Home › Blog › Is Cybersecurity in Demand? Current Jobs, Skills and Career Evidence
Professional Development

Is Cybersecurity in Demand? Current Jobs, Skills and Career Evidence

August 2, 2026 · Cyber Security · 7 min read

Is Cybersecurity in Demand? Current Jobs, Skills and Career Evidence

Cybersecurity skills are in demand, but the strongest evidence does not support one global claim about “millions of unfilled jobs” or one salary that applies everywhere. Demand varies by country, role and experience level, and current workforce research increasingly distinguishes a shortage of specific skills from a simple shortage of people.

What current labour-market data says

In the United States, the Bureau of Labor Statistics projects employment of information security analysts to grow 21% from 2025 to 2035, much faster than the 3% average for all occupations. BLS projects about 14,100 openings per year on average over the decade.

Source: U.S. Bureau of Labor Statistics, Information Security Analysts, updated August 2026

These are U.S. occupational projections for one defined occupation. They should not be converted into a global cybersecurity-job growth rate.

Cybersecurity is also one of the fastest-growing skill areas globally

The World Economic Forum’s Future of Jobs Report 2025 places networks and cybersecurity among the three fastest-growing skill areas expected through 2030, alongside AI and big data and technology literacy. Information Security Analysts also appear among the report’s fastest-growing roles.

Source: World Economic Forum, Future of Jobs Report 2025

The WEF findings are based on a global employer survey. They describe expected direction of demand, not a guaranteed number of vacancies in a specific country.

The 2025 cybersecurity workforce research shifted from headcount to skills

ISC2’s 2025 Cybersecurity Workforce Study surveyed 16,029 cybersecurity practitioners and decision-makers across North America, Latin America, Asia-Pacific, and Europe, the Middle East and Africa.

ISC2 deliberately did not publish a global workforce-gap estimate in 2025. Its research note explains that respondents increasingly identified shortages of critical skills as more important than a single headcount-gap number.

Source: ISC2 Cybersecurity Workforce Study 2025

In that study, 59% of respondents reported critical or significant skills needs and 95% reported at least one skills need. Those are survey results from cybersecurity practitioners and decision-makers, not percentages of all employers worldwide.

Which cybersecurity skills are organisations looking for?

The exact mix depends on the organisation, but common capability areas include:

  • security operations and monitoring;
  • incident response;
  • cloud security;
  • identity and access management;
  • application and API security;
  • vulnerability management;
  • governance, risk and compliance;
  • security architecture;
  • digital forensics;
  • threat intelligence;
  • AI-related security and governance;
  • communication and business-risk translation.

Cybersecurity careers are not limited to penetration testing, and technical depth is not identical across roles.

Salary claims need geography and occupation

BLS reports that the median annual wage for U.S. information security analysts was $129,180 in May 2025. This is a U.S. national median for the specific BLS occupation “Information Security Analysts”.

It should not be presented as the salary for all cybersecurity professionals globally. Entry-level analysts, governance specialists, security engineers, consultants and senior leaders can have very different pay structures, and compensation varies widely by labour market.

Do you need a degree?

BLS says information security analysts typically need a bachelor’s degree in a computer and information technology field or a related field, often with related work experience. It also notes that some workers enter the occupation with a high-school diploma plus relevant industry training and certifications.

That means there is no single entry route. Useful preparation depends on the target role.

Build demonstrable capability, not a list of buzzwords

For an early-career candidate, useful evidence can include:

  • a small home lab or controlled practice environment;
  • documented security investigations;
  • network or cloud configuration exercises;
  • incident-response walkthroughs;
  • risk assessments;
  • secure coding or vulnerability-remediation examples;
  • clear written explanations of technical findings.

Only practise on systems you own or are explicitly authorised to test.

Choose a path before choosing certifications

Certifications can help structure learning and signal baseline knowledge, but the right choice depends on the role you want. A governance-and-risk path, cloud-security path and security-operations path do not need the same certification sequence.

Start with job descriptions in the market you want to enter. Identify recurring tasks, tools and knowledge areas, then build a learning plan around those requirements.

Cybersecurity demand does not mean every applicant will find work easily

A growing occupation can still be competitive at entry level. Employers may ask for experience because security work often involves access to sensitive systems and consequential decisions.

Ways to reduce that gap include:

  • IT support, networking, systems administration or development experience;
  • internships or apprenticeships;
  • practical projects;
  • role-specific certifications;
  • security responsibilities inside an existing non-security role;
  • clear evidence of communication and analytical ability.

A realistic cybersecurity career decision

Cybersecurity remains a strong growth area in current U.S. occupational projections and a rising global skills priority in employer surveys. The opportunity is real, but it is better understood as demand for demonstrable security capability than as a promise that every certificate leads directly to a high-paying role.

Choose a cybersecurity path before choosing credentials
Operations
Detect, investigate, respond
Engineering
Build and secure systems
GRC
Risk, controls, compliance
Identity / Cloud
Access, platforms, configuration

Map the role before you build the learning plan

“Cybersecurity” is too broad to be a useful career target. A candidate who wants security operations needs a different evidence portfolio from someone targeting governance, cloud security or application security. Start with ten to twenty job descriptions in the geography you actually want to work in and extract recurring tasks rather than recurring buzzwords.

Path Typical evidence employers may look for Useful practice
Security operations Alert triage, investigation, escalation, incident handling Build a small lab, analyse logs, write incident notes
Governance, risk and compliance Risk assessment, control mapping, policy, audit support Write a sample risk register and control test
Cloud security Identity, permissions, logging, configuration, architecture Secure a sandbox cloud environment and document decisions
Application security Secure development, vulnerability review, threat modelling Review your own test application and document remediation
Identity and access Authentication, access lifecycle, privileged access Model joiner-mover-leaver and role-based access scenarios

The objective is to make your preparation resemble the work. A generic collection of courses can show motivation, but a portfolio that demonstrates how you think through a security problem is much stronger evidence of readiness.

Build a 90-day capability portfolio

A candidate does not need to wait until they have a job to demonstrate disciplined security work. Over ninety days, build three or four small artefacts around one target role. Each artefact should explain the problem, your assumptions, what you did, what evidence you used, what you found and what you would do next.

For example, a security-operations portfolio might include a phishing investigation, an authentication-log review and an incident-response tabletop. A GRC portfolio might include a third-party risk assessment, a simple control matrix and a policy gap review. A cloud-security portfolio could include an identity design, logging baseline and configuration review in an authorised sandbox.

Do not publish credentials, personal data, customer information or offensive techniques that could create risk. The portfolio should demonstrate judgement and communication, not recklessness.

Use certifications as structure, not as the entire strategy

A certification can create a syllabus and help a recruiter interpret baseline knowledge. It cannot substitute for role-specific practice. Before buying an exam, check whether the target job descriptions actually mention it, whether the content matches the work and whether the credential assumes prior experience.

A simple decision test is:

  1. Does the target role repeatedly ask for this knowledge?
  2. Will the learning close a real gap in my current capability?
  3. Can I practise the knowledge in a legal, controlled environment?
  4. Will I be able to explain how I applied it?
  5. Is the cost proportionate to the signal it creates in my target market?

Do not confuse demand with entry-level ease

Strong long-term demand can coexist with a difficult first-job market. Security teams often handle sensitive systems, incident decisions and regulated data, so employers may prefer candidates who already understand IT operations, networks, cloud platforms or software delivery.

That means an adjacent role can be a rational entry route. Help desk, systems administration, cloud operations, software development, audit, compliance or data roles can all create relevant foundations when the work exposes you to controls, incidents, access management or technical systems.

Evaluate job-market evidence locally

Before making a career decision, separate four kinds of evidence: occupational projections, current vacancies, employer-survey expectations and workforce-skills studies. They answer different questions. A projection may show long-term growth while current entry-level openings remain limited. A skills survey may show a shortage of particular capabilities without proving that employers will hire inexperienced candidates quickly.

The practical career decision should therefore combine macro evidence with local vacancy analysis and an honest assessment of your starting point.

Related MATSH resources

Sources

⏱
7 min read 1,412 words · practical and to the point
Upcoming Dates
Monitoring and Evaluation Course 05 Oct 2026 · USD 2,850
View all upcoming dates →
More on This Topic
Cybersecurity Career Guide: Entry Routes, Skills and Progression 6 min read Cybersecurity Analyst Role: Responsibilities, Skills and Career Path 7 min read Cybersecurity Training: How to Choose the Right Course for Your Role 6 min read Understanding Cyber Security: Essential Info 5 min read

Need In-House Training?

We run all our courses as private programmes for organisations across the GCC and Africa.

Request In-House →