The cybersecurity workforce gap — unfilled positions versus qualified workers — is counted in the millions globally (roughly 4-5 million by the industry's standard (ISC)²/ISC2 workforce studies in recent years, with the U.S. share in the hundreds of thousands), and simultaneously, entry-level job seekers report they cannot get hired. Both facts are real and the tension between them is the story: the shortage is overwhelmingly a shortage of experienced practitioners, produced by an industry that demands five years of experience for jobs designed to train people, pays mid-career salaries it will not pay beginners, and burns out the workers it has. The consequence for everyone else is measurable: understaffed security teams, alert fatigue, and the checklist-first security that breaches walk through.
Where the numbers come from
The canonical figure comes from ISC2's annual workforce study — a survey-based estimate of employed professionals versus positions employers want filled, with the global need near 5 million workers in recent editions and the gap (unfilled roles) around 4 million. National initiatives treat the numbers seriously: the U.S. White House's 2023-2024 national cyber workforce strategy poured funding into skills-based hiring and apprenticeships precisely because the gap was deemed an economic-security risk. Critics reasonably note that survey-defined "need" can inflate the figure — a role unfilled because its salary is set at half the market rate is counted the same as a role no qualified person exists for. Both readings are informative: the industry genuinely lacks people, and it also genuinely misprices and mismanages the people pipeline.
Why can't newcomers get in?
The structure is circular: employers demand prior experience because security errors are expensive and training is a cost someone else should bear; so juniors can't get first jobs; so the experienced pool never grows; so experienced salaries rise; so employers demand more experience. Certifications — Security+, then mid-career marks like CISSP — became the filter, but CISSP itself requires years of experience, making it an entry barrier dressed as an entry credential. The past few years added a harsher cycle: after the pandemic-era hiring surge, 2023-2025 brought layoffs to security teams along with the rest of tech, and AI-assisted tooling is quietly restructuring what entry-level analysis work looks like — the tier where humans used to get their start is exactly the tier automation absorbs first.
What is actually being done?
- Skills-based hiring: the federal government and a growing set of states dropped degree requirements; the Pentagon's cyber apprenticeships and programs like the U.S. Cyber Corps fund non-degree pipelines.
- Apprenticeships and rotational programs at large employers, converting the training burden into a structured first rung.
- Community-college and bootcamp pipelines, uneven but real; the DoD's Cybersecurity and Cyber Policy programs and similar public efforts standardize curricula.
- Automation as relief valve: vendors argue AI triage closes the gap by doing Tier-1 work; critics note it may simply delete the career ladder's bottom rung.
What does the shortage mean for organizations?
Practical posture decisions: understaffed teams must automate relentlessly (patch tooling, managed detection, email filtering — the boring stack), outsource what cannot be staffed (managed SOC services exist precisely for this market), and prioritize by exposure rather than trying to cover everything. Retention is cheaper than replacement — realistic on-call, training budgets, and sane incident rotation keep the practitioners you have. And hiring managers who keep posting five-years-required junior roles are contributing to their own future shortage.
What should someone entering the field do?
Build demonstrable skill and evidence: home labs, capture-the-flag results, bug-bounty history, contributions to open-source security tooling — artifacts that read as experience because they are. Target the adjacent-entry routes that actually convert: helpdesk-to-security internally, GRC and compliance analysis, security sales engineering, and the government pipelines with structured ladders. Get Security+ for the HR filter, then let projects do the talking. The door is narrower than the marketing of a million unfilled jobs suggests — but the work is real, the ladder, once entered, is steep in the good direction, and the field's structural need for trustworthy practitioners is not going away.
For more context, read Who pays for the open source everything runs on?.
For more context, read bug bounty.
For more context, read Why schools are ransomware's favorite target.

