Skip to content
Wednesday, August 26, 2026
KAJ NEWSCYBER · PRIVACY · SECURITY
Home / Tech News
Tech News

The cybersecurity skills shortage: how many jobs, and does it even exist?

Workforce counts show a global gap in the millions while entry-level job seekers can't get interviews — both are true, and understanding why explains a lot about the industry's failure mode.

Asha Venkataswamy, · July 18, 2026 · 4 min read
ShareXFacebookLinkedInTelegramEmail
Small security team collaborating in an understaffed operations center

The cybersecurity workforce gap — unfilled positions versus qualified workers — is counted in the millions globally (roughly 4-5 million by the industry's standard (ISC)²/ISC2 workforce studies in recent years, with the U.S. share in the hundreds of thousands), and simultaneously, entry-level job seekers report they cannot get hired. Both facts are real and the tension between them is the story: the shortage is overwhelmingly a shortage of experienced practitioners, produced by an industry that demands five years of experience for jobs designed to train people, pays mid-career salaries it will not pay beginners, and burns out the workers it has. The consequence for everyone else is measurable: understaffed security teams, alert fatigue, and the checklist-first security that breaches walk through.

Where the numbers come from

The canonical figure comes from ISC2's annual workforce study — a survey-based estimate of employed professionals versus positions employers want filled, with the global need near 5 million workers in recent editions and the gap (unfilled roles) around 4 million. National initiatives treat the numbers seriously: the U.S. White House's 2023-2024 national cyber workforce strategy poured funding into skills-based hiring and apprenticeships precisely because the gap was deemed an economic-security risk. Critics reasonably note that survey-defined "need" can inflate the figure — a role unfilled because its salary is set at half the market rate is counted the same as a role no qualified person exists for. Both readings are informative: the industry genuinely lacks people, and it also genuinely misprices and mismanages the people pipeline.

Why can't newcomers get in?

The structure is circular: employers demand prior experience because security errors are expensive and training is a cost someone else should bear; so juniors can't get first jobs; so the experienced pool never grows; so experienced salaries rise; so employers demand more experience. Certifications — Security+, then mid-career marks like CISSP — became the filter, but CISSP itself requires years of experience, making it an entry barrier dressed as an entry credential. The past few years added a harsher cycle: after the pandemic-era hiring surge, 2023-2025 brought layoffs to security teams along with the rest of tech, and AI-assisted tooling is quietly restructuring what entry-level analysis work looks like — the tier where humans used to get their start is exactly the tier automation absorbs first.

What is actually being done?

What does the shortage mean for organizations?

Practical posture decisions: understaffed teams must automate relentlessly (patch tooling, managed detection, email filtering — the boring stack), outsource what cannot be staffed (managed SOC services exist precisely for this market), and prioritize by exposure rather than trying to cover everything. Retention is cheaper than replacement — realistic on-call, training budgets, and sane incident rotation keep the practitioners you have. And hiring managers who keep posting five-years-required junior roles are contributing to their own future shortage.

What should someone entering the field do?

Build demonstrable skill and evidence: home labs, capture-the-flag results, bug-bounty history, contributions to open-source security tooling — artifacts that read as experience because they are. Target the adjacent-entry routes that actually convert: helpdesk-to-security internally, GRC and compliance analysis, security sales engineering, and the government pipelines with structured ladders. Get Security+ for the HR filter, then let projects do the talking. The door is narrower than the marketing of a million unfilled jobs suggests — but the work is real, the ladder, once entered, is steep in the good direction, and the field's structural need for trustworthy practitioners is not going away.

Frequently Asked Questions

How big is the cybersecurity skills shortage?
ISC2's workforce studies put the global gap near 4 million unfilled positions in recent years, with total need approaching 5 million and the U.S. gap in the hundreds of thousands. Critics note survey-based need can overstate true scarcity — mispriced roles count as unfilled.
Why is it hard to get an entry-level cybersecurity job if there's a shortage?
The shortage is concentrated in experienced roles. Employers demand prior experience for junior positions, training budgets are scarce, and now AI automation absorbs Tier-1 analysis work — the traditional first rung of the ladder.
What certifications help start a cybersecurity career?
Security+ is the standard HR filter for entry roles. Mid-career certifications like CISSP require years of experience and are not entry credentials — pair early certs with demonstrable work: home labs, CTFs, bug bounties, open-source contributions.
Is AI reducing the cybersecurity workforce gap?
Partially — AI triage and automated tooling absorb routine Tier-1 work, which helps understaffed teams but also removes the traditional entry-level learning tier. Its net effect on the pipeline is one of the industry's open debates.