A survey of 500+ cybersecurity pros sheds light on which skills they find most useful in cybersecurity job candidates, and which are most frequently lacking
Thousands of people graduate from colleges and universities each year with cybersecurity or computer science degrees only to find employers … Tweets: @bettersafetynet , @briankrebs , @infosecsherpa , and @foresightcyber Tweets: Mick Douglas / @bettersafetynet : Put the work in! Get your learn on... and get PAID. Infosec is not for the faint of heart, but for those who are willing to study/work hard, you have a bright future. Pick something and learn it WELL. Then pick another thing. Find those who will help you on your way. Join us! https://twitter.com/... @briankrebs : Considering a career in cybersecurity? Here are some hard truths about what you should expect potential employers will expect, and how to better stand out from the crowd. https://krebsonsecurity.com/ ... @infosecsherpa : Happy to see @WomenCyberjutsu mentioned in this @briankrebs article. Their classes and events are a big part of my own #InfoSec career success. What I didn't see was a mention of the very important so-called soft skills. Communication & ppl skills are 🔑! https://krebsonsecurity.com/ ... @foresightcyber : We agree: “know how computers and networks work with hands-on experience”. Perhaps setup home network with coup of RaspberryPIs and free AWS or Azure account to play with Cloud? One cannot secure something one does not know how it works. https://twitter.com/...
Context & Ripple Effects
This survey lands in the middle of a running thread on cybersecurity's hiring mismatch: a December 2020 report put the global talent gap at 3.1M unfilled professionals, and coverage of the $266B cybersecurity market by 2024 already flagged the skills shortage as the industry's binding constraint, with automation and AI positioned as partial relief. What the survey adds is the demand-side detail — which skills practitioners actually value in candidates, and which employers find missing.
That detail matters because both sides of the market are already under strain: the US government and private sector face what the Washington Post called a severe worker shortage amid an unprecedented threat slate, and CISA itself is reported short on talent. A survey naming the specific gaps gives employers and degree programs a concrete target instead of a headcount deficit.
First-order effects
- Employers get a practitioner-validated checklist for screening candidates, shifting weight from degrees toward the specific skills the 500+ respondents flag as most useful — and most frequently lacking.
- Recent graduates with cybersecurity or computer science degrees learn that their credential alone doesn't cover what hiring practitioners say is missing, changing what they need to demonstrate.
Second-order effects
- Companies under pressure to fill roles — the same pressure driving calls to relax hiring requirements — can use the survey to justify skills-based screening over degree requirements, widening the candidate pool.
- Training providers and university programs face demand to close the named skill gaps, while vendors selling automation and AI tools gain an argument that their products offset the shortfall the survey documents.
Third-order effects
- If employers act on the survey, cybersecurity hiring structurally shifts from credential-based to skills-verified — a market where the 3.1M-person gap forces buyers to hire for demonstrated capability rather than pedigree.
- Persistent gaps in the specific skills practitioners name push the industry toward automation-first staffing models, with human hires concentrated where machines demonstrably fall short.
The trend: Cybersecurity hiring is moving from degree- and credential-based screening toward skills-verified selection as the multi-million-person talent gap forces employers to hire for demonstrated capability.