Position: C-SCRM & Post-Quantum Cryptography Subject Matter Expert (Anticipated Position)
Location: Remote / Virtual
Employment: Full-Time or Contract
Clearance: Active Top Secret with SCI eligibility required
*Note: This position has not yet been funded. We are currently soliciting resumes from interested candidates in anticipation of a contract award.
Background:
Navanti Group is seeking a senior Cybersecurity Supply Chain Risk Management (C-SCRM) and Post-Quantum Cryptography (PQC) Subject Matter Expert to support a federal customer in strengthening enterprise supply-chain risk management and preparing acquisition processes for emerging cryptographic requirements.
The SME will support government stakeholders to improve C-SCRM strategy, vendor-risk assessment processes, risk-scoring methodologies, documentation, implementation guidance, and post-quantum cryptography readiness.
Responsibilities:
- Develop and refine an enterprise C-SCRM strategy and implementation plan
- Assess existing supplier and vendor risk-management processes and recommend improvements
- Develop standardized C-SCRM risk frameworks, methodologies, guides, and operating procedures
- Review and improve vendor-risk questionnaires, scoring criteria, and assessment methodologies
- Conduct analysis of post-quantum cryptography readiness within a federal acquisition environment
- Develop a PQC readiness roadmap aligned with NIST and applicable federal cybersecurity guidance
- Advise government stakeholders on cryptographic algorithms, modernization requirements, and emerging PQC risks
- Support development of repeatable processes for identifying, assessing, documenting, and mitigating cybersecurity supply-chain risks
- Translate complex cybersecurity, supplier, and technology risks into practical acquisition and risk-management decisions
- Support project management, quality management, status reporting, and transition activities
Required Qualifications:
- Minimum 3 years of experience establishing or managing a risk-management program that includes C-SCRM
- Demonstrated experience with cybersecurity supply-chain risk management, supplier/vendor risk, and third-party risk assessment
- Minimum 3 years of experience working with cryptographic algorithms
- Experience developing cybersecurity or risk-management strategies, frameworks, assessment methodologies, scoring models, SOPs, or implementation guidance
- Experience supporting the types of activities described above, including C-SCRM strategy, vendor-risk assessments, documentation, questionnaires, scoring, and implementation guidance
- One or more senior cybersecurity/risk certifications such as CISSP, CISM, CRISC, or equivalent
- Strong written and verbal communication skills and the ability to advise senior government stakeholders
Desired Skills and Experience:
- Direct experience with post-quantum cryptography and federal PQC transition requirements
- Knowledge of NIST SP 800-161 and related federal C-SCRM guidance
- Experience supporting federal acquisition, procurement, or GSA environments
- Experience developing supplier-risk scoring methodologies or technology/vendor assessment frameworks
- Experience translating technical cybersecurity risk into acquisition or executive decision-support products
Ideal Candidate:
The strongest candidate will combine hands-on C-SCRM program experience with deep cybersecurity risk-management expertise and meaningful cryptographic experience. This is not simply a general cybersecurity role. The successful candidate must be able to independently advise a federal customer on both supply-chain risk management and cryptographic modernization.
Equal Opportunity Statement
Navanti Group, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status, or disability status.
#CJ
Skills Required
- At least 3 years of experience establishing or managing a risk-management program that includes C-SCRM
- Experience with cybersecurity supply-chain risk management, supplier or vendor risk, and third-party risk assessment
- At least 3 years of experience working with cryptographic algorithms
- Experience developing cybersecurity or risk-management strategies, frameworks, assessment methodologies, scoring models, SOPs, or implementation guidance
- Experience with C-SCRM strategy, vendor-risk assessments, documentation, questionnaires, scoring, and implementation guidance
- Senior cybersecurity or risk certification such as CISSP, CISM, CRISC, or equivalent
- Strong written and verbal communication skills and ability to advise senior government stakeholders
- Direct experience with post-quantum cryptography and federal PQC transition requirements
- Knowledge of NIST SP 800-161 and related federal C-SCRM guidance
- Experience supporting federal acquisition, procurement, or GSA environments
- Experience developing supplier-risk scoring methodologies or technology/vendor assessment frameworks
- Experience translating technical cybersecurity risk into acquisition or executive decision-support products
What We Do
Navanti Group is an applied analytics firm dedicated to delivering real-time insight into economic, political, and security trends in complex and conflict-affected environments. Utilizing primary research and open-source analysis, they provide on-demand analytical reports to support clients, including U.S. government agencies, across Africa, the Arabian Peninsula, Central Asia, the Levant, and Eastern Europe to enable informed decision-making and strategic interventions.








