patch&proof.
← Field manual

Careers / Field guide

Cybersecurity is not an entry-level field. Here's how people actually get in.

The job data honestly: real demand at mid and senior level, a hard entry level, and the routes that actually work — including two nobody mentions.

From the supplied September 2026 research package. Historical figures and evolving policy require source review; see the correction record.

Demand for experienced security practitioners is real and growing. The entry level is oversupplied and difficult. Both things are true at once, and most career content about this field only tells you the first half.

Here's the honest version, with the data.

What the numbers actually say

CyberSeek recorded 514,359 US cybersecurity job postings in the year to April 2025. The Bureau of Labor Statistics projects 21% growth for information security analysts through 2035, with median pay around $129,180.

That's real demand. But it's concentrated at mid and senior level, and ISC2's 2025 workforce study tells the other half: 39% of organizations under hiring freezes, 24% with layoffs, 36% with budget cuts.

About that "4.8 million unfilled jobs" figure

You'll see it everywhere, usually attached to a bootcamp advert. It deserves scrutiny.

The number comes from surveying security managers about desired headcount and extrapolating globally. It counts wishes, not funded roles. And it's hard to reconcile with a quarter of organizations conducting layoffs in the same year.

Notably, ISC2 — the source of the figure — de-emphasised it in its own 2025 study, reframing the problem as a skills gap rather than a headcount gap: 59% report critical skills needs, while hiring contracts.

That reframing is the accurate one. Organizations want specific capabilities — AI security, cloud, risk — more than they want bodies. Which changes how you should prepare.

How people actually get in

The most common route is sideways, not straight in. Help desk, then sysadmin or networking, then security. Or software engineering, then application security. Or audit and compliance, then governance and risk.

Realistic timeline from standing start to a first security role, including the adjacent-IT time: one to three years.

That's not a discouraging number. It's just a different plan from the one bootcamps sell, and knowing it up front means you spend your first year building relevant experience instead of collecting certifications that don't convert.

The two side doors nobody mentions

Governance, risk and compliance is the most realistic entry lane in 2026. The growth of compliance automation created steady demand, and the work tolerates career-changers from audit, finance, law and project management. Entry salaries run roughly $65,000–$90,000, rising to $125,000–$170,000 at senior level.

The stigma — "GRC is paperwork" — is wrong and works in your favour. Good GRC people run the risk conversation that decides where the security budget goes.

Privacy is the other. CIPP-certified privacy professionals come from legal and compliance backgrounds far more often than technical ones. Analyst roles start around $80,000–$120,000; privacy counsel and data protection officers reach $170,000–$250,000+. It's one of the few genuinely open doors for non-technical entrants, and AI governance is expanding it further.

Neither route requires you to be good at Linux. Both are real security careers.

What employers actually value

The consistent finding across 2026 hiring guidance: hands-on beats multiple-choice, and the ability to write beats both.

Certifications that carry weight, roughly in order of what they unlock:

  • ISC2 CC ($199, sometimes free) — a genuine zero-experience starting credential
  • CompTIA Security+ (~$404) — the default HR filter for entry roles
  • CPTS (~$210 exam) or PNPT ($499 all-in) — practical, report-producing, and rising fast in employer recognition
  • OSCP / OSCP+ ($1,749 bundle) — still the strongest signal for penetration testing roles
  • CISSP ($749, requires five years' experience) — the management and architecture gate

What matters as much: a public portfolio. A home lab with writeups. Documented detections in a repository. Hack The Box or TryHackMe rankings. A CTF result. One meetup talk. An open-source contribution.

And the differentiator nobody expects: report writing. Multiple 2026 hiring guides converge on communication as the thing separating otherwise equivalent candidates. It's exactly why practical certifications that require a professional report and a live debrief have gained ground on multiple-choice exams.

A budget path to employable

Roughly $1,500 total:

  • Security+ or ISC2 CC — $199–$404
  • A year of TryHackMe and Hack The Box — around $200
  • CPTS or CySA+ — $210–$423
  • Used lab hardware — a few hundred

Compare that with $8,800 SANS courses. SANS is excellent and employers respect it — which is why employers should fund it, not you. Do not put a SANS course on a credit card early in your career.

Start with the free things, in this order: PortSwigger's Web Security Academy (free, and the best web security curriculum that exists), OverTheWire for command-line fundamentals, TryHackMe's structured paths, and picoCTF — now CyLab Security Academy — for student-level competition.

Picking a direction

SOC analyst is still the widest door: $55,000–$80,000 entry, and the field's residency programme. Be aware that AI triage is compressing Tier-1 hiring, so differentiate with automation skills.

Application security is among the best-paid individual-contributor tracks ($130,000–$190,000, senior $180,000–$250,000+) precisely because the supply of security people who genuinely write code is thin. You arrive from software engineering.

Cloud security ($120,000–$180,000) is the second-highest-demand skill area in current workforce data.

Penetration testing is crowded and glamorised. It's roughly 30% testing and 70% scoping, writing and re-reporting the same findings. Clients pay for the report.

Red team operations is not an entry field at any level. It's a five-plus-year destination.

Full role-by-role detail, with skills, certifications, salaries and progression, is in the role guides. If you want to understand the work itself before choosing a track, minimum viable security is what most of these jobs exist to deliver.

The things nobody warns you about

Incident response and SOC work are surge-driven and on-call. Burnout is real and well-documented. Ask about rotation and staffing levels in interviews — the answer tells you a lot.

Security is a communication job earlier than you expect. Architects and CISOs spend more time on persuasion than technology.

CISO roles now carry personal legal exposure. Average tenure runs two to four years, and directors' and officers' coverage and indemnification are now standard negotiating points. That's a consequence of a 2022 criminal conviction of a security executive for concealing a breach.

The skepticism module

Any programme promising a six-figure salary in six months, citing millions of unfilled jobs, is selling against the data above.

That doesn't mean training is worthless — it means you should ask what happens to graduates, how many are placed, where, and at what salary. Good programmes answer readily. The rest talk about the gap.


What to do next: Pick one free platform and do fifteen hours on it this month. PortSwigger's Web Security Academy if you lean application security; TryHackMe's SOC path if you lean defensive. Fifteen hours will tell you more about whether you enjoy this work than any amount of reading about it.

Related: Minimum viable security — the controls every one of these roles is ultimately responsible for · Role guides · Certifications and what they cost · Labs and training directory · What security actually costs

Sources: CyberSeek — US job-posting data, May 2024 to April 2025. US Bureau of Labor Statistics — Information Security Analysts occupational outlook and median pay. ISC2 2025 Cybersecurity Workforce Study (Dec 2025) — hiring freezes, layoffs, skills-gap reframing. Certification pricing from ISC2, CompTIA, OffSec, Hack The Box and TCM Security, verified 2026. Salary.com and levels.fyi — compensation ranges.

Evidence & dates

Follow the source.

Source published
See individual source / original research
Event date
No single confirmed day assigned
Site publication
Unpublished · local review
Make it useful

Turn the reading into a decision.

Open the interactive lab ↗
Search the evidence
Source image / inspection view

View original source ↗Local review · rights and provenance pending owner approval