readiness roadmap aligned with NIST and applicable federal cybersecurity guidance.
  • Advise government stakeholders on cryptographic algorithms, modernization requirements, and emerging PQC risks.
  • Support development of repeatable processes for identifying, assessing, documenting, and mitigating cybersecurity supply-chain risks.
  • Translate complex cybersecurity, supplier, and technology risks into practical acquisition and risk-management decisions.
  • Support project management, quality management, status reporting, and transition activities.

Skills

C-SCRM program
Risk assessment
Cryptographic algorithms
Documentation guidance
SOP development
Stakeholder communication

Education

CISSP/CISM/CRISC

Job description

DEVELOP YOUR CAREER
Navanti Group is a young company with significant growth potential, and we offer rapid advancement for those who excel. The success of our company lies in the quality of our people, which is why we will work hard to foster your talents and develop your career.

Do really interesting work
Work on innovative projects in international security, countering radicalization, new media, and business development.

Have a voice
We eschew traditional hierarchies because they stunt potential. We believe everyone has unique value to add regardless of age or title. We celebrate great ideas that can help our clients meet their objectives, and so we have institutionalized the practice of idea-sharing and development at all levels.

We honor drive and excellence
Our meritocratic system provides great rewards to those who excel and drive the business.

Be creative
We encourage fresh thinking because that's what drives innovation in our field.

Navanti provides equal employment opportunities (EEO) to all employees and qualified applicants for employment without regard to race, color, religion, gender, gender identity, sexual orientation, ancestry, national or ethnic origin, age, marital status, handicap, disability, or status as a Veteran. We do not tolerate discrimination in any form and take measures to prevent discrimination against any employee or job applicant. We have a zero-tolerance policy for sexual harassment, exploitation, and/or abuse of power.

C-SCRM & Post-Quantum Cryptography Subject Matter Expert (Anticipated Position)

Position: C-SCRM & Post-Quantum Cryptography Subject Matter Expert (Anticipated Position)

Location: Remote / Virtual

Employment: Full-Time or Contract

Clearance: Active Top Secret with SCI eligibility required

*Note: This position has not yet been funded. We are currently soliciting resumes from interested candidates in anticipation of a contract award.

Background:

Navanti Group is seeking a senior Cybersecurity Supply Chain Risk Management (C-SCRM) and Post-Quantum Cryptography (PQC) Subject Matter Expert to support a federal customer in strengthening enterprise supply-chain risk management and preparing acquisition processes for emerging cryptographic requirements.

The SME will support government stakeholders to improve C-SCRM strategy, vendor-risk assessment processes, risk-scoring methodologies, documentation, implementation guidance, and post-quantum cryptography readiness.

Responsibilities:

  • Develop and refine an enterprise C-SCRM strategy and implementation plan
  • Assess existing supplier and vendor risk-management processes and recommend improvements
  • Develop standardized C-SCRM risk frameworks, methodologies, guides, and operating procedures
  • Review and improve vendor-risk questionnaires, scoring criteria, and assessment methodologies
  • Conduct analysis of post-quantum cryptography readiness within a federal acquisition environment
  • Develop a PQC readiness roadmap aligned with NIST and applicable federal cybersecurity guidance
  • Advise government stakeholders on cryptographic algorithms, modernization requirements, and emerging PQC risks
  • Support development of repeatable processes for identifying, assessing, documenting, and mitigating cybersecurity supply-chain risks
  • Translate complex cybersecurity, supplier, and technology risks into practical acquisition and risk-management decisions
  • Support project management, quality management, status reporting, and transition activities

Required Qualifications:

  • Minimum 3 years of experience establishing or managing a risk-management program that includes C-SCRM
  • Demonstrated experience with cybersecurity supply-chain risk management, supplier/vendor risk, and third-party risk assessment
  • Minimum 3 years of experience working with cryptographic algorithms
  • Experience developing cybersecurity or risk-management strategies, frameworks, assessment methodologies, scoring models, SOPs, or implementation guidance
  • Experience supporting the types of activities described above, including C-SCRM strategy, vendor-risk assessments, documentation, questionnaires, scoring, and implementation guidance
  • One or more senior cybersecurity/risk certifications such as CISSP, CISM, CRISC, or equivalent
  • Strong written and verbal communication skills and the ability to advise senior government stakeholders

Desired Skills and Experience:

  • Direct experience with post-quantum cryptography and federal PQC transition requirements
  • Knowledge of NIST SP 800-161 and related federal C-SCRM guidance
  • Experience supporting federal acquisition, procurement, or GSA environments
  • Experience developing supplier-risk scoring methodologies or technology/vendor assessment frameworks
  • Experience translating technical cybersecurity risk into acquisition or executive decision-support products

Ideal Candidate:

The strongest candidate will combine hands-on C-SCRM program experience with deep cybersecurity risk-management expertise and meaningful cryptographic experience. This is not simply a general cybersecurity role. The successful candidate must be able to independently advise a federal customer on both supply-chain risk management and cryptographic modernization.

Equal Opportunity Statement

Navanti Group, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote C-SCRM & Post-Quantum Crypto SME
Remote C-SCRM & Post-Quantum Crypto SME

Navanti Group • Arlington (VA)

On-site
USD 120,000 - 190,000
Cybersecurity Analyst – Post-Quantum Cryptography (PQC) and Cryptographic Inventory
Cybersecurity Analyst – Post-Quantum Cryptography (PQC) and Cryptographic Inventory

Novul Solutions • Alexandria (VA)

On-site
USD 105,000 - 145,000
Paid Time Off (PTO)
401(k) with a 3% match
Comprehensive health insurance
+1
Quantum Computing / Cryptography Engineer New
Quantum Computing / Cryptography Engineer New

Mks2, Llc • Washington

On-site
USD 200,000 - 230,000
Cybersecurity Architect – Cyber Supply Chain Risk Management (C-SCRM)
Cybersecurity Architect – Cyber Supply Chain Risk Management (C-SCRM)

AnaVation LLC • Fort Meade (MD)

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Disability insurance
+5
Cybersecurity Architect – Cyber Supply Chain Risk Management (C-SCRM)
Cybersecurity Architect – Cyber Supply Chain Risk Management (C-SCRM)

Nava • Fort Meade (MD)

On-site
USD 205,000 - 235,000
Medical insurance
Dental insurance
Disability insurance
+6
Quantum Cryptography Policy, Strategy, and Migration SME
Quantum Cryptography Policy, Strategy, and Migration SME

Core4ce Careers • Washington

On-site
USD 180,000 - 240,000
401(k) with company match
Comprehensive medical, dental, and vis
Training and certifications
+2
Quantum Computing / Cryptography Engineer
Quantum Computing / Cryptography Engineer

ClearFocus Technologies • Washington

On-site
USD 180,000 - 240,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Cybersecurity SME/Security Control Assessor
Senior Cybersecurity SME/Security Control Assessor

QinetiQ U.S. • Chantilly (VA)

On-site
USD 150,000 - 185,000
Cryptography Engineer
Cryptography Engineer

Phase2 Technology • Chantilly (VA)

On-site
USD 112,000 - 257,000
COMSEC & Cryptographic Modernization Architect – G-6
COMSEC & Cryptographic Modernization Architect – G-6

Missing Link Security • Fort Belvoir (VA), Northern (KY)

Hybrid
USD 170,000 - 210,000