Practice Director- Post Quantum Cryptography- Remote (Anywhere in the U.S.)
General Description
We are looking for an experienced Practice Director to build and lead GuidePoint’s Post-Quantum Cryptography (PQC) advisory practice within the GRC division. This role will drive the development and delivery of PQC readiness assessments, cryptographic migration strategies, and quantum-risk advisory services while providing “Wow Them” service to clients and internal stakeholders.
The Practice Director — Post-Quantum Cryptography will be responsible for directing a portfolio of PQC services, projects, and resources for GuidePoint’s customers in North America. This leader will establish GuidePoint as a market leader in post-quantum cryptographic readiness, helping organizations navigate the transition to quantum-resistant algorithms and cryptographic agility.
The Practice Director will be required to demonstrate deep expertise in applied cryptography and public key infrastructure, strong business and financial acumen, and the ability to lead by influence to drive the adoption of progressive post-quantum security programs aligned with evolving NIST standards and federal mandates.
About the GRC Practice
The Governance, Risk & Compliance (GRC) Practice is responsible for helping organizations assess, build, and mature their cybersecurity programs. We deliver advisory, assessment, and implementation services across compliance frameworks, risk management, security governance, data governance, data privacy, AI governance, cyber resilience, strategic advisory, and other emerging governance services.
Our team of consultants, assessors, and advisors focuses on regulatory compliance, enterprise risk management, data privacy, and executive advisory services. We partner with CISOs, executive teams, and boards to drive measurable security outcomes.
Post-Quantum Cryptography is a new, high-growth service line addressing the emerging threat quantum computing poses to current cryptographic standards
The PQC practice will operate alongside our Compliance, Risk Management, Governance, and Strategic Advisory sub-practices
This role represents a greenfield opportunity to build a practice from the ground up
Roles and Responsibilities
Practice Leadership & Growth
Build and lead GuidePoint’s Post-Quantum Cryptography advisory practice from the ground up — defining service offerings, delivery methodologies, and go-to-market strategy.
Develop and execute a growth strategy for expanding GuidePoint’s PQC portfolio, including cryptographic inventory assessments, PQC migration roadmaps, crypto-agility advisory, and quantum risk quantification.
Manage the Practice’s P&L and achieve target KPIs for revenue, utilization, and margin.
Recruit, mentor, and develop a team of PQC consultants and cryptographic engineers to deliver services and advance internal practice objectives.
Ensure alignment of the PQC practice with GuidePoint’s broader GRC mission and service ecosystem.
Engage with GuidePoint’s regional leadership to drive a culture of collaboration, integrity, and shared success across geographically distributed teams.
Lead strategic sales efforts through conference speaking, blog/whitepaper authoring, and podcast participation.
Lead the sales process through generation of thought leadership content, proposal development, and developing executive relationships.
Create new sales, marketing, and delivery collateral specific to PQC services and improve existing content.
Shape and approve key engagement decisions such as project scope, work breakdown, estimates, and delivery schedule.
Client Engagement & Delivery Excellence
Partner with CISOs, CTOs, Chief Information Officers, and enterprise security architects to assess cryptographic posture and develop quantum-readiness strategies.
Oversee the design and delivery of PQC readiness assessments, cryptographic inventory analysis, and migration roadmaps aligned to NIST Post-Quantum Cryptography standards (ML-KEM, ML-DSA, SLH-DSA), CNSA 2.0 guidance, and crypto-agility frameworks.
Lead assessments of cryptographic dependencies across enterprise environments — TLS/SSL, PKI, code signing, key management, HSMs, and data-at-rest encryption.
Ensure advisory engagements deliver measurable business outcomes, including reduced quantum risk exposure and clear remediation timelines.
Lead and manage pre-sales and business development activities, including executive workshops, SOW scoping, and technical presentations with client stakeholders.
Engage with client executive teams and boards as part of service delivery, translating complex cryptographic concepts into business risk terms.
Execute on cryptographic transformation programs in a leadership role, typically coordinating with peer GPS practice teams (compliance, risk management, cloud security).
Establish strong relationships and trust with customers to understand their business environments, regulatory obligations, and cryptographic dependencies.
Team Development & Operational Enablement
Serve as a coach and advocate for continuous professional development and technical excellence in applied cryptography and PQC.
Proactively mature the practice, including improving existing service offerings, creating new offerings, and mentoring team members on PQC methodologies.
Author comprehensive business and technical collateral proficiently tailored to technical, managerial, and executive audiences.
Build and sustain a high-performing team recognized for quality, depth of cryptographic expertise, and client influence.
Foster engagement, accountability, and collaboration across regional and practice boundaries.
Partner with transformation, enablement, operations, and marketing teams to strengthen practice visibility, performance, and alignment.
Work with other GuidePoint Security practices (Compliance, Risk Management, Cloud Security, Offensive Security) as part of a cohesive cross-functional team.
Thought Leadership & Market Positioning
Represent GuidePoint’s PQC practice at executive briefings, industry conferences (RSA, Black Hat, NIST workshops), and cybersecurity summits.
Contribute to the development of GuidePoint’s PQC methodologies, assessment frameworks, and migration toolkits.
Publish and present thought leadership content on post-quantum cryptography, cryptographic migration, quantum risk, and crypto-agility.
Advance GuidePoint’s reputation as a trusted partner for enterprise-level cryptographic transformation and quantum-readiness advisory.
Monitor and interpret developments in NIST PQC standardization, NSA/CNSA 2.0 timelines, and emerging quantum computing capabilities to inform service strategy and client guidance.
Required Experience and Education
12+ years of experience in cybersecurity, with deep expertise in applied cryptography, public key infrastructure (PKI), and/or cryptographic engineering.
Demonstrated experience leading advisory teams or cryptographic transformation initiatives.
Strong understanding of NIST Post-Quantum Cryptography standards and algorithms (ML-KEM/Kyber, ML-DSA/Dilithium, SLH-DSA/SPHINCS+, FN-DSA/Falcon).
Familiarity with NSA CNSA 2.0 transition timelines, FIPS 203/204/205, and federal quantum-readiness mandates (NSM-10, OMB M-23-02).
Experience engaging at Board, CXO, and CISO levels on technical and strategic cybersecurity matters.
Proven ability to design and operationalize cryptographic migration programs or enterprise-wide technology transformation initiatives.
Strong executive presence and credibility with senior business and technical leaders.
Exceptional interpersonal and communication skills; ability to translate complex cryptographic concepts into business risk language.
Strategic thinker with the ability to translate vision into actionable plans and measurable outcomes.
Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.
Preferred Experience and Education
Prior experience as a CISO, Deputy CISO, Chief Cryptographer, or senior cybersecurity executive advisor.
Certifications such as CISSP, CISM, CCISO, or specialized cryptography credentials.
MBA, MS in Cybersecurity, Computer Science, Mathematics, or equivalent advanced education.
Hands-on experience with cryptographic libraries, HSM management (Thales, Entrust, AWS CloudHSM), and key management systems.
Experience with crypto risk quantification, cryptographic inventory tools, or crypto-agility platforms (e.g., Venafi, Keyfactor, InfoSec Global).
Familiarity with FIPS 140-3 validation processes and cryptographic module testing.
Background in quantum computing concepts, quantum key distribution (QKD), or quantum-safe network architectures.
Travel Requirements
Up to 25% travel
Physical Requirements
Sedentary work
Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day