Team collaborating in a modern office setting, focused on a digital display showing 85% progress.

What Do PQC Jobs Pay? The Roles, the Qualifications and Salaries of Post-Quantum Cryptography Jobs

What do PQC jobs pay?

What types of roles are available in the PQC field?

What qualifications do I need to work there?

A rapidly growing number of people are asking those questions as post-quantum cryptography positions begin to climb out of academia and into the commercial world.

For a little background on the PQC career landscape, every U.S. federal civilian agency was required to name a post-quantum cryptography migration lead by late July. The deadline came from Executive Order 14412, signed June 22 and published in the Federal Register three days later. The order gave agency heads 30 days to identify the person and report the name to the Office of Management and Budget and the National Cyber Director.

The order also defines a PQC migration lead as an official who reports to the agency chief information officer and is responsible for agency-wide cryptographic inventory management, for developing a prioritized migration plan, and for coordinating cross-agency work. It is an unusual document. A job description written into an executive order is a pretty good indication that those jobs will follow.

That is the state of the post-quantum labor market in 2026. Demand is no longer speculative, and it is being manufactured largely by regulation rather than by any demonstrated quantum attack.

Why is Hiring Accelerating Now?

The technical trigger for this boost in PWC jobs might be rooted in standardization, specifically with NIST publishing its first three post-quantum standards in August 2024. They are FIPS 203, which specifies ML-KEM for key establishment, FIPS 204, which specifies ML-DSA for digital signatures, and FIPS 205, which specifies the hash-based SLH-DSA as a fallback signature scheme.

On the commercial side, OMB Memorandum M-26-15, issued June 24 by Director Russell T. Vought, implements the executive order for federal civilian agencies. It requires each agency to submit a PQC migration plan within 120 days, and it sets out a five-phase schedule running from 2026 to 2035. Phase 1 covers strategy and discovery through 2027. Phase 2 covers pilots and early migration through 2028. Phase 3 requires migration of high-value assets and high-impact systems to post-quantum key establishment by 2030. Phase 4 covers signature migration in 2031. Phase 5 completes the remaining estate by 2035.

In order to learn what PQC jobs might be available and what PQC jobs pay, the memorandum can provide an intriguing glimpse at tomorrow’s PQC career ladder.

The memorandum also requires each plan to include an estimate of the funding and personnel resources needed. Agencies are being asked, in writing, to say how many people this will take.

The executive order offers requirements that extended beyond government payrolls, directing the Federal Acquisition Regulatory Council to publish a proposed rule within 180 days that would require covered contractors to comply with NIST’s post-quantum standards by Dec. 31, 2030.

For national security systems, the National Security Agency’s CNSA 2.0 suite sets an earlier gate. New acquisitions must support CNSA 2.0 algorithms starting Jan. 1, 2027.

Other jurisdictions have set their own clocks. The U.K. National Cyber Security Centre published migration timelines in March 2025 that ask organizations to complete discovery by 2028, finish high-priority migration by 2031, and complete the transition by 2035. The European Commission and member states published a coordinated implementation roadmap in June 2025. It calls on all member states to begin the transition by the end of 2026 and to migrate critical infrastructure no later than the end of 2030.

The orders also recognize that one of the timelines is that quantum computers never arrive. M-26-15 states plainly that a cryptographically relevant quantum computer is not yet known to exist. The work is being funded against the possibility that encrypted data collected today is decrypted later.

What PQC Jobs Actually Exist?

Appendix B of M-26-15 Appendix C offers some insight into PQC job categories and it also reveals responsibilities that stretch across a migration program. It names a PQC cryptographic inventory and migration lead, also described as a migration program manager, who coordinates agency-wide activity and reports to senior leadership. It names a PQC technical lead, who oversees inventory, algorithm selection, testing and deployment. It names a security architect, who integrates post-quantum cryptography into zero-trust components and supports interoperability planning. It assigns accountability for prioritization and resource allocation to the CIO and CISO, budget representation to the chief financial officer, vendor requirements to program offices, and implementation to individual application and system owners.

Private-sector titles follow roughly the same functions without the consistency. Just a few:

These postings track four PQC job categories:

Discover: Building and maintaining a cryptographic inventory.

Implementation: Integrating the new algorithms into protocols, libraries, certificates and hardware.

Program management: Sequencing a multi-year migration across systems the organization does not fully control.

Research: Openings and is concentrated in universities, national laboratories and a handful of vendors. (This tends to be the smallest share)

What Experience and Qualifications do Employers Ask for in PQC Jobs?

Most listings describe an existing security or software engineering job with new algorithms attached. Employers ask for hands-on experience with public key infrastructure, TLS, key management systems and hardware security modules. They ask for working knowledge of the NIST standards by their FIPS numbers. They ask for C, C++ or Python, particularly where the work touches embedded systems or performance benchmarking.

Two skills appear more often than they did a year ago. One is automated cryptographic discovery. M-26-15 directs agencies to use automation for inventory, policy enforcement and compliance reporting, and it names the specific techniques, including software composition analysis against software bills of materials, static and dynamic application security testing to find cryptographic functions in code, and network scanning to detect protocols and cipher suites. It directs that the output populate a cryptographic bill of materials. The executive order requires CISA, working with NIST, to publish minimum elements for a CBOM within 270 days.

The other is cryptographic agility and the memorandum treats it as an architectural requirement rather than a preference. It specifies what that means in practice. Configuration-driven algorithm selection rather than compiled-in choices. Modern provider-based libraries such as OpenSSL 3.x. Protocol-level cipher suite negotiation with downgrade protection. Key management infrastructure capable of handling both classical and post-quantum key types. Agencies must also support TLS 1.3 no later than Jan. 2, 2030.

One of the difficulties in helping PQC job seekers with finding careers is that formal credentials remain unsettled. There is still no accredited degree in post-quantum cryptography and no established certifying body. A number of commercial training providers now sell post-quantum certificates, but employers have not standardized around any of them, and none carries the recognition of a CISSP. Engineering and implementation roles typically ask for a bachelor’s or master’s degree in computer science, mathematics or cybersecurity. Doctorates are concentrated in algorithm research. Government and defense work adds clearance requirements that function as a separate and often decisive filter.

The gap employers describe is not primarily mathematical. ISACA’s Quantum Computing Pulse Poll, which surveyed 2,685 professionals in digital trust fields and was published in April 2025, found that 7% of respondents reported a strong understanding of the NIST standards and 44% had never heard of them. Only 5% said their organization had a defined quantum computing strategy.

What do PQC Jobs Pay?

Published aggregator figures for post-quantum roles should be treated with caution. ZipRecruiter reported $63,546 for U.S. post-quantum cryptography roles as of July 2026, with most workers between $42,500 and $75,500. However, on closer inspection, some of these positions are part-time and might be in areas that tend to have lower salary expectations from potential workers. Those numbers are also difficult to reconcile with the disclosed pay bands on named postings, and they appear to reflect keyword matching across a wide and mismatched set of listings rather than a defined occupation.

The federal wage survey offers perhaps a more reliable assessment for the question: what do PQC jobs pay. In the Bureau of Labor Statistics Occupational Employment and Wage Statistics release covering May 2025, information security analysts numbered 190,650 nationally, with a mean annual wage of $132,510 and a median hourly wage of $62.11, or roughly $129,000 a year. The Occupational Outlook Handbook projects 29% employment growth for the occupation between 2024 and 2034 and about 16,000 openings a year over the decade.

Pay transparency laws make individual postings more useful than averages. Bank of America listed a band of $98,400 to $160,800 for a post-quantum cryptography engineer, plus eligibility for a discretionary annual award. Booz Allen Hamilton listed a projected range of $112,800 to $257,000 for a cryptography engineer working on post-quantum architectures with a security clearance requirement. The financial press reported in 2025 that a JPMorgan Chase lead security engineer role in post-quantum cryptography, based in California, carried a salary of up to $215,000.

Research pay may be a bit different. The University of Edinburgh advertised a fixed-term research associate position on post-quantum proof systems in January 2026, requiring a doctorate in cryptography or a closely related field, at £41,064 to £48,822.

Three patterns hold across the disclosed bands. Ranges are unusually wide, which reflects employer uncertainty about the level of the role rather than generosity. Clearance requirements raise the ceiling substantially. And the specialty premium sits within the senior security engineering band rather than above it. There is no evidence that post-quantum work commands its own separate pay scale.

Where Does the Work go From Here?

The next few years may be easier to forecast, because the deadlines are already published. Federal migration plans were due in October. Pilots and early migration run through 2028. Prioritized key-establishment migration must be finished by 2030, signature migration by 2031, and the remainder by 2035. Contractor obligations arrive through the Federal Acquisition Regulation, which will pull the requirement into supply chains that have no direct federal reporting line.

The standards themselves are not finished. NIST selected HQC in March 2025 as an additional key encapsulation mechanism, chosen for a different mathematical basis than ML-KEM so that a break in lattice assumptions would not compromise both. It has not been published as a final standard. FN-DSA, to be issued as FIPS 206, remains in draft, with finalization expected in late 2026 or early 2027. NIST is also evaluating further signature candidates. Each addition creates integration, validation and testing work.

This is quite a moving target and some of the information is very new and — most likely — not quite as reliable about employment data in other — more mature — fields and industries.

We should therefore mention some limitations and cautions.

The first is that this is a migration, not a permanent function. Discovery and inventory work is the most exposed, because it is also the work the federal guidance explicitly directs organizations to automate. The durable positions are more likely to be the ones defined around cryptographic agility, key management and standards tracking, which persist after the current algorithms are deployed.

The second is that job titles remain inconsistent enough to make the market hard to read. The same responsibilities appear as engineering roles at one employer, program management at another and architecture at a third. Candidates entering now are still, to a meaningful extent, defining what the job is. That is an opportunity and a source of career risk at the same time.

Leave a Comment

Your email address will not be published. Required fields are marked *