Team of post-quantum cybersecurity experts collaboratively working on data protection in a dimly lit room filled with computers.

Hiring a PQC Leadership Team? The Warning Signs Companies Miss When Hiring Post-Quantum Cryptography Talent

Corporate security teams in banking, healthcare and critical infrastructure are moving to hire post-quantum cryptography specialists following the National Institute of Standards and Technology’s August 2024 finalization of three encryption standards built to withstand attacks from future quantum computers.

The hiring push has run into a problem that predates quantum computing itself. There is no reliable, widely accepted way to separate a credentialed cryptographer from someone who has memorized a vendor’s talking points.

More than 2,600 digital trust, audit and risk professionals surveyed by ISACA, the international IT governance association, said they worry quantum computers will eventually break the encryption protecting today’s internet traffic. Sixty-two percent cited that risk directly, and 56% pointed to “harvest now, decrypt later,” the practice of storing encrypted data now so it can be unlocked once quantum computers are powerful enough. Only 5% of respondents said their organization treats quantum preparation as a near-term priority, according to the survey.

For roughly eight years, NIST has been running a public competition among cryptographers before settling on its first three standards, known as FIPS 203, 204 and 205, in 2024. That process created sudden, sector-wide demand for people who can inventory an organization’s existing encryption, prioritize which systems need protection first and manage a migration that touches everything from browser sessions to code-signing certificates. Universities and training providers have not caught up. Job postings across finance, defense and cloud computing now compete for a small pool of people who understand both classical cryptography and the newer, quantum-resistant math behind it.

Why Don’t Standard Security Certifications Solve the Hiring Problem?

A candidate holding a Certified Information Systems Security Professional credential, a Certified Information Security Manager designation and a SANS GIAC certification satisfies most conventional hiring checklists.

None of those credentials, on their own, teaches a practitioner how to choose between competing parameter sets within a single NIST-approved algorithm, a decision that affects both security margin and system performance. Newer, dedicated post-quantum credentials have started to appear from training providers including SANS, ISC2 and Tonex, along with academic certificate programs at several universities. These are recent additions to the market and carry far less established authority than the certifications security teams have relied on for two decades. Employers should treat any post-quantum certification as evidence a candidate has studied the material, not as proof the candidate is ready to run a migration.

Roles in this field split roughly into four tracks, inclusing research, engineering, policy and consulting, and the qualifications differ by track. Research positions developing new cryptographic schemes typically require a doctorate in mathematics or computer science. Engineering and migration roles, which make up most current openings, generally call for a bachelor’s or master’s degree in computer science, mathematics or cybersecurity, along with hands-on programming ability in Python, C, C++ or Rust.

Across every track, a candidate should be able to speak specifically about lattice-based cryptography, which underlies the ML-KEM and ML-DSA standards, and about hash-based schemes, which underlie SLH-DSA. A candidate who can only speak in generalities about “quantum-safe” technology, without naming which mathematical problem their preferred algorithm depends on, has not done the reading.

What are the Clearest Warning Signs of an Unqualified Hire or Vendor?

Security researchers have documented these patterns for decades under the label “snake oil,” and the same warning signs apply to post-quantum claims.

A vendor or candidate who describes a proprietary encryption method that cannot be examined, citing a non-disclosure agreement or trade secret, is asking a buyer to trust an unverifiable claim. Cryptographic security is supposed to rest on the secrecy of a key, not the secrecy of the method, and a scheme that has not been published for outside cryptanalysis has not been tested the way NIST’s finalists were.

Absolute language may be another tell for unqualified candidates. Terms such as “unbreakable,” “quantum-proof” or “military-grade,” used without a citation to a specific standard, function as marketing rather than a technical claim. So does a vague appeal to unnamed intelligence-agency sources suggesting quantum computers are further along than publicly known.

A qualified expert can name the specific NIST standard, or the specific round-four backup candidate under continued evaluation, that a given product implements.

Two of NIST’s own finalists illustrate why absolute certainty is itself a red flag. The Rainbow signature scheme, which had withstood cryptanalysis since 2005, was broken by researcher Ward Beullens in February 2022. One month later, researchers Wouter Castryck and Thomas Decru showed that SIKE, another finalist that had been studied for years, could be fully broken in about an hour on ordinary hardware. Both schemes had passed years of public scrutiny before failing.

That history is why cryptographers who describe residual risk and advocate hybrid deployments, pairing a classical algorithm with a post-quantum one so an attacker must break both, tend to be more trustworthy than those who promise a permanent fix. A candidate who cannot discuss what could go wrong with their own recommended approach is not describing the field accurately.

How Should Companies Structure the Hiring and Vetting Process?

ISACA’s guidance for digital trust professionals recommends forming a cross-functional working group spanning security architecture, public-key infrastructure ownership, identity management, networking, DevOps and compliance, rather than hiring a single specialist to own quantum readiness alone. That structure limits the damage if any one hire turns out to be weaker than advertised, and it matches how the actual migration work gets done, since replacing cryptography touches nearly every system in an organization.

For vendors, buyers should ask for a documented history of independent cryptanalysis, request specifics on which finalized NIST algorithm or backup candidate a product uses, and confirm the product supports hybrid configurations that allow algorithms to be swapped later without a full rebuild.

The talent gap in this field is real and likely to widen before training programs mature. The organizations that manage it well will be the ones that judge candidates and vendors on verifiable technical literacy rather than on the confidence of their claims.

Leave a Comment

Your email address will not be published. Required fields are marked *