August 2, 2026 · Cyber Security · 7 min read
Cybersecurity skills are in demand, but the strongest evidence does not support one global claim about “millions of unfilled jobs” or one salary that applies everywhere. Demand varies by country, role and experience level, and current workforce research increasingly distinguishes a shortage of specific skills from a simple shortage of people.
In the United States, the Bureau of Labor Statistics projects employment of information security analysts to grow 21% from 2025 to 2035, much faster than the 3% average for all occupations. BLS projects about 14,100 openings per year on average over the decade.
Source: U.S. Bureau of Labor Statistics, Information Security Analysts, updated August 2026
These are U.S. occupational projections for one defined occupation. They should not be converted into a global cybersecurity-job growth rate.
The World Economic Forum’s Future of Jobs Report 2025 places networks and cybersecurity among the three fastest-growing skill areas expected through 2030, alongside AI and big data and technology literacy. Information Security Analysts also appear among the report’s fastest-growing roles.
Source: World Economic Forum, Future of Jobs Report 2025
The WEF findings are based on a global employer survey. They describe expected direction of demand, not a guaranteed number of vacancies in a specific country.
ISC2’s 2025 Cybersecurity Workforce Study surveyed 16,029 cybersecurity practitioners and decision-makers across North America, Latin America, Asia-Pacific, and Europe, the Middle East and Africa.
ISC2 deliberately did not publish a global workforce-gap estimate in 2025. Its research note explains that respondents increasingly identified shortages of critical skills as more important than a single headcount-gap number.
Source: ISC2 Cybersecurity Workforce Study 2025
In that study, 59% of respondents reported critical or significant skills needs and 95% reported at least one skills need. Those are survey results from cybersecurity practitioners and decision-makers, not percentages of all employers worldwide.
The exact mix depends on the organisation, but common capability areas include:
Cybersecurity careers are not limited to penetration testing, and technical depth is not identical across roles.
BLS reports that the median annual wage for U.S. information security analysts was $129,180 in May 2025. This is a U.S. national median for the specific BLS occupation “Information Security Analysts”.
It should not be presented as the salary for all cybersecurity professionals globally. Entry-level analysts, governance specialists, security engineers, consultants and senior leaders can have very different pay structures, and compensation varies widely by labour market.
BLS says information security analysts typically need a bachelor’s degree in a computer and information technology field or a related field, often with related work experience. It also notes that some workers enter the occupation with a high-school diploma plus relevant industry training and certifications.
That means there is no single entry route. Useful preparation depends on the target role.
For an early-career candidate, useful evidence can include:
Only practise on systems you own or are explicitly authorised to test.
Certifications can help structure learning and signal baseline knowledge, but the right choice depends on the role you want. A governance-and-risk path, cloud-security path and security-operations path do not need the same certification sequence.
Start with job descriptions in the market you want to enter. Identify recurring tasks, tools and knowledge areas, then build a learning plan around those requirements.
A growing occupation can still be competitive at entry level. Employers may ask for experience because security work often involves access to sensitive systems and consequential decisions.
Ways to reduce that gap include:
Cybersecurity remains a strong growth area in current U.S. occupational projections and a rising global skills priority in employer surveys. The opportunity is real, but it is better understood as demand for demonstrable security capability than as a promise that every certificate leads directly to a high-paying role.
“Cybersecurity” is too broad to be a useful career target. A candidate who wants security operations needs a different evidence portfolio from someone targeting governance, cloud security or application security. Start with ten to twenty job descriptions in the geography you actually want to work in and extract recurring tasks rather than recurring buzzwords.
| Path | Typical evidence employers may look for | Useful practice |
|---|---|---|
| Security operations | Alert triage, investigation, escalation, incident handling | Build a small lab, analyse logs, write incident notes |
| Governance, risk and compliance | Risk assessment, control mapping, policy, audit support | Write a sample risk register and control test |
| Cloud security | Identity, permissions, logging, configuration, architecture | Secure a sandbox cloud environment and document decisions |
| Application security | Secure development, vulnerability review, threat modelling | Review your own test application and document remediation |
| Identity and access | Authentication, access lifecycle, privileged access | Model joiner-mover-leaver and role-based access scenarios |
The objective is to make your preparation resemble the work. A generic collection of courses can show motivation, but a portfolio that demonstrates how you think through a security problem is much stronger evidence of readiness.
A candidate does not need to wait until they have a job to demonstrate disciplined security work. Over ninety days, build three or four small artefacts around one target role. Each artefact should explain the problem, your assumptions, what you did, what evidence you used, what you found and what you would do next.
For example, a security-operations portfolio might include a phishing investigation, an authentication-log review and an incident-response tabletop. A GRC portfolio might include a third-party risk assessment, a simple control matrix and a policy gap review. A cloud-security portfolio could include an identity design, logging baseline and configuration review in an authorised sandbox.
Do not publish credentials, personal data, customer information or offensive techniques that could create risk. The portfolio should demonstrate judgement and communication, not recklessness.
A certification can create a syllabus and help a recruiter interpret baseline knowledge. It cannot substitute for role-specific practice. Before buying an exam, check whether the target job descriptions actually mention it, whether the content matches the work and whether the credential assumes prior experience.
A simple decision test is:
Strong long-term demand can coexist with a difficult first-job market. Security teams often handle sensitive systems, incident decisions and regulated data, so employers may prefer candidates who already understand IT operations, networks, cloud platforms or software delivery.
That means an adjacent role can be a rational entry route. Help desk, systems administration, cloud operations, software development, audit, compliance or data roles can all create relevant foundations when the work exposes you to controls, incidents, access management or technical systems.
Before making a career decision, separate four kinds of evidence: occupational projections, current vacancies, employer-survey expectations and workforce-skills studies. They answer different questions. A projection may show long-term growth while current entry-level openings remain limited. A skills survey may show a shortage of particular capabilities without proving that employers will hire inexperienced candidates quickly.
The practical career decision should therefore combine macro evidence with local vacancy analysis and an honest assessment of your starting point.
We run all our courses as private programmes for organisations across the GCC and Africa.
Request In-House →