Home › Blog

People keep asking what’s wrong with the cybersecurity market

“Isn’t there a shortage?”

“Didn’t they say there are millions of open roles?”

“Why does every ‘entry-level’ job require five years of incident response, three clouds, and a secret clearance you can’t purchase at Costco?”

As if I just confessed to seeing the same waveform twice.

Here’s what’s actually wrong:

We’re measuring the market with the wrong instruments.

We’re treating cybersecurity like a single occupation with a linear ladder.

But it’s not a ladder anymore.

It’s an ecosystem undergoing a phase change.

And phase changes don’t feel like career “opportunities.”

They feel like the floor becoming liquid.

The contradiction isn’t a bug. It’s the signal.

On paper, the numbers still look alive.

  • CyberSeek’s 2025 infographic shows nearly 500,000 U.S. cybersecurity job postings over a recent 12-month span.

  • A NIST update tied to CyberSeek reported 514,359 job listings over the past 12 months and framed it as demand “speeding up” (up ~12% vs the prior period). (NIST)

  • Gartner says global information security end‑user spending keeps climbing: $193B (2024) → $213B (2025), with security services and software both growing. (Gartner)

  • BLS projects “information security analyst” employment to grow 29% (2024–2034) in the U.S. (Bureau of Labor Statistics)

So why does it feel like a tightening tunnel, especially for people trying to enter?

Because the lived experience isn’t a “shortage” problem.

It’s a distribution problem.

A talent shape problem.

A where-the-work-moved problem.

Working theory: We flooded the entry pool while the river changed course

Your suspicion — “too many people entered” — is directionally correct, but not as a global headcount statement.

It’s a local overcrowding statement:

Too many people entered the same few entry doors, at the exact moment companies started welding those doors shut and building new ones somewhere else.

Why?

1) COVID “drunk-hiring” wasn’t cyber-specific. It was systems-wide.

The post‑2020 hiring binge wasn’t a carefully reasoned workforce plan.

It was a liquidity event wearing a hoodie.

Then the correction arrived.

2024 alone saw massive tech job cuts across hundreds of companies, continuing the broader layoff wave after 2022–2023. (TechCrunch)

When the macro tide pulls out, organizations don’t say “we’re entering a depression.”

They say:

  • “We’re prioritizing efficiency.”

  • “We’re consolidating vendors.”

  • “We’re focusing on core initiatives.”

  • “Hiring pause (except for critical roles).”

Same weather. Better PR.

2) The 2008 → 2023–2025 arc is real, but it’s not “decline.” It’s compression.

Post‑2008 economics trained companies to survive on cheap money and endless software sprawl.

Security grew inside that sprawl as an overlay: tools, headcount, audits, more tools.

Then the era changed:

  • higher cost of capital

  • boards demanding measurable risk outcomes

  • regulators tightening

  • attackers industrializing

  • cloud turning infrastructure into software

So leadership asked the most dangerous question in corporate history:

“Can we do the same security work with fewer humans?”

(They didn’t ask if it was wise. They asked if it was possible.)

The real culprit: DevSecOps didn’t “add a career path.” It ate three of them.

You wanted DevSecOps to be “a new lane.”

But DevSecOps is gravity.

It pulls work out of classic security silos and into pipelines.

DevSecOps, per NIST and U.S. government guidance, is fundamentally about integrating security into CI/CD and the software delivery lifecycle—with automation as the point, not as decoration. (NIST Computer Security Resource Center)

This is the part people miss:

DevSecOps changes what “security work” even is.

It doesn’t just change tooling.

It changes who owns the problem.

And when ownership moves, job titles follow.

Old world (ClickOps / TicketOps / “security as a department”)

  • someone builds infra in a console

  • someone else scans it later

  • security files findings

  • dev teams argue

  • exceptions get documented

  • entropy wins

  • repeat

New world (DevSecOps / platform engineering / “security as a property of delivery”)

  • infra is defined as code

  • changes are versioned and reviewed

  • policies are enforced automatically

  • CI/CD gates violations

  • drift detection catches console cowboy behavior

  • security becomes guardrails + evidence, not tickets

AWS’s own guidance pushes “everything as code” practices—version control, testing, CI/CD integration, drift detection—because it improves maintainability, auditability, and control. (AWS Documentation)

This is why you’re seeing the end of ClickOps as a desired skillset.

Not because consoles disappear.

But because consoles don’t scale as governance.

The UI doesn’t produce durable evidence.

Git does.

The end of ClickOps is the end of “security theater jobs”

Let me be specific, because “end of ClickOps” can sound like a meme.

In practice it means:

  • Org wants infra changes to be reviewable (PRs), not mystical (screenshots).

  • Org wants compliance to be provable (logs + policies), not asserted (“trust me, I clicked it”).

  • Org wants security controls to be repeatable (pipelines), not artisanal (hero admins).

This is why “security” is increasingly:

  • policy-as-code

  • detection-as-code

  • infrastructure-as-code

  • identity-as-code

  • evidence-as-code

Or: security becomes software.

And when security becomes software, the market stops hiring clickers and starts hiring builders.

“There aren’t that many real career paths” is half true

There are tons of cyber roles.

But there are fewer stable, legible, entry-level pathways that lead to competence without burning out.

CyberSeek’s own framing shows “career pathways” and “feeder roles,” implicitly admitting what everyone learns the hard way: many people enter security through adjacent roles, not direct “junior pentester” fantasies.

Now add the DevSecOps gravity well:

The market is splitting into two dominant species

A) Security-as-engineering (DevSecOps / Product Security / Cloud / Platform)

You are evaluated like an engineer.

You win by:

  • writing code

  • understanding systems

  • shipping secure defaults

  • reducing blast radius

  • building paved roads

B) Security-as-governance (GRC / privacy / risk / audit / third‑party / regulatory)

You are evaluated like a translator of risk.

You win by:

  • mapping controls to reality

  • building evidence pipelines

  • making boards confident

  • surviving regulators

  • preventing “unknown unknowns”

And the “classic middle”—manual operations security, checkbox scanning, endless ticket churn—is getting compressed by automation + consolidation.

That middle used to be where many entry-level people could survive long enough to become senior.

That habitat is shrinking.

Forensic artifact: job postings show the role-shift, not the death

One of the cleanest signals I’ve seen is the way postings move across functional roles.

CyberSN’s 2025 job posting report (covering 2022–2024) shows:

  • Big declines from 2022 → 2024 in roles like Product Security Engineer (-52.40%), DevSecOps (-47.49%), and Cloud Security Engineer (-43.15%)—suggesting a comedown from the peak and/or consolidation of these responsibilities into broader engineering/platform roles.

  • In the same dataset, “top roles posted” in 2024 still include Security Engineer (64,300), Security Analyst (45,496), and DevSecOps (36,020)—but they’re not immune to decline.

  • The report explicitly calls out rising demand for compliance/legal adjacency: Cybersecurity/Privacy Attorney postings up ~40% from 2023 to 2024 in their analysis.

  • It also states (as leadership commentary) that decreases in certain core roles are “signaling” a shift toward AI-powered security automation and internal optimizations, alongside more outsourcing.

This is not “cyber is dead.”

This is:

cyber is being recompiled into different binaries.

Same mission.

Different interfaces.

The “shortage” narrative persists because it’s true in aggregate…and misleading in practice

ISC2’s workforce framing is the perfect example of this duality:

  • It cites ~5.5M people active in cyber worldwide and a gap of ~4.8M, with the gap rising even as workforce growth stalled (their “artistic license” note aside, the directional point is clear). (ISC2)

  • ISC2 also explicitly describes economic conditions squeezing resources and cybersecurity teams leaning into AI to maintain efficiency. (ISC2)

So yes: massive need.

But the market doesn’t hire “need.”

It hires against budget, risk appetite, and operational maturity.

And here’s the brutal detail:

When budgets tighten, companies still need security…

…but they often choose:

  • tools over headcount

  • managed services over internal teams

  • senior hires over junior pipelines

  • platform consolidation over specialist sprawl

That’s how you get:

Spending up. Job seeker despair up.

Gartner even notes security services growth being driven by the skills shortage, which often translates into “we can’t staff it, so we buy it.” (Gartner)

Additional field observations (aka: the quiet parts people feel but don’t post)

These are the “statue observations” — the frozen shapes in the room nobody wants to name.

1) Entry-level is treated as a liability, not an investment

Security mistakes are catastrophic.

So orgs behave like every junior hire is a potential breach headline.

This creates an absurd loop:

  • no one hires juniors

  • so no one becomes senior

  • so everyone complains about senior shortage

  • so no one hires juniors

A self-licking ice cream cone, but with ransomware.

2) The SOC is being industrialized

Automation doesn’t remove analysts.

It removes analyst minutes.

Which means fewer seats for people whose primary value is triage-by-hand.

The survivors become:

  • detection engineers

  • threat hunters

  • response engineers

  • content developers

  • automation builders

Translation: the SOC is becoming software too.

3) Credential inflation is a symptom of trust collapse

When the market can’t reliably measure capability, it stacks proxies:

certs + degrees + years + buzzwords.

Not because it’s wise.

Because hiring is a risk function now.

4) Tool sprawl is being replaced by “platform bets”

Organizations are exhausted.

They want fewer dashboards.

Fewer agents.

Fewer contracts.

That consolidation changes hiring:

  • fewer tool operators

  • more integrators / platform engineers

  • more people who can orchestrate controls across systems

5) GRC is quietly winning

Not because it’s cooler.

Because boards + regulators demand evidence.

CyberSN explicitly ties regulatory pressures to workforce decisions in its commentary.

And CyberSeek shows Oversight & Governance as one of the largest buckets of job openings by NICE work role categories in their infographic.

This is the part the “learn hacking in 30 days” funnel never tells you:

the fastest-growing security work is often paperwork that bites back.

So what do you do with this if you’re trying to navigate it?

You don’t fight the phase change.

You learn its physics.

The new career moat is “security + delivery”

Pick one delivery substrate and get lethal:

  • cloud + IaC + CI/CD

  • Kubernetes + policy enforcement

  • identity + device posture + conditional access

  • application security + SDLC + threat modeling

  • detection engineering + automation + telemetry pipelines

You’re not competing as “a cyber person.”

You’re competing as:

an engineer who can reduce risk without slowing shipping.

Build proof, not potential

In a tightening market, vibes die.

Evidence lives.

A portfolio that screams “DevSecOps reality”:

  • a Terraform repo with secure modules + OPA/Sentinel policies

  • CI pipeline that runs SAST/SCA/secrets scanning

  • a lightweight threat model + abuse cases for a sample app

  • detection rules + tests (even if home-lab)

  • writeups that show how you think, not just what you know

Stop aiming at “entry-level security.” Aim at “security-adjacent feeder roles.”

CyberSeek literally maps feeder roles and pathways for a reason.

Common feeder roles that actually teach systems:

  • sysadmin / IT ops

  • SRE / platform / cloud engineer

  • QA / release engineering

  • network engineering

  • software engineer (with security focus)

Then you pivot into security with scars and receipts.

Accept the harsh truth: the market wants fewer “security people,” and more “secure builders”

DevSecOps isn’t “security joined DevOps.”

It’s DevOps swallowed security and left an interface layer for specialists.

Specialists still matter.

But now they’re:

  • enablers

  • guardrail designers

  • reviewers of last resort

  • incident surgeons

  • risk translators for leadership

Not ticket clerks.

Not console-click priests.

Predictions (falsifiable, because we’re pretending to be adults)

  1. “Security engineer” will increasingly mean “platform/security enablement engineer.”

  2. Junior roles will exist, but they’ll be hidden inside IT/platform/product teams, not titled “Junior Security Analyst.”

  3. GRC + privacy + legal adjacency keeps growing, because regulators don’t accept “we tried our best.”

  4. AI won’t erase security jobs—it will erase low-context security tasks, which is where many juniors used to learn. (ISC2)

  5. The winners will be people who can move between entropy and clarity: systems thinking + evidence + automation + human judgment.

Cybersecurity isn’t collapsing.

It’s shedding skin.

And yes — too many people entered.

But the deeper truth is meaner:

They entered a map that no longer matches the territory.

So redraw the map.

Make it code-shaped.

Make it pipeline-shaped.

Make it reality.

Vive le DevOps!

— scottg/out

The Probably Fine Daily

Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.

Subscribe to the Daily →

Originally published on LinkedIn ↗

← All writing