Confidential mandate
Quantum-Safe Cryptography Transition Director — Securities Infrastructure
Planned Hiring / New
Quantum-Safe Cryptography Transition Director mandate in Tokyo, Japan · Securities Infrastructure
A Tokyo securities utility needs an independent director to inventory cryptographic dependency, prioritise harvest-now risk and deliver a tested quantum-safe transition blueprint within eight months.
The mandate
Long-lived transaction and participant data depend on cryptography scattered across applications, appliances, certificates and partner protocols. Existing inventories find certificates but miss hard-coded algorithms, proprietary message formats, backup archives and third-party signing dependencies. The defined problem is to create an executable transition sequence addressing harvest-now exposure and operational interoperability, not a speculative quantum forecast or wholesale platform replacement.
Deliverables are a cryptographic inventory, data-longevity model, dependency graph, algorithm policy, hybrid migration patterns, pilot results, vendor requirements and multi-year roadmap. Each asset record must connect protected information, confidentiality horizon, protocol counterparties, key ownership, change window and rollback route so migration waves reflect actual settlement dependencies.
Milestone one on 27 November 2026 accepts inventory and risk tiers; milestone two on 29 January 2027 delivers target patterns; milestone three on 26 March concludes pilots across one participant interface and archival flow; final delivery on 28 May requires tested sequencing and council acceptance. Formal reviews record incompatible counterparties and unresolved vendor commitments.
Acceptance requires sampled assets to trace to owners, pilots to meet performance, message-size and interoperability tolerances, rollback to work and budget estimates to reconcile with platform plans. A mixed-version participant test and recovery from failed hybrid negotiation are mandatory. Operators must repeat discovery and policy checks unaided before the council releases final payment.
The client provides code scanning, certificate, appliance and protocol data, test participants and architecture owners, with access disputes resolved within three working days. The consultant cannot set regulatory policy, change production algorithms or select vendors; management retains production risk, participant communication and procurement decisions.
Why this is external work
Platform teams see only their local cryptography and vendors promote proprietary migration paths. Internal architecture lacks concentrated post-quantum test experience. Independent direction produces a comparable, technology-neutral plan.
What you will own
- Inventory algorithms, keys, certificates, libraries, appliances, protocols, counterparties and protected-data lifetimes with accountable owners and discovery confidence.
- Rank exposure by confidentiality horizon, replacement friction, algorithm concentration, external coordination and operational interoperability.
- Define algorithm and crypto-agility policies with explicit legacy exception, compensating protection and retirement treatment.
- Design hybrid migration patterns for participant messaging, archives and administrative access.
- Pilot approved post-quantum mechanisms under realistic latency, size and failure conditions.
- Test rollback, mixed-version operation, negotiation failure and supplier dependency across representative transition states.
- Deliver costed migration waves, procurement requirements, interoperability gates and governed inventory maintenance through a client-run refresh.
Candidate qualifications
- Directed cryptographic transformation in financial-market or other critical infrastructure with multi-party protocol dependencies.
- Built cryptographic inventories beyond certificate discovery to application, appliance, archival and external protocol dependency.
- Implemented hybrid or post-quantum pilots with measurable latency, message-size, failure and interoperability constraints.
- Governed PKI, HSM, key lifecycle, application libraries and crypto-agility architecture as one transition portfolio.
- Worked through multi-party interoperability, data-longevity, performance and long-retention confidentiality risks with external participants.
- Delivered board-approved investment sequencing without overstating quantum timelines or claiming immediate universal algorithm replacement across heterogeneous estates.
Non-negotiables
- Available across Tokyo, Osaka and Singapore milestones.
- Independent of cryptographic and appliance vendors evaluated.
- Will contract against discovery and pilot acceptance evidence.
- Has director or principal cryptography authority in critical systems.
- 49 words maximum. Which cryptographic dependency is most likely to escape automated inventory?
- 49 words maximum. Describe a post-quantum pilot whose operational result changed migration sequencing.
- 49 words maximum. How would you value harvest-now exposure without asserting a quantum date?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.