Cyber Security is an intensely broad term. Even so, Cyber Security is a subset of Information Technology, and, as such, it isn’t an entry-level field. Most Cyber Security jobs require experience, and job hunters who want to differentiate their skill list typically also obtain industry certifications and specific schooling.
There’s a problem in the industry, though – an intensely large number of open jobs and an equally large or even greater number of job seekers who are excited to work in the field as new practitioners. At the core of the problem and what perpetuates it regards the mismatches – mismatches of job descriptions, expectations, and experience. Also, there are other compromises made regarding what’s needed now and for the future, both within organisations and across the industry.
Cyber Security and Software Development – a Contrast
Consider the field and career path of Software Development – building computer programs from algorithms and with code; it’s got a full lifecycle. Software Development doesn’t group in and include Data Science or Quality Assurance, though those roles are clearly adjacent and part of the lifecycle. Separate, but adjacent.
Cyber Security as a field is about as broad as Medicine. Medicine’s clearly been through several iterations of qualifications and a clear career path, but the young field of Cyber Security/Information Security is missing the benefits of those iterations and the clarity they can bring.
As such, there’s no agreed entry-level and early practitioner path to a field that is an advanced subset of Information Technology. Instead, the glut of Cyber Security jobs available tend to require 3-7 years of specialty in a subset area. That’s a problem for learners and current early and future practitioners – a challenge they struggle to meet with a two-year or four-year practical or liberal arts degree.
The Black Hole of 3-5-7 Years of Cyber Security Experience
How do you fill a position requiring 3-5 (okay, often 7) years of specialized experience? You either promote staff members from your organisation who’ve gained that experience working with you or you hire them from other organisations. In Cyber Security, the latter’s quite common.
These options seem logical, but it’s worth noting that absent a clear internal technical progression plan, it seems easier (and the default case) and most cost effective – for now – to pilfer experienced workers from other organisations.
That practice encourages job hopping and a continued cycling of more open and similar jobs requiring 3-5 (or 3-7) years of specialized experience. Meanwhile, the years tick by, and the system and its problems perpetuate.
Why? Well, one reason is that there’s a lack of standardized titles, qualifications, and paths for employers to consult and review in Cyber Security. There’s not a central focus on this issue – no expert output from a working group tackling the problem.
Now is the time to solve the issue. Many medium-sized and larger businesses would benefit from a hiring overhaul led from intentional attempts to both hire some entry-level practitioners and seek to retain the wisdom gained by senior members of technical teams. (That’s a topic for another article).
There’s This Need for More Practitioners (Now!)
Generative AI emboldens cyber criminals and increases their skills. Emerging technology realization of quantum computing will disrupt cryptography. Business is conducted online, and it must be secure, as this will not change.
These statements all lead to a clear conclusion that the need for an increasing number of skilled Cyber Security practitioners will continue to increase. Learners and aspiring workers benefit from a clear path that matches them with jobs and employers who want to invest in their growth AND keep them working and progressing in the same organisation. Turnover is expensive and also a business and security risk.
Find the Standard Solution…and Use Cyber Security as the Start
Some thoughts from my experience in Cyber Security Workforce Development. First, split the field sooner by helping learners determine their focus based on interest. Yes, colleges and universities should continue to teach to keep current on course content, but add a means (or course) by which students know upon graduation what’s required to get an entry-level job in their interest area. For now, that will include work experience beyond coursework.
The industry would benefit from building and making available a set of standard Cyber Security job descriptions and qualifications that are tool and vendor agnostic for these specialties. This will require a working group with some prestige to tackle and build something widespread. Alternatively – as a solution for now – an organisation can undertake its own project to investigate the gaps of what is and what needs to be…and how to hire – strategically – for the latter.
Bolster HR to understand Cyber Security related terms and operations, and within this effort, include reclassification reviews, terminology clarification, and qualification investigation for other computer-based positions as well. Include that plan for hiring at entry level and career progression paths – beyond an unpaid or lightly paid internship. You may require a consultant to guide you through this mix of workforce, strategy, and documentation.
Adopt industry standard upskilling options and make them known to your team; they are already available – involve the vendors and non-profits who are local to your businesses.
Strategic HR needs to plan to revise what’s in place and plan for the future that includes how frequently review is necessary. Such plans need to focus on retaining knowledge from retiring individuals as well. A hint – technology positions change rapidly, so that review/revision of job descriptions, terms, and compensation plans will need to adapt as well.
Conclusion
The immediate industry problem is the number of unfilled Cyber Security jobs that require 3 or more years of experience coupled with a dearth of jobs for new entrants into the Cyber Security workforce.
Individual organisations are losing their mid- to senior-level talent as they leave for work elsewhere to further their careers, pointing to likely lack of career progression in this field within their own workplaces.
New workers in Cyber Security are needed to tackle the problems of both today and tomorrow. There isn’t a place for many of them considering our current system and the problems it causes.
Determine if this is a problem with which you identify and whether it benefits you to be a part of the solution.
Looking forward to an announcement of an industry working group. Who will lead it?



