top of page
ICON-Final-05_edited.png

4.8 Million Open Roles: Why Cybersecurity Is Still the Career Bet of the Decade

3 days ago
3 min read

The global cybersecurity workforce gap is once again making headlines: roughly 4.8 million unfilled positions worldwide, up 19% in a single year, according to ISC2's 2024 Cybersecurity Workforce Study. It's the most-cited number in the industry, and for good reason. Only 14% of organizations say they currently have the skilled people they need (World Economic Forum, 2025), and 90% report at least one skills gap on their security team (ISC2).


The gap isn't just a staffing headache. It shows up as risk: organizations with critical skills gaps are nearly twice as likely to experience a material breach (22% versus 17%, ISC2), and 56% of organizations name a lack of cybersecurity skills as a top cause of the breaches they've experienced (Fortinet, 2026), a figure that's held steady for three years running.


For anyone considering their next career move, the message is clear: this is a field where demand structurally outpaces supply, and has for years.



The skills in shortest supply are the ones you can actually learn

Here's the part that should make people sit up: the most sought-after skills right now aren't the ones that take a decade to build. ISC2's 2025 data shows AI/ML security climbing fastest, now the top-cited skills need at 41%, up from 34% the year before, followed by cloud security (36%), risk assessment (29%), and application security (28%). Fortinet's 2026 report adds that 60% of hiring managers say finding candidates with AI-specific security experience is their single biggest recruiting challenge.


None of these are things you need a computer science degree or ten years in the trenches to start building. They're exactly the kind of skills you build through structured training and a recognized credential.


That last point matters more than it might seem. Certification-level data shows real, measurable shortages in the more specialized, governance-oriented roles: there are roughly 2.2 job postings for every CISM holder, and 1.5 for every CISA holder. Compare that to an entry-level credential like Security+, where certified professionals outnumber open roles nearly 4 to 1. In other words, the crowded door is the beginner door. The shortage is in the next room: risk, compliance, audit, and governance roles that most people assume require years of tenure to reach, but that are really gated by a recognized certification proving you can apply a standard, not just talk about it.


You don't need to be "a hacker" to walk through this door

Security teams need risk assessors, compliance leads, auditors, and trainers just as much as they need penetration testers, arguably more, given where the certification shortages actually sit. What all of these roles share is the same entry mechanism: a certification that proves competence against a recognized standard.


Whether you're a student choosing a direction or a professional planning a pivot, the door is open. The honest caveat is that not every open "seat" is equally accessible: the raw 4.8 million figure describes perceived organizational need more than it does live job postings, and headcount budgets remain tight at plenty of organizations even as the skills gap persists. But the underlying pattern across every recent study is the same: demand for applied, certifiable skills, especially in AI security, cloud, and governance, is outrunning the supply of people who hold the credentials to prove they have them.


That's a rare thing in any labor market. It's worth taking seriously.


Sources: ISC2 2024/2025 Cybersecurity Workforce Study, World Economic Forum (2025), Fortinet 2026 Cybersecurity Skills Gap Global Research Report, StationX Cybersecurity Skills Gap Statistics 2026, Hakia Cybersecurity Talent Crisis 2026.

bottom of page