Welcome to the team: (Senior) Quantum Computing & Post-Quantum Cryptography Specialist (m/f/diverse)

-
FunctionFunction:
Risk / Credit / Financing -
LocationLocation:
Praha
Group ICT-Risk and Resilience Management is responsible for the group-wide management of cyber and information security risks and ensures an adequate and sustainable level of (cyber) security at Commerzbank through clearly defined roles and responsibilities within the security organisation. GRM-ICT RRM serves as the second line of defence (2LoD) for managing cyber and information security risks across Commerzbank.
GRM-ICT RRM establishes the ICT Policy & Control Framework, sets standards, monitors compliance, and assesses ICT risks to ensure adherence to regulatory requirements, including the Digital Operational Resilience Act (DORA). In this role, GRM-ICT RRM provides independent challenge and oversight of the 1st LoD, monitors the effectiveness and completeness of security controls, and intervenes in a controlling manner where necessary.
Your tasks
- As a (Senior) Quantum Computing & Post-Quantum Cryptography Specialist, you are the central contact for risks arising from quantum computing and the transition to post-quantum cryptography, including cryptographic migration readiness.
- You monitor and assess developments in quantum computing, PQC standards, cryptographic algorithms, regulatory requirements, and industry practices.
- You conduct structured risk assessments of cryptographic assets, including exposure to “harvest now, decrypt later” scenarios, crypto-agility gaps, legacy cryptography, and third-party dependencies.
- You advise and support internal stakeholders in identifying appropriate mitigating controls and defining risk-based priorities for PQC migration.
- You contribute to the development and quality assurance of ICT security policies, procedures, standards, and control requirements relating to cryptography and quantum-safe transformation.
- You research technology developments, innovations, and disruptions relevant to ICT risk management, with a focus on quantum technologies, cryptography, and related emerging technologies.
- You evaluate potential security implications, emerging attack vectors, and opportunities for enhanced controls resulting from relevant technology developments.
- You prepare and publish research findings, technology-risk opinions, and recommendations to inform strategic, governance, and risk-management decisions.
- You provide independent 2LoD challenge, technology-risk opinions, and residual-risk assessments to support management and governance decisions on PQC/QC-related initiatives.
- You work closely with colleagues across GRM-ICT RRM, IT, architecture, infrastructure, and external service providers on the secure implementation of cryptographic solutions.
Your Profile
- University degree in computer science, mathematics, physics, electrical engineering, cyber security, quantum technologies, or a comparable field; alternatively, equivalent professional training and relevant practical experience.
- Proven professional experience in applied cryptography, ICT security, security architecture, or ICT risk management, with sound knowledge of post-quantum cryptography, quantum-computing-related threats, cryptographic inventory, key management, crypto-agility, and cryptographic migration.
- In-depth knowledge of cryptographic technologies, certificates, security protocols, and their implementation within complex ICT environments.
- Demonstrated knowledge of relevant PQC standards, regulatory requirements, and current quantum-computing and PQC industry developments.
- Demonstrated ability to research and assess emerging technology developments, identify associated ICT risks and attack vectors, and translate research findings into practical control and governance recommendations.
- Very good analytical, conceptual, research-oriented, and solution-oriented thinking and acting.
- High self-initiative, independence, and service orientation, combined with the ability to communicate complex technical risks clearly to management and non-technical stakeholders.
- Business-fluent German and English skills, both written and spoken.
Our Benefits
30 days of vacation; Employer-funded pension; Flexible work; Employee conditions; Digital learning; Diversity; Family & job friendly; Friendly work environment; Inspiring company culture; Work-life balance
The company
Commerzbank has been present in the Czech Republic with a branch in Prague since 1992. Decades of experience combined with the world class know-how and skills of our employees enabled the Prague branch to become the second largest Commerzbank international hub globally, providing extensive services to Commerzbank worldwide, especially in IT, Finance, Risk Control, Credit Risk management, Human Resources and Procurement. In Commerzbank you will find yourself supported by a team of nearly 1,000 colleagues locally and over 30,000 co-workers globally, located in more than 40 countries, with diverse talents and backgrounds. We are an equal opportunity employer that strives to enhance our product offering by hiring individuals driven to create a positive impact in the banking world.
Contact
In case of interest please apply via this job portal.

