What you’ll learn in this article…
- NIST RAMPS awarded FAU $200,000 for quantum cybersecurity workforce training.
- Post-quantum cryptography job postings reached 221 open roles, mostly security work.
- BLS publishes no dedicated quantum security salary, only adjacent security roles.
A $200,000 NIST RAMPS award to Florida Atlantic University puts public money behind quantum-aware cybersecurity training, including a D-Wave Advantage2 quantum computer slated for the Boca Raton campus. That is a concrete shift, not a white paper.
For students and career changers, the practical questions are narrower: which degree, certificate, or cybersecurity certification actually maps to post-quantum roles, and which salary figures are real. The distinction between post-quantum cryptography, quantum cryptography, and NICE framework tools shapes those choices more than most program pages admit.
The funding signals a market expectation: employers in critical infrastructure will ask for migration-ready security skills well before the first quantum attack happens.
What the NIST RAMPS Grant to FAU Signals for Students
Most cybersecurity students still choose between a general online cybersecurity program and a quantum specialization that exists mostly on paper. The sharper line now runs between programs that treat quantum-safe security as a future topic and those that give you hands-on access to quantum hardware through hands-on cybersecurity labs and industry partners. Florida Atlantic University's $200,000 NIST RAMPS cooperative agreement lands firmly on the second side.1
FAU is one of nine organizations in eight states selected in NIST's September 2026 RAMPS round, which awarded more than $1.7 million to build regional cybersecurity workforce partnerships.2 Other awardees include University of Houston, University of Tennessee, Wright State, New Mexico Highlands, and Kentucky Community and Technical College.2 FAU's project, 'Building the Quantum Cybersecurity Workforce in the Palm Beach and Treasure Coast Region,' will serve Palm Beach, Broward, Martin, St. Lucie, and Indian River counties.3 Partners include D-Wave Quantum Inc., InfraGard South Florida, the School District of Palm Beach County, Broward County Public Schools, and FAU's Alexander D. Henderson University School.3 A D-Wave Advantage2 system is coming to FAU's Boca Raton campus, giving students access to a 4,400+ annealing quantum computer with hands-on training and curriculum development focused on power systems infrastructure.1
What This Means for Your Degree Plan
Look for programs with direct lab access, named industry partners, and a critical infrastructure focus, not just cryptography theory.
Keep the Scale in Perspective
A single $200,000 grant is a signal of demand, not a hiring surge. Treat it as evidence that quantum cybersecurity is becoming a funded workforce priority, especially in regions like South Florida.
Quantum Cybersecurity, Post-Quantum Cryptography and Quantum Cryptography: Which Is Which?
Most security jobs labeled "quantum" are post-quantum cryptography jobs, not quantum physics jobs. The distinction matters more than the title on the posting.
Post-quantum cryptography is the main event
Post-quantum cryptography, or PQC, means classical algorithms designed to resist attacks from a future quantum computer. It runs on ordinary computers and fits directly into existing security teams. This is where nearly all current quantum security hiring sits, including entry-level cybersecurity jobs and specialized roles.
Quantum cryptography is a hardware niche
Quantum cryptography, often called quantum key distribution or QKD, uses the physics of quantum states to exchange encryption keys. It requires specialized hardware, limited distance, and far fewer job openings. It is a real field, but not the one most students should build a cybersecurity degree plan around.
Quantum computing is the threat, not the job title
Quantum computing itself is the research and engineering field building the machines that threaten current encryption. "Quantum cybersecurity" is a loose umbrella term that may cover any of these.
The reason employers care today is "harvest now, decrypt later." Attackers can capture encrypted data now, store it, and decrypt it once quantum computers become capable. That makes PQC a current workforce problem, not a distant research exercise.
On job boards, search "post-quantum cryptography," "PQC," "quantum-safe security," and "cryptographic agility." Avoid searching only "quantum computing" unless you specifically want hardware or research roles.
NIST Post-Quantum Standards Every Job Seeker Should Know
Job seekers do not need to memorize every NIST specification, but familiarity with these standards signals that you understand the post-quantum transition already underway. The table below separates finalized standards, draft documents, and the classical algorithms being phased out.
| Standard | Algorithm (Common Name) | Purpose | Status / Key Date |
|---|---|---|---|
| FIPS 203 | ML-KEM | Key-encapsulation mechanism | Final; published August 13, 2024 |
| FIPS 204 | ML-DSA | Generate and verify digital signatures | Final; published August 13, 2024 |
| FIPS 205 | SLH-DSA | Digital signatures for detecting unauthorized data modification and authenticating the signatory | Final; published August 13, 2024 |
| Draft FIPS 206 | FN-DSA (based on FALCON) | Digital signatures | Draft under development; NIST released the draft for public comments in 2025 |
| HQC | HQC | Key-encapsulation mechanism | Selected for standardization on March 11, 2025; draft standard underway |
| NIST IR 8547 transition guidance (RSA) | RSA | Public-key cryptography used for key establishment and digital signatures | 112-bit security-strength RSA: deprecated after 2030 and disallowed after 2035; RSA with at least 128-bit security strength: disallowed after 2035 |
| NIST IR 8547 transition guidance (ECC) | ECC | Public-key cryptography used for key establishment and digital signatures | NIST IR 8547 transition tables specify deprecation after 2030 and disallowance after 2035 for applicable classical elliptic-curve mechanisms |
What Post-Quantum Cryptography Jobs Actually Involve
A recent national scan of post-quantum cryptography job postings counted 221 open roles,1 pointing to a small but defined market that splits into engineering, migration, and governance work. Most of these jobs are conventional security or cryptography roles with a PQC migration scope, so few titles actually say "quantum."
Common Role Families
- Applied cryptography / PQC engineer: Implements and tests post-quantum algorithms in libraries, prototypes, or products. Day-to-day work includes writing C, C++, or Python, benchmarking lattice-based and hash-based schemes, and hardening TLS, SSH, or IPsec stacks.
- Crypto-agility or migration analyst: Builds a cryptographic inventory by finding where RSA and ECC are used across applications, services, certificates, and vendors. They map dependencies, track algorithm usage, and draft migration sequence plans.
- Security architect / PQC architect: Leads enterprise readiness assessments, reviews cryptographic bills of materials, and designs transition roadmaps for Federal or financial environments. Vendor assessment and executive reporting are central.
- Quantum-risk or GRC cybersecurity specialist: Translates NIST standards and quantum risk into policy, controls, and stakeholder briefings. They often work in government, defense contracting, or regulated finance.
- Researcher: Focuses on cryptanalysis, lattice-based and hash-based cryptography, finite field arithmetic, or formal verification, typically at national labs, large tech firms, or universities.
The Skills That Recur
Postings repeatedly ask for applied cryptography, NIST PQC standards such as FIPS 203, 204, and 205,2 PKI and key management, TLS, and risk assessment. Strong communication matters as much as technical depth because these roles must explain migration impact to both engineers and executives. Employers are concentrated in government, defense contracting, finance, large tech, and vendors. Government-facing roles often involve Federal systems, so clearance suitability can matter, but postings do not show a uniform clearance requirement.
Related Articles
How NIST NICE Framework Work Roles Map to Quantum Security Tasks
The 2026 NICE Framework distributes quantum-safe responsibilities across existing work roles. Cryptography itself appears as a competency area, NF-COM-006, rather than a standalone work role. The table below maps roles and competency areas to post-quantum cryptography and crypto-agility tasks.
| NICE Work Role | Role ID | PQC / Crypto-Agility Task It Covers | Typical Background |
|---|---|---|---|
| Security Architect | SP-ARC-002 | Designs enterprise and systems security throughout the development life cycle; relevant to embedding post-quantum cryptography and crypto-agility requirements into architecture and system design. | Background in enterprise and systems security architecture across the development life cycle. |
| Systems Security Analyst | 461 | Responsible for analysis and development of integration, testing, operations, and maintenance of systems security; relevant to assessing, integrating, testing, operating, and maintaining PQC-enabled systems. | Background in systems-security analysis, integration, testing, operations, and maintenance. |
| Risk Analyst | N/A | Performs risk analysis, including threat, vulnerability, and probability-of-occurrence analysis, when an application or system undergoes a major change; relevant to evaluating quantum risks and PQC-migration risks during major system changes. | Background in threat, vulnerability, and probability-of-occurrence analysis for applications and systems. |
| Cybersecurity Supply Chain Risk Management | OG-WRL-017 | Addresses cybersecurity supply-chain risk management; relevant to evaluating vendor, component, dependency, and procurement risks associated with PQC migration and cryptographic-agility requirements. | Background in cybersecurity supply-chain risk management. |
| Security Control Assessor | N/A | Assesses security controls; relevant to evaluating whether PQC migration and crypto-agility controls are appropriately designed, implemented, and operating. | Background in security-control assessment. |
| Cryptography competency area | NF-COM-006 | Describes capabilities to transform data using cryptographic processes so that only authorized persons can read it; directly relevant to selecting, implementing, and migrating cryptographic mechanisms, including PQC. | Background in cryptographic processes and protection of data from unauthorized access. |
Degree Vs. Certificate Vs. Certification for Post-Quantum Careers
Choosing a post-quantum credential usually means deciding among a degree, a course certificate, or a professional certification. Each path serves a different purpose, so aligning the credential with your current experience and target role is more useful than treating them as interchangeable. Below is a side-by-side view of what each option tends to offer.
| Aspect | Degree | Certificate | Certification |
|---|---|---|---|
| Primary purpose | Builds academic foundation in computer science, IT, or a related field, with possible cryptography and quantum electives. | Provides targeted, short-form training in post-quantum cryptography or quantum-safe security topics. | Validates existing professional security knowledge and experience through an external exam. |
| Example credential | Master's in computer science, information technology, or a related field. | University or vendor course certificate in post-quantum cryptography or quantum computing foundations. | CISSP, CISM, or GIAC cryptography-related certification such as GCTI. |
| Typical time commitment | Varies widely by program and pace; no universal duration applies. | Usually weeks to months, depending on the course format and depth. | CISSP and CISM require at least five years of relevant professional experience; exam preparation time varies. |
| Cost example (USD) | Tuition varies by institution, program format, and residency; no single cost applies. | Varies; university and vendor course fees are generally lower than degree tuition. | CISSP exam fee is 749; CISM is 575 for ISACA members or 760 for nonmembers; GIAC pricing varies, with listed examples from 399 to 999. |
| Role level supported | May support advanced technical, engineering, architecture, research, or specialist roles; not required for all security positions. | Generally supports skill-building for current or future security professionals; not independently a senior qualification. | CISSP and CISM support mid-level and senior security professionals; GIAC credentials support technical practitioners at varying levels. |
| Strongest use case | Academic, research-heavy, or advanced technical pathways where deeper computer science and cryptography preparation is valuable. | Targeted upskilling for a specific post-quantum cryptography skill or tool. | Externally validated security-practice competence for hiring, promotion, or program leadership. |
| Post-quantum readiness limitation | A master's alone does not guarantee hands-on post-quantum cryptography implementation expertise. | A course certificate shows exposure to PQC concepts but may not carry broad industry recognition. | CISSP and CISM are broad or management-focused and do not by themselves prove PQC implementation skill; GIAC relevance depends on the specific credential and syllabus. |
Questions to Ask Yourself
Universities and Regions Building Quantum Cybersecurity Tracks
The cybersecurity career path for quantum-safe security professionals is still forming, and the clearest signal this year is regional investment rather than a single standardized degree.
Programs and Gateways Worth Watching
- Dakota State University: A 12-credit, fully online Quantum Computing for Cybersecurity Graduate Certificate that starts in fall and spring and covers post-quantum encryption, quantum cryptography, and quantum key distribution.1
- Florida Atlantic University: The NIST RAMPS-backed effort is not yet a named certificate, but it pairs curriculum development with a hosted D-Wave Advantage2 quantum computer and connects students to employers across five South Florida counties.2
- University of Maryland, Baltimore County: Its online Introduction to Post-Quantum Cryptography through edX is a focused short course, though published credit hours are not available.3
- Northern Arizona University: Offers PHY599, a graduate-level Quantum and Post Quantum Cryptography course.4
- MIT: Graduate course 6.S976/18.S996 spans quantum key distribution, quantum money, post-quantum cryptography, and unclonable cryptography.5
How to Evaluate a Program
- Coursework: Look for explicit post-quantum cryptography or quantum-safe encryption, not just quantum computing theory.
- Hands-on access: Ask whether you will use simulators, real quantum hardware, or labs tied to energy and critical infrastructure.
- Partners: RAMPS-style regional alliances tend to create cybersecurity internships, apprenticeships, and employer pipelines that are hard to find elsewhere.
A final caution: many quantum computing programs teach qubits, algorithms, and hardware physics without requiring you to migrate a cryptographic system or understand NIST's post-quantum standards. Read the course list before enrolling. If the credits lean toward physics or abstract quantum mechanics, you may be building a different skill than a security team needs.
A degree with quantum in the name is less important than whether you can apply cryptographic fundamentals and hands-on security skills to real post-quantum threats.
Quantum Security Salary and Outlook: What We Can and Can't Say
The U.S. Bureau of Labor Statistics does not publish a separate quantum security occupation, so the three rows below are adjacent 2025 occupational baselines only. They show pay and employment for related computer and information security roles, not pay for any one degree program or quantum-focused role. Across recent job postings and aggregator surveys, advertised quantum cryptography and post-quantum cryptography salary bands tend to cluster from about $77,600 to $224,100, with some director-level or specialized postings reaching above $300,000. Those posting-based figures vary by employer, location, clearance, and experience and should be read as market signals, not guaranteed salaries.
| Occupation (2025 BLS) | 25th percentile pay | Median pay | 75th percentile pay | Estimated employment |
|---|---|---|---|---|
| Information Security Analysts | $97,810 | $129,180 | $163,500 | 190,650 |
| Network and Computer Systems Administrators | $78,010 | $99,130 | $126,640 | 314,340 |
| Computer Occupations, All Other | $79,370 | $116,580 | $157,500 | 435,370 |
A Practical Degree Plan for Students and Career Changers
A practical degree plan is a sequence of courses, credentials, and on-the-job tasks that moves you from general cybersecurity knowledge toward the quantum-safe skills employers are starting to request. A quantum physics PhD is not required; what matters is layering the right electives, projects, and certifications on top of a solid security foundation.
If you are starting a bachelor's degree
A cybersecurity major, a math major, or a computer science cybersecurity degree is the most direct route. Add elective coursework in cryptography, number theory, and discrete math, then complete an applied post-quantum cryptography project. A strong option is a crypto inventory of your university's laboratory systems or an experiment with an open-source library such as liboqs and the ML-KEM algorithm. This turns an abstract standard into a portfolio item.
If you are already working in IT or security
Build crypto-agility and public key infrastructure experience in your current role. Read NIST IR 8547, the transition guidance for post-quantum cryptography, and the related FIPS standards. Then use the Cybersecurity Certifications Guide to pick one certification that matches your role, such as a security or cloud credential with cryptography content, rather than collecting several at once.
When a master's degree or graduate certificate makes sense
A master's degree or a cybersecurity graduate certificate online is worth it if you want a design, research, or leadership role in quantum-safe systems or if your undergraduate program lacked cryptography depth. It is less useful if you already have strong work experience and only need a targeted certification. For government and defense jobs, factor in clearance eligibility early; an internship through a regional workforce program, like the NIST-funded partnership in South Florida, can provide both security experience and a clearance sponsor.










