Opens in a new tab
vmblog logo 2024 wht (updated)

The Cybersecurity Skills Gap Is Still Wide Open: What the BLS Data Says and How IT Professionals Are Closing It

Share: 

cybersecurity skills gap still wide open

By Tina Martin of Ideaspired

Despite years of awareness campaigns, vendor training programs, and university investment, the cybersecurity workforce gap hasn’t closed. Here’s what the labor market data actually shows about the skills employers need, and what’s working for tech professionals who are building toward a security career.

The cybersecurity workforce shortage has been a fixture of technology industry conversations for long enough that it risks becoming background noise. It shows up in every annual threat report, every HR survey of IT hiring challenges, and every vendor whitepaper about the future of enterprise security. The familiarity of the problem can make it easy to tune out.

But the underlying data is worth looking at directly, because it’s not a narrative constructed by vendors with a training product to sell. It comes from the Bureau of Labor Statistics, which tracks occupational demand, median wages, and projected growth across the U.S. economy with the kind of methodological rigor that makes it the most reliable public source on labor market conditions. And what the BLS data shows about cybersecurity is that the gap between employer demand and available qualified candidates is real, persistent, and showing no signs of resolving on its own.

This article is for IT professionals who are thinking seriously about moving into cybersecurity or advancing within it, and for organizations trying to understand what skills they actually need when they post a security role. The job posting language and the credential requirements in this space are often disconnected from what the work actually involves, and understanding that disconnect is useful context for anyone on either side of the hiring table.

What the BLS Data Actually Shows About Cybersecurity Demand

The Bureau of Labor Statistics tracks information security analysts as a distinct occupational category, and the numbers for this role are consistently among the most striking in the entire Occupational Outlook Handbook. The BLS projects job growth for information security analysts at 32 percent through 2032, a rate it classifies as “much faster than average” and that places cybersecurity among the fastest-growing occupations in the U.S. economy across all sectors.

Median annual wages for information security analysts were reported at over $120,000 in the most recent BLS data, placing the role well above the median for all occupations and in the upper tier of the broader computer and information technology category. That wage premium reflects genuine scarcity: employers are paying above market because qualified candidates are hard to find, not because the work is inherently more complex than other senior technical roles.

The demand picture is reinforced by independent labor market data from Lightcast, which tracks job postings at scale and consistently shows cybersecurity roles among the hardest to fill in the technology sector. Open positions in information security stay unfilled significantly longer than comparable technical roles, and the rate at which new positions are being posted continues to outpace the rate at which qualified candidates are entering the market.

The Skills the BLS Identifies for Information Security Analysts

Understanding what the BLS identifies as the core skill set for information security analysts is useful context for both career changers and hiring managers, because it clarifies what the role actually requires as distinct from what job postings tend to ask for.

The BLS skill profile for information security analysts includes both technical and analytical competencies. On the technical side, the role requires proficiency in network security architecture, intrusion detection systems, vulnerability assessment tools, and security information and event management (SIEM) platforms. Familiarity with regulatory compliance frameworks, including NIST, ISO 27001, and SOC 2, is increasingly expected as organizations face growing regulatory pressure around data protection.

The analytical and problem-solving dimensions of the role are equally important and often underweighted in job postings that lead with tool-specific requirements. Information security analysts spend a substantial portion of their time on threat modeling, risk assessment, incident investigation, and the kind of structured reasoning under uncertainty that doesn’t show up cleanly in a list of certifications. These are skills that develop through practice and can be developed through well-designed educational programs, but they’re harder to document than tool proficiency, which is part of why the credential landscape for this role is more complex than for purely technical positions.

For IT professionals in adjacent roles, the skills overlap is often more substantial than it appears from the outside. Network administrators, systems engineers, DevOps practitioners, and IT operations professionals frequently have working knowledge of several core security competencies already, and the gap between their current skill set and a cybersecurity role is often narrower than a job posting’s credential requirements suggest.

Why Credential Requirements in Cybersecurity Job Postings Are Often Misleading

One of the more frustrating features of the cybersecurity hiring market is the mismatch between what job postings require and what the work actually demands. This mismatch is well-documented and it affects both candidates trying to break into the field and organizations trying to fill roles.

On the credential side, a large proportion of cybersecurity job postings include degree requirements, often a four-year degree in computer science or a related field, that aren’t actually predictive of job performance in the role. Research on hiring outcomes in cybersecurity consistently shows that domain-specific certifications, demonstrated hands-on experience, and verified skills in relevant tools and methodologies are better predictors of success than general degree credentials. The degree requirement in many postings is a filtering mechanism, not a genuine assessment of job readiness.

The certification landscape has partially addressed this, with credentials like CompTIA Security+, Certified Ethical Hacker (CEH), and the Certified Information Systems Security Professional (CISSP) providing more specific signal about a candidate’s technical capabilities than a general degree. But certifications have their own limitations: they tend to test knowledge rather than applied skill, they don’t document how that knowledge was developed or assessed, and they don’t provide employers with evidence of the analytical and problem-solving competencies that distinguish strong security professionals from those who’ve memorized the right answers for an exam.

The emerging response to this gap is skills-based hiring frameworks that evaluate candidates on documented, verifiable competencies rather than credential proxies. A candidate who can demonstrate specific skills in network security architecture, threat modeling, and incident response, with verified evidence of how those skills were assessed, is more useful to a hiring manager than one who has a degree in a related field but no documented security competency.

How Working Adults Are Closing the Cybersecurity Skills Gap

For IT professionals who are actively building toward a cybersecurity role, the path forward is clearer than it used to be, partly because the credential infrastructure for documenting specific security skills has matured considerably.

The most effective approach tends to combine targeted certification preparation with structured educational programs that develop and document the broader analytical and technical competencies the role requires. Certifications provide point-in-time evidence of specific technical knowledge. Degree programs that are designed around employer-validated competencies and issue verifiable credentials at the course level provide a more complete picture of a candidate’s capabilities, including the problem-solving and risk assessment skills that are harder to capture in a certification exam.

For working adults who are mapping their own skill gaps against the BLS competency profile for information security analysts, a practical starting point is occupation-level skills data that cross-references what the BLS identifies for specific roles with how those skills can be developed and documented through degree programs. Resources that compile BLS-sourced skills requirements across cybersecurity and other IT career pathways make it easier to see specifically where your current skill set aligns with what employers in the field are looking for and where the gaps are.

The timeline question is worth addressing directly. For an IT professional in a network administration or systems engineering role, building toward an information security analyst position typically takes twelve to twenty-four months if approached systematically: targeted coursework and certifications in parallel, hands-on experience in security-adjacent responsibilities where the current role allows, and documented credentials that make the skill development visible to prospective employers throughout the process rather than only at the end.

What Skill Verification Means for Tech Hiring in 2026

The broader shift toward skills-based hiring that’s been building across the technology sector has specific implications for cybersecurity, a field that has always had a more pragmatic relationship with credentials than most.

Enterprise technology employers, including the major cloud providers, managed security service providers, and the large financial and healthcare organizations that employ the most security professionals, have been moving steadily toward hiring frameworks that evaluate candidates on verified, specific competencies rather than degree requirements. The talent shortage in security has accelerated this: when qualified candidates are genuinely scarce, filtering on degree credentials is a luxury the market can’t sustain.

The practical implication for IT professionals is that the ability to present verified evidence of specific security skills, through course-level digital credentials, certifications, portfolio evidence, or some combination, matters more in this market than it does in fields where the credential-to-competency mapping is cleaner. A candidate who can say “here’s a verified credential showing I completed advanced coursework in network security architecture, here’s my Security+ certification, and here’s a description of the incident response work I did in my current role” is presenting a more useful picture to a hiring manager than one who leads with a degree and a list of tools.

For organizations doing the hiring, the shift toward skills verification also has internal talent development implications. IT professionals who are already on staff in adjacent roles are often closer to cybersecurity competency than their current titles suggest. Building internal pathways that help these professionals document and develop security-relevant skills, rather than defaulting to external hiring for every open security position, is both more cost-effective and more likely to produce professionals who understand the organization’s specific environment.

The Fields Adjacent to Cybersecurity With the Strongest Skills Overlap

For IT professionals who are considering a move into security from an adjacent role, understanding where the skills overlap is densest can help prioritize where to focus development efforts.

Network administration and engineering is the most natural adjacent role. Network professionals who understand TCP/IP architecture, routing and switching, firewall configuration, and network monitoring already have a substantial portion of the technical foundation for network security roles. The additional competencies required, intrusion detection, vulnerability scanning, incident response protocols, build directly on that foundation.

Cloud infrastructure and DevOps roles have developed significant overlap with security as cloud environments have become the primary attack surface for most enterprise organizations. Cloud security, identity and access management, and infrastructure-as-code security practices are areas where cloud engineers and DevOps practitioners frequently have working knowledge that translates directly to security roles. The DevSecOps movement has formalized this overlap considerably.

IT operations and systems administration professionals often have broader visibility into an organization’s technology environment than more specialized roles, which is a genuine asset in security work that involves understanding how systems interact and where vulnerabilities are most likely to surface. The analytical dimension of security work, thinking systematically about risk and failure modes, maps well to the troubleshooting and systems thinking that operations professionals develop over time.

Software development roles have an increasingly direct relationship with security, particularly as application security and secure development practices have moved from compliance requirements to genuine engineering disciplines. Developers who understand how vulnerabilities are introduced in code and how secure development practices prevent them are well-positioned for application security and penetration testing roles.

The Bottom Line

The cybersecurity skills gap is a genuine labor market condition, not a marketing narrative. The BLS data on demand, wage premiums, and projected growth is consistent and has been for years. The gap between what employers need and what they’re able to hire reflects a real shortage of professionals with the specific, documented skills the role requires.

For IT professionals who are thinking seriously about moving into security, the good news is that the path is more concrete than it’s ever been. The BLS competency profile for the role is public and specific. The credential infrastructure for documenting security skills, from certifications to course-level digital badges from degree programs, has matured considerably. And the shift toward skills-based hiring in enterprise technology means that documented, verifiable competency is increasingly what opens doors, not the degree credential that might have been the primary filter five years ago.

The professionals who are closing the gap most effectively are the ones who approach it systematically: map the BLS skill requirements for the specific role they’re targeting, identify the gaps honestly, build credentials that document their development in verifiable form, and present that evidence actively rather than waiting for a degree or certification to do the signaling on their behalf.