Astra Trainer
Future Industries

There Is No Entry-Level Cybersecurity Shortage

Aleksandr Mikhailov
Founder, Astra Trainer
Updated
9 min read

Job advertisements describe a desperate shortage. Junior applicants describe sending two hundred applications without a reply. Both are accurate, and the explanation matters.

The shortage has a specific shape

The demand is real. The US Bureau of Labor Statistics projects employment of information security analysts to grow 28.5 percent between 2024 and 2034, an increase of 52,100 jobs, against 3.1 percent growth across all occupations. Adoption of new technology, including artificial intelligence, expands the attack surface and the regulatory obligations at the same time.

But the demand is not evenly distributed across experience levels, and this is the part that gets lost.

What organisations want: someone who has handled real incidents, can make a judgement call at two in the morning, understands the systems they are defending, and will not either ignore a genuine intrusion or shut down production over a false positive.

What is abundant: people with certifications, home labs, capture-the-flag experience and enthusiasm, who have never been responsible for a production environment.

Almost nobody is hiring for potential, and almost everybody is complaining that experienced people are scarce.

Those two facts are the same fact. The pipeline is blocked at the first step, and it is blocked because the roles that used to create security experience have been removed or outsourced.

The practical consequence for an employer is that the fastest route to an experienced security team is internal progression from technical roles, not external recruitment into a market where everyone is competing for the same small group.

What the direction covers

The scope: networks, attacks and defence, identity, cloud security, incident response, forensics and governance.

Four areas.

Foundations. Networks, operating systems, identity and cryptography, at the level required to reason about what an attacker can actually do.

Defence and detection. Hardening, monitoring, detection engineering and response.

Offensive understanding. How attacks work, so that defences address method rather than category.

Governance and risk. Frameworks, regulation, third party risk and the work of making security decisions inside an organisation that has other priorities.

Why certifications did not fix it

Considerable money has been spent on certification and the experienced shortage persists. The reason is worth stating without hostility, because certifications do something real and it is not the thing that is missing.

A certification demonstrates that someone knows a defined body of material. That is genuinely useful. It filters for effort and for baseline knowledge, and several are respected for good reason.

What it does not demonstrate is judgement under uncertainty, which is what the scarce roles require.

Deciding what matters. A scanner returns four hundred findings. Knowing which three are actually exploitable in this environment is experience, not knowledge.

Working with incomplete information. An alert fires at midnight. Something might be happening. The choice is to escalate and disrupt the business or wait and risk the intrusion spreading, and both are wrong sometimes.

Understanding the specific environment. Which systems matter, what normal looks like here, where the undocumented dependencies are. This cannot be certified because it is local.

Making the argument. Most security work involves persuading people who have other priorities to accept friction. That is a communication and organisational skill.

The implication is not that certification is worthless. It is that certification plus no operational responsibility does not produce what the market is short of, and organisations funding the former while providing none of the latter are buying half of something.

Where this sits in the domain

Cybersecurity is the fifth of eight directions in Astra Trainer's AI, data and computing domain, and it is where much of the demand created by the other directions lands. Adopting artificial intelligence, moving to cloud infrastructure and connecting more systems all expand what has to be defended.

It rests on IT systems and computer networks and on computer science, because security judgement requires knowing how the thing actually works, and connects to cloud computing and DevOps where a large share of modern exposure originates. You can see the eight directions here.

Most breaches are not sophisticated

Security marketing emphasises advanced persistent threats and novel techniques. The incident reports read differently, and the difference should shape where training money goes.

The recurring routes in are unremarkable. Credentials that were stolen, guessed, reused from another breach or phished. Systems missing patches for vulnerabilities that were disclosed and fixed months or years earlier. Services exposed to the internet that were never meant to be, including storage and management interfaces left open by configuration error. Excessive permissions that let a minor foothold become a major one. Third party access through a supplier with weaker controls.

Four implications that follow directly.

The basics are the work. Asset inventory, patching, multi-factor authentication, least privilege, backup and recovery, logging. Unglamorous, difficult to sustain, and responsible for most of the risk reduction available.

You cannot protect what you do not know you have. Asset inventory is the least interesting control and the one whose absence explains most of the rest.

Identity is the perimeter now. Once work happens across cloud services and remote endpoints, the network boundary stops being the control point and credentials become the target.

Detection matters more than prevention alone. Assuming compromise and building the ability to notice it, quickly, is a better posture than assuming the perimeter holds.

The roles that are genuinely hard to fill

Being specific here helps organisations aim their training at the real gaps.

Detection engineers. People who write and tune the rules that decide what gets noticed. This requires knowing both attacker technique and the specific environment, and there are very few of them.

Incident responders with real incident experience, as distinct from tabletop exercises.

Cloud security engineers. Cloud security differs enough from traditional infrastructure security that the transfer is not automatic, and the demand has outpaced the supply badly.

Application security engineers who can actually read code, which is a much smaller group than the number of people with the title.

Operational technology and industrial security specialists, where information technology security practice frequently makes things worse if applied without process understanding.

Security architects who can design rather than assess.

The common feature is that each requires depth in something other than security. That is the finding that should determine recruitment strategy.

The roles, named

Security analysts, in operations centres.

Detection engineers.

Incident responders and forensic analysts.

Penetration testers and red team operators.

Application security engineers.

Cloud and infrastructure security engineers.

Identity and access management specialists.

Governance, risk and compliance professionals.

Threat intelligence analysts.

Who can be trained into it

Systems administrators. The strongest conversion available. They know how systems work, what normal looks like, and where the undocumented dependencies are. Security knowledge added to that foundation produces a useful defender quickly.

Network engineers. Into network security and detection, already holding the traffic picture.

Software developers. Into application security, where the ability to read code is the scarce part and cannot be acquired from a course.

Cloud and platform engineers. Into cloud security, which is one of the hardest gaps to fill externally.

Service desk and support staff. Into security operations, holding user behaviour knowledge and incident handling instinct.

Industrial control and automation engineers. Into operational technology security, where process understanding is what general security staff lack.

Auditors and risk professionals. Into governance and compliance, where the methodology already transfers.

Military and law enforcement personnel with relevant background, particularly into investigation and response.

Legal boundaries and regulated obligations. Unauthorised access to computer systems is a criminal offence in most jurisdictions, and security testing requires explicit written authorisation defining scope. Breach notification, incident reporting and sector-specific security obligations are set by law, differ by jurisdiction and carry penalties. Forensic evidence handling has requirements that affect admissibility. Astra Trainer builds defensive and analytical capability and awareness of where these duties apply. It does not authorise testing of any system, is not legal advice, and confers no professional certification or status.

What to take from this

The demand is real, projected at 28.5 percent growth to 2034, and it is concentrated at the experienced end.

Junior applicants are plentiful and blocked, which makes this a progression problem rather than a supply problem.

Certifications demonstrate knowledge and not judgement, which is why certification budgets have not closed the gap.

Most breaches use unremarkable methods against known weaknesses, so disciplined basics deliver most of the available risk reduction.

And every genuinely hard-to-fill security role requires depth in something else first. The people who can fill them are already in your infrastructure, network and development teams.

Frequently asked questions
Is there really a cybersecurity talent shortage?

At the experienced end, yes. BLS projects 28.5 percent growth for information security analysts to 2034. At entry level, applicants are plentiful and frequently cannot get a first role, so the pipeline is blocked at the first step rather than short of people.

Why have certifications not solved it?

Because certification demonstrates knowledge of a defined body of material, while the scarce roles require judgement under uncertainty: deciding which findings matter, acting on incomplete information, understanding a specific environment and persuading people with other priorities.

What causes most breaches?

Stolen, guessed, reused or phished credentials; unpatched systems with long-disclosed vulnerabilities; services unintentionally exposed to the internet; excessive permissions; and access through third parties with weaker controls.

Which security roles are hardest to fill?

Detection engineers, experienced incident responders, cloud security engineers, application security engineers who can read code, operational technology security specialists, and architects who design rather than assess.

Who converts best into security?

Systems administrators first, then network engineers into detection, developers into application security, cloud engineers into cloud security, support staff into security operations, and control engineers into industrial security.

Promote into it rather than recruiting against everyone
Eight directions across AI, data and computing, including cybersecurity alongside IT systems and networks, cloud and DevOps, and software engineering. Scoped with your own teams, in five-minute lessons.
Written by Aleksandr Mikhailov
Founder, Astra Trainer · Published · Updated
Continue reading