Written by Brian McGraw on January 2, 2026 | Categories: Career

The Security Job Market Is Broken — Here’s Why

Security job market - empty office chairs at interview table

The security job market is broken. Not slow. Not competitive. Broken.

Candidates with years of experience can’t get callbacks. Hiring managers can’t find qualified people. Entry-level applicants face job postings requiring five years of experience. Senior professionals see roles disappear mid-interview process.

Everyone is frustrated. And the dysfunction isn’t accidental — it’s structural.

Job Descriptions That Don’t Reflect Reality

Most security job postings are wish lists, not actual role definitions.

I’ve seen entry-level analyst positions requiring CISSP, CISM, cloud certifications, and five years of experience. I’ve seen senior architect roles listing fifteen different technologies as “required” when the actual job uses three of them.

This happens because job descriptions often get written by HR using templates, or by hiring managers who list everything they might ever need rather than what the role actually requires. The result is postings that discourage qualified candidates from applying while attracting people who exaggerate their backgrounds.

The security job market suffers because the first filter — the job description — is miscalibrated from the start.

The Experience Paradox

Entry-level security roles barely exist anymore. Everyone wants experienced practitioners, but nobody wants to develop them.

Companies eliminated junior positions during budget cuts and never brought them back. They expect other organizations to do the training, then poach those people after a few years. The math doesn’t work. If everyone wants to hire experienced talent and nobody wants to grow it, the supply shrinks.

I’ve talked to candidates with homelab experience, certifications, IT backgrounds, and genuine passion for security who can’t get interviews because they lack “professional security experience.” Meanwhile, the same companies complain they can’t find anyone.

This is a failure of imagination. Some of the best security professionals I’ve worked with came from help desk, system administration, development, or completely unrelated fields. They didn’t possess a degree or certification, but learned on the job because someone gave them a chance. Building a team that actually stays requires this kind of intentional investment in people. That path is closing.

Compensation Is All Over the Place

Salary ranges for similar roles vary wildly. I’ve seen the same title and role at comparable companies range from $100,000 to $200,000 in the same city.

Part of this is legitimate variation in scope and responsibility. A “Security Engineer” at a startup means something different than at a Fortune 500. But much of it is just market confusion.

Candidates don’t know what to ask for. Employers don’t know what to offer. Both sides anchor on incomplete information and walk away feeling like they got a bad deal.

The security job market lacks the transparency that exists in more mature fields. Until that changes, compensation negotiations will continue to feel arbitrary.

Hiring Processes That Take Forever

Six interviews. A take-home assessment. A panel presentation. A “culture fit” conversation. Then silence for three weeks.

I’ve watched strong candidates drop out of processes because they accepted other offers while waiting. I’ve seen hiring managers lose budget approval mid-search because the process dragged on too long.

Speed matters in hiring. The best candidates have options. If your process takes two months, you’re not getting the best candidates — you’re getting whoever is still available at the end.

Security teams often make this worse by involving too many stakeholders, requiring too many approval layers, or treating hiring as a lower priority than project work. Every week of delay increases the chance you lose the person you want.

Certifications Carry Too Much Weight

Certifications have value. They demonstrate baseline knowledge and commitment to the field. But the security job market has become overly dependent on them as screening criteria.

I’ve interviewed candidates with impressive certification lists who couldn’t troubleshoot a basic firewall rule. I’ve interviewed candidates with no certifications who understood attacker methodology better than people with a decade of experience.

Certifications test knowledge retention. They don’t test judgment, problem-solving, or how someone performs under pressure. Using them as primary filters screens out capable people while letting others through based on test-taking ability.

This connects to a broader truth — the skills that make someone effective in security are hard to assess through credentials alone. This is part of what makes the CISO role so demanding, and it applies at every level.

Remote Work Confusion

The shift to remote work should have expanded the talent pool. In some ways it has. But it’s also created new friction.

Some companies post roles as “remote” but actually mean “remote within specific states” due to tax and legal complexity. Candidates apply, go through interviews, then learn at the end that their location doesn’t qualify.

Other companies are pulling back on remote work entirely, limiting their options to local candidates in competitive markets. They’d rather leave roles open for months than hire someone who works from another state.

The security job market hasn’t settled on norms around remote work. Until it does, both sides waste time on mismatched expectations.

Layoffs and Budget Cuts Created a Glut

The past two years saw significant security layoffs, particularly in tech. Experienced professionals flooded the market at the same time that companies tightened hiring budgets.

This created a temporary imbalance where supply exceeded demand, making it harder for candidates even as companies claimed they couldn’t find talent. What they meant was they couldn’t find talent willing to accept lower compensation than the market commanded two years ago.

Some of this is correcting. But the psychological impact lingers. Candidates are anxious and accept less than they should. Employers got used to having leverage and resist adjusting expectations.

What Needs to Change

The security job market won’t fix itself. It requires intentional effort from both sides.

Employers need to write realistic job descriptions, invest in developing junior talent, speed up hiring processes, and stop using certifications as the primary filter.

Candidates need to apply even when they don’t meet every requirement, negotiate based on value rather than anxiety, and be willing to walk away from broken processes. And once you do land the role, recognize that the hard part is just beginning.

Organizations like CISA have published guidance on building security workforce pipelines, but adoption remains inconsistent.

The dysfunction isn’t permanent. But it won’t resolve until both sides acknowledge that the current approach isn’t working.

📬 Stay Ahead of the Storm

Weekly insights on security leadership — no vendor spin, no recycled advice.

Subscribe Now!