Most cybersecurity staffing searches are lost before a single résumé is sourced. The requisition asks for a single person to run the security operations centre, own cloud posture, manage the audit, and build the detection pipeline — and lists eleven certifications as required. That person exists in perhaps four companies in the country, and none of them are leaving.
The talent shortage in security is real, but it is smaller than it looks. A meaningful share of it is a scoping problem wearing a shortage costume. This guide covers the seven distinct roles that get collapsed into “we need a security person,” how to screen for them when nobody on your interview panel is a security practitioner, and what certifications actually tell you.
Table of Contents
- Why cybersecurity staffing fails before sourcing begins
- The seven roles people lump together as “security”
- Scoping the requisition: three decisions before you post
- How to screen security candidates without a security team
- Certifications: what they prove and what they do not
- Contract or permanent in cybersecurity staffing
- Common mistakes
- Frequently asked questions
- Conclusion and next step
Why Cybersecurity Staffing Fails Before Sourcing Begins
Security hiring has three structural features that make it behave unlike any other technical search.
The discipline is far broader than the job title suggests. A detection engineer and a GRC analyst share a department and almost nothing else. One writes queries against telemetry at three in the morning; the other negotiates control language with auditors. Both are “cybersecurity.” Hiring one when you needed the other is the most common and most expensive failure in the category.
Almost nobody is actively looking. Competent security staff are employed, well compensated and courted continuously. Posting a job and waiting produces a pool dominated by people who are between roles for reasons you will need to understand. The candidates worth hiring come through relationships and referrals.
The people evaluating are usually not practitioners. In most mid-sized organizations the hiring manager is an IT director or a CTO who knows security matters but cannot judge whether an answer about lateral movement detection was any good. This is the gap that produces credential-based hiring, which is how you end up with someone who holds five certificates and has never triaged a real incident.
Expert tip: Before you write the job description, write the list of things that will be this person’s responsibility in month one. If the list crosses more than two of the seven roles below, you are writing a requisition for a person who does not exist — and you will spend a quarter proving it.
The Seven Roles People Lump Together as “Security”
Titles vary wildly between organizations, so scope the work rather than trusting the label. These seven cover the overwhelming majority of security requisitions.
| Role | What they actually do | Strongest screening signal |
|---|---|---|
| SOC / detection analyst | Triages alerts, investigates incidents, tunes detections | Can walk through a real investigation and what turned out to be nothing |
| Detection engineer | Builds and maintains the detection logic behind the alerts | Talks about false positive rates and data quality unprompted |
| Cloud security engineer | Identity, configuration and workload security in AWS, Azure or GCP | Fluency in the identity model of one platform, deeply |
| Application security engineer | Secure design review, code and dependency analysis, developer enablement | Has shipped code and can explain a vulnerability class to a developer |
| Offensive security / pentester | Adversary simulation, penetration testing, red teaming | Reporting quality and remediation advice, not exploit collection |
| GRC analyst | Frameworks, audits, risk register, vendor and control assessment | Can explain why a control failed rather than that it failed |
| Security architect | Cross-cutting design, standards, threat modelling, technology selection | Has said no to a business initiative and made it stick |
The overlap between adjacent roles is genuine — a cloud security engineer often does application security work, and a small team will ask one person to cover both. The overlap between distant roles is not. A pentester will not enjoy your audit, and a GRC analyst cannot tune your SIEM.
Scoping the Requisition: Three Decisions Before You Post
1. Are you buying build capacity or run capacity?
Building a capability — standing up logging, implementing identity governance, establishing a vulnerability management programme — is project work with a definable end. Running it is continuous. These attract different people, and a builder placed into a run role leaves within a year because the interesting work finished in month five. Decide which you need and say so in the posting; candidates self-select accurately when you are honest about it.
2. What is the actual reporting line and authority?
Security roles fail when the person can identify risk but cannot compel anyone to act on it. Experienced candidates ask about this in the first interview, and a vague answer is disqualifying to them even if the compensation is strong. Settle who this person reports to, what they can block, and who arbitrates when engineering disagrees — before the search starts, not after an offer.
3. Which two skills are genuinely non-negotiable?
Cut the requirements list to two. Everything else becomes “valued.” This is not a lowering of standards — it is a recognition that security professionals specialize, and a list of fourteen requirements describes a committee. The pool for two deep requirements is many times larger than the pool for fourteen shallow ones, and the candidate you get is better at the things you actually needed.
How to Screen Security Candidates Without a Security Team
This is the practical problem for most organizations making their first or second security hire. You cannot assess depth in a field you do not practise. Three approaches work.
Ask for narrative, not knowledge
Knowledge questions are easy to study for and tell you nothing. Narrative questions are not. “Walk me through an incident you worked, from the first alert to the closing writeup” produces an answer whose texture you can evaluate even without domain expertise. Real practitioners include the dead ends, the thing they initially misread, and what the business impact turned out to be. Rehearsed candidates give you a clean, linear story with no friction in it.
Test the explanation, not the answer
Ask the candidate to explain a vulnerability class to you as though you were a developer who has to fix it. Security work is overwhelmingly persuasion — the technical finding is the easy half, and getting an engineering team to prioritize the fix is the job. Someone who cannot explain the risk clearly to a non-specialist will not be effective regardless of their technical depth.
Borrow a practitioner for one hour
A single hour of a genuine security engineer’s time on your final panel is worth more than three rounds of your own. Use an advisor, a board contact, a fractional CISO, or a staffing partner whose technical screen is run by practitioners rather than keyword matching. This is the specific thing to test when evaluating a partner — our 12-point guide to choosing an IT staffing agency opens with exactly that question, because it is the highest-signal one available.
Certifications: What They Prove and What They Do Not
Certifications are a reasonable filter and a terrible decision criterion. Used well they confirm a baseline vocabulary and a willingness to study. Used badly they become the entire screen, which is how cybersecurity staffing produces expensive mis-hires.
A few distinctions worth holding:
- Management-oriented certifications signal breadth, governance vocabulary and years of experience. They do not indicate that someone can investigate an alert.
- Hands-on, practical-exam certifications — the ones requiring you to actually compromise or defend a live environment — carry considerably more technical signal, because they cannot be passed by memorization.
- Vendor and cloud certifications confirm platform familiarity, which is genuinely useful when your environment is that platform and near-worthless when it is not.
- Compliance-driven requirements occasionally mandate specific credentials for specific contracts. If that applies to you, it is a hard requirement rather than a preference — confirm it early, because it materially shrinks the pool.
For structuring what you actually need, the role and skill taxonomies published through CISA and the control language of the NIST Cybersecurity Framework are more useful than any certification list. They let you describe the work in terms candidates recognize, which improves the quality of applications considerably.
Expert tip: Treat certifications as a tiebreaker between two candidates who both cleared the narrative screen — never as an entry gate. Some of the strongest defenders in the field came from systems administration, software engineering or IT support and never sat an exam, because their employer never required one.
Contract or Permanent in Cybersecurity Staffing
Security divides unusually cleanly along this line, which makes the decision easier than in most disciplines.
Contract suits penetration testing and assessments, compliance readiness sprints ahead of an audit, incident response surge capacity, and capability build-outs with a defined endpoint. These are bounded, specialist and genuinely episodic — renting the expertise for the window you need it is the rational choice, and the specialists themselves often prefer it.
Permanent suits anything requiring accumulated knowledge of your environment: detection tuning, security architecture, the ownership of your risk register, and anyone who needs organizational standing to say no. A contractor cannot build the internal credibility that security leadership depends on, however capable they are.
The trade-offs generalize beyond security, and our guide to contract staffing vs permanent hiring works through the cost comparison and the classification questions in detail. Regulated environments add another layer — the credentialing and access-provisioning sequencing described in our healthcare IT staffing guide applies to security contractors in finance and healthcare almost identically.
Common Mistakes
Writing one requisition for three jobs
The single most common error. If the responsibilities span the SOC, the cloud estate and the audit, you have three part-time roles and no viable candidate. Split them, sequence them, or accept that you are hiring for one and buying the others as services.
Screening on tool names
A named SIEM on a résumé tells you nothing about whether the person wrote detections or merely watched a dashboard. Tools change every three years; the analytical habit does not. Screen for how they think about signal and noise, then confirm the tool exposure separately.
Moving too slowly for the market
Security candidates typically hold multiple conversations at once, and a four-week loop loses people you had already decided to hire. The scheduling and feedback discipline in our guide to reducing time-to-fill for IT roles matters more here than almost anywhere else.
Hiring a leader before there is anything to lead
A security director with no team, no budget and no mandate will leave. If you need the capability rather than the headcount, a fractional arrangement or a well-scoped engineer usually delivers more in the first year.
Excluding people who came in sideways
Systems administrators, developers and network engineers who moved into security bring operational context that is difficult to teach and frequently outperform candidates with a straight security-only background. Automated keyword screens discard them routinely.
Frequently Asked Questions
Why is cybersecurity staffing so difficult compared with other IT hiring?
Three reasons compound: the discipline contains several genuinely distinct specialisms that share one job title, qualified people are almost never actively job-seeking, and the hiring panel usually lacks the expertise to assess depth. The first of these is within your control and is where most of the difficulty actually originates.
Do we need certified candidates, or is experience enough?
Unless a specific contract or regulatory obligation mandates a named credential, experience wins. Certifications confirm vocabulary and study discipline; they do not demonstrate judgment under pressure. Use them to break ties, not to build the shortlist. Bodies such as ISC2 publish useful workforce research, but their credentials are one input among several.
Should a first security hire be a leader or an engineer?
In most cases an engineer, supported by fractional or advisory leadership. A senior leader with nothing to lead has no way to demonstrate value and typically departs inside a year. Hire the person who will do the work, then add leadership when there is a team and a budget for them to run.
Can we hire security talent remotely?
Most security work is remote-compatible, and insisting on on-site presence without a concrete reason shrinks an already thin pool. The genuine exceptions are roles requiring physical access to facilities or hardware, and positions where a contract or clearance imposes location constraints.
How long should a cybersecurity search take?
Sourcing is rarely the constraint for a well-scoped role. A partner with an existing security network can produce a qualified shortlist within days; elapsed time is then driven by your scheduling, your panel’s availability and your decision speed. Poorly scoped roles, by contrast, can run for months and still fail.
Conclusion: Scope the Role, Then Search
The shortage is real, but it is not the reason most security searches stall. Write down what the person will own in month one. Cut the requirements to two non-negotiables. Decide whether you are buying build capacity or run capacity, and settle the authority question before anyone is interviewed. Searches scoped that way close in weeks; searches scoped as a wish list do not close at all.
Then screen for narrative rather than knowledge, and get one practitioner in the room before you make an offer.
KJIT Solutions INC provides IT staffing, contract hiring, permanent recruitment and managed workforce programmes across the United States, with specialist practices in technology, healthcare, finance and engineering. If you have a security role that is proving hard to fill, talk to our team — bring the requisition and we will work through the scoping question with you first.
Prefer to keep reading? Browse more hiring and workforce insights from the KJIT Solutions team.