Guide

Cybersecurity recruitment has a pipeline shortage, not a headcount one.

The shortage recruiters quote and the shortage the posting data shows are two different things. What 8,093 US cybersecurity postings say about who you can actually hire, and at what price.

Ask a hiring manager why the security engineer req has sat open for six weeks and you'll hear "talent shortage." Ask the same question on r/cybersecurity and you'll get a different answer: there's no shortage of people, there's a shortage of jobs for anyone with five years of experience or less, and too much demand chasing the same fifteen-year veterans. Both groups are describing the same market. Neither has measured it.

We did. 119,998 people make up the US cybersecurity talent pool right now, against 7,865 active openings. That's roughly 15 candidates per opening, on paper enough supply that filling a security req should be routine. It rarely is, and the reason is where that headcount sits, not whether it exists.

What 8,093 postings actually show

The median US cybersecurity salary is $141,440, based on 8,093 analyzed postings. Divide the talent pool by the 7,865 roles currently active and you get about 15 candidates per opening, a ratio that looks comfortable until you break down who those candidates are. This is the same candidates-per-role math we've already run for seven other tech stacks; cybersecurity is the first one where the ratio and the composition tell different stories.

TierShare of poolHeadcountMedian salary
Entry2.1%2,549$83,000
Specialist67.1%80,554$141,000
Expert25.2%30,246$194,000
Leader5.5%6,649$277,000

Two thirds of the pool sits in one tier. Entry-level talent is 2.1% of it. Read against a $141,440 median and an average listing life of 9.5 days, the real shortage is where the pipeline sits, not how many people are in the pool overall. The pipeline meant to produce next year's specialists barely exists, and everyone with an open req is competing over the same middle third of the market. The full breakdown, including role and geography cuts, lives in the USA Cybersecurity Salary Report.

Only 44.2% of the postings behind that median disclose pay at all, and 91.7% of the roles in the dataset are full-time. That rules out one easy alternative explanation: a contractor market being miscounted as a headcount shortage. The roles here are overwhelmingly full-time hires, and pay transparency is thinner than it should be for a market this size, which is part of why this data comes from Glozo Intelligence reading live postings directly rather than from a survey that depends on employers volunteering a number.

An argument the comments already won, the vendor reports haven't caught up to

None of this is a new claim. SANS Institute published research in 2026 under the headline that the cybersecurity talent shortage narrative is wrong. Asked to choose between "not enough staff" and "not enough skills," 60% of the security leaders SANS surveyed picked skills, up from a four-point gap a year earlier. The same research found 27% of organizations had suffered a breach they traced directly to a capability gap on the team, not an empty seat.

ISC2's 2025 Cybersecurity Workforce Study reaches a related conclusion from the budget side: staff and budget cuts are increasing perceived security risk industry-wide, which is a resourcing problem, not a population problem. Fortinet's 2026 Cybersecurity Skills Gap report puts a number on the same friction: 49% of IT leaders say they struggle to get approval to add cybersecurity headcount even when they've identified the need, and 56% name a lack of cybersecurity skills, not a lack of applicants, as a leading cause of the breaches their teams have handled.

Put together, SANS and Fortinet are describing the same shift from two different rooms: security leaders already believe the shortage is really about which skills sit on the team, not how many seats are filled. Our posting data gives that belief a shape: 21 specific role categories, separated by a 63.5% pay range, are hiding inside the single word "cybersecurity."

Cybersecurity Ventures has projected 3.5 million unfilled cybersecurity jobs worldwide, a figure it has carried for several years running as evidence of scale. Read next to what we measured in 8,093 US postings, the two aren't contradictory. A global vacancy count and a composition problem inside the US market can both be true, they're just answers to different questions. What none of the vendor research above does is put both halves on one axis: how many people, against how many roles, broken down by who they actually are. That's the piece that's been missing, and it's the same measurement we ran for revenue operations hiring, where the market moves in eight days instead of 9.5.

Four gaps hiding inside one shortage number

Only one of the four gaps below is a real shortage. The other three belong to the employer, and all three are fixable this quarter.

A pipeline gap

Entry-level talent is 2.1% of the pool. That's the one gap nobody fixes by posting a more senior req: it's an intake problem, not a sourcing one, too few people entering the field relative to how fast demand for specialists is growing. This is the honest, unfixable-in-a-quarter piece of the shortage narrative, and it's the only piece that deserves the word.

A specificity gap

"We can't find security people" usually means the req hasn't decided which security person it wants. The data spans 21 distinct role medians across a 63.5% range, from about $105,000 for a cyber risk analyst to about $171,700 for an AI and ML security engineer. AI security carries the largest single skill premium in the dataset, roughly 18.6% over the median, which lines up with Fortinet's finding that 60% of IT leaders say AI-specific security experience is the hardest thing to hire for right now. A req written against "cybersecurity" as a single category is really being written against 21 different labor markets at once. Skills-based hiring covers the certs-versus-skills half of that argument; the short version here is that a certification list isn't a substitute for naming the role.

A price gap

Named employers in the dataset pay medians between roughly $220,000 and $313,500 for the roles they're actively filling. A range built against a generic "cybersecurity salary" number is competing with a figure nobody in the actual market is offering, not with what named employers actually pay. ISC2's finding on budget cuts and Fortinet's 49% approval-friction number both point at the same failure mode: the budget conversation is happening against last year's market, not this one. Add the 44.2% pay disclosure rate from above and the problem compounds, since most postings in this category never state a number at all, leaving a candidate weighing offers with little to compare against except word of mouth. Sizing the market before pricing the role is the fix, and it's a same-quarter fix, not a hiring-pipeline one.

A speed gap

The average cybersecurity listing stays open 9.5 days, ranging from 7.5 days for security consultant roles to 12.1 for incident response and DFIR. Nine and a half days is barely enough time to run one structured interview loop end to end, let alone source, screen, and get an offer approved from a standing start. Teams that treat the req as the starting gun are already behind teams that were quietly building a shortlist before the role was headcount-approved. It's also a market where enough pressure builds that shortcuts creep in: deepfake candidates on video interviews are a real problem specifically for security hiring, where the role itself is the thing being trusted to protect against exactly that kind of fraud. A market that moves in single-digit days rewards recruiting that's already running before the req goes live, which is the whole case for an always-on sourcing agent instead of a search that starts from zero every time. Not every tool that calls itself an agent actually runs in the background; how to tell a real one from a chatbot with a search box is worth the five minutes before you pick one.

What this changes about your next security req

Three of the four gaps above are yours to close this quarter. Start with specificity: decide which of the 21 role categories you're actually filling before the req goes out, not after the first round of resumes makes it obvious you didn't. Price against the roughly $220,000 to $313,500 that named employers are actually paying for that category, not a blended cybersecurity average that undersells you to anyone with options. And treat the 9.5-day window as the real clock, which means sourcing has to start before the req is approved, not after.

Matching against 21 role categories by hand doesn't scale past a handful of open reqs. That's the specific job a skill graph is built for: turning a candidate's actual experience into a weighted map of what they've done, so a req for an AI and ML security engineer surfaces a different shortlist than a req for a cyber risk analyst, even when both resumes use the word "security" the same number of times.

That last piece is where candidate surfacing that runs before you post matters more than another job board. Glozo's Open to Offers signal is built to surface people who match a role's skill graph and are showing behavioral signs of being receptive, without waiting for anyone to mark themselves "open to work" on a market where the good candidates rarely do.

None of this requires waiting on the pipeline gap to close. A recruiter who fixes specificity, price, and speed this quarter is competing for the same 119,998 people as everyone else, just with a shortlist that actually matches the role, a number that actually matches the market, and a head start measured in days instead of weeks.

The pipeline gap will still be there next quarter. The other three don't have to be.

Frequently asked questions

How much does it cost to hire a cybersecurity professional in 2026?
Based on 8,093 US postings, the median cybersecurity salary is $141,440, but that spans a 63.5% range across 21 distinct roles, from about $105,000 for a cyber risk analyst to about $171,700 for an AI and ML security engineer. Named employers filling specialist and leader-tier roles pay medians closer to $220,000 to $313,500.
Is there really a cybersecurity talent shortage?
Not in headcount terms. The US talent pool is 119,998 people against 7,865 active openings, about 15 candidates per role. The real shortage is structural: entry-level talent is only 2.1% of the pool, so the pipeline feeding future specialists is thin even though the overall pool looks large.
Why do cybersecurity roles take so long to fill?
Listings that do fill move fast, averaging 9.5 days, but many reqs stall because they're written against a generic "cybersecurity" label instead of one of the 21 distinct role categories the market actually hires for. Fixing the job description usually does more than widening the search.
What cybersecurity roles are hardest to hire?
Roles requiring AI-specific security experience carry the largest pay premium in the dataset, about 18.6% over the median, and Fortinet's 2026 research found 60% of IT leaders name AI-related security skills as their hardest search. Incident response and DFIR roles also run longer to fill, averaging 12.1 days against a 9.5-day market median.
Which cybersecurity skills carry a pay premium?
AI security skills carry the top premium measured, about 18.6% above the median. More broadly, roles that sit in the expert and leader tiers, which together are 30.7% of the talent pool, carry medians from $194,000 to $277,000, well above the $141,440 market median.
Where are cybersecurity salaries highest in the US?
City and state medians in the underlying dataset are directional rather than fixed figures, so treat any single-location number as an estimate. The full city and state breakdown is in the USA Cybersecurity Salary Report.
How do you source cybersecurity candidates who are not actively applying?
Most of the specialist and expert tier isn't posting a resume anywhere, since demand for that group already outpaces supply. Surfacing them means matching against a skill graph built from experience, not keywords, and reading behavioral signals of openness to a move instead of waiting for a self-reported "open to work" flag that this audience rarely sets.