Confidential mandate

Post-Quantum Cryptography Discovery & Migration Authority

Planned Hiring / New

Post-Quantum Cryptography Discovery & Migration Authority mandate in Zurich, Switzerland · Global Private Banking

A global private bank requires an independent cryptography authority to expose undocumented dependencies, prioritise quantum-vulnerable services and deliver an accepted six-week migration blueprint spanning applications, vendors and trust infrastructure.

The mandate

The bank cannot set a defensible post-quantum migration budget because certificates, embedded libraries, hardware roots of trust and third-party cryptographic services are catalogued by separate teams. The defined problem is to establish which business services depend on quantum-vulnerable public-key mechanisms, where long-lived confidential data creates an earlier exposure, and which supplier constraints govern migration order.

The principal deliverable is a cryptographic dependency and migration dossier: a traceable cryptographic bill of materials for the sampled estate, an exposure taxonomy, a crypto-agility target pattern, vendor obligations, wave sequencing and an investment range. It must distinguish discovery evidence from assumptions and use current NIST-standard transition concepts without declaring untested algorithms safe in the bank's environment.

Milestone one, due on day ten, is a reconciled discovery baseline and coverage report; milestone two, at the end of week four, is a service-ranked risk register plus laboratory findings from two representative pathways. Milestone three, at the close of week six, is the final migration dossier, procurement clauses and Board Technology Risk Committee paper.

Acceptance requires the CISO and operational-risk sponsor to reproduce the lineage from each priority service to its cryptographic dependencies, agree owners and funding ranges for the first two waves, and confirm that the proposed hybrid or replacement patterns can enter architecture governance. Unsupported inventory coverage, vendor assurances without evidence, or a roadmap lacking rollback criteria will prevent final acceptance.

The client will provide authenticated scanner access, architecture repositories, certificate records, code-search support, vendor contracts and a named working group. Production changes, algorithm certification, wholesale key-management replacement and execution of the resulting multi-year programme are outside this statement of work.

Why this is external work

Internal security architects own individual platforms and cannot independently arbitrate their competing completeness claims. The bank also lacks concentrated experience translating post-quantum discovery into service-level migration economics. An external specialist gives the board a bounded opinion without displacing accountable architecture owners.

What you will own

  • Reconcile certificate, key, library, protocol and hardware evidence into a service-linked cryptographic discovery ledger with explicit coverage confidence.
  • Classify data-retention and harvest-now-decrypt-later exposure so migration urgency reflects information lifetime rather than headline algorithm age.
  • Design laboratory tests for two representative transaction paths, recording interoperability, latency, key lifecycle and rollback observations.
  • Challenge strategic suppliers on roadmaps, interface dependencies, support windows and contract language instead of accepting generic readiness statements.
  • Sequence migration waves by customer harm, regulatory criticality, technical coupling, asset refresh cycles and feasible compensating controls.
  • Cost the first two implementation waves with sensitivity ranges for hardware, licences, engineering capacity, testing and dual-operation overhead.
  • Present a decision-ready committee dossier containing evidence gaps, accepted assumptions, architecture choices, accountable owners and stage gates.

Candidate qualifications

  • Directed enterprise cryptography or security architecture for a regulated financial institution with demonstrable accountability for keys, certificates and trust services.
  • Built a cryptographic inventory that connected code, infrastructure and supplier findings to business services rather than reporting scanner counts alone.
  • Applied NIST post-quantum transition guidance in a controlled laboratory or migration assessment and can explain its limits without overstating assurance.
  • Evaluated hybrid cryptographic patterns, protocol interoperability and performance trade-offs across legacy and modern application estates.
  • Negotiated technical evidence and transition commitments with hardware, cloud, payment-network or security-product vendors at executive level.
  • Produced board-approved cyber investment roadmaps whose cost, sequencing and residual-risk assumptions survived independent challenge.

Non-negotiables

  • Can work in Zurich for three days each week and travel twice to Geneva during the six-week engagement.
  • Holds no undisclosed commercial interest in a cryptographic algorithm, hardware-security-module provider or migration tooling vendor being assessed.
  • Will label inferred dependencies separately from observed evidence and will not issue product-certification claims.
  • Can begin discovery within three weeks and reserve sufficient capacity to meet all three fixed acceptance dates.
  1. 49 words maximum. Which cryptographic discovery programme have you led, and how did you measure service-level coverage when scanners, repositories and vendor inventories disagreed?
  2. 49 words maximum. Outline the evidence you would seek before prioritising a long-retention data service for post-quantum migration.
  3. 49 words maximum. Name one current client, investment or vendor relationship that could affect your independence on this assignment.

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.