Both of those things are true at the same time, and nobody explains why.
Every article about cybersecurity careers opens with the shortage. The numbers are real and they are large. And if you already work in IT — running the network, holding the tickets, patching the servers — you have read those numbers and thought the obvious thing: then why hasn’t anyone hired me?
That gap is the actual subject of this page. Not the demand number. The distance between the demand number and your inbox.
What the demand data actually says
Sourced and dated, because the rest of this only matters if the foundation is real.
- The U.S. Bureau of Labor Statistics projects 29% employment growth for information security analysts from 2024 to 2034 — roughly ten times the average across all occupations — with about 16,000 openings per year. Median pay was $124,910 in May 2024. BLS also notes that analysts commonly arrive from related IT occupations, including network and systems administration. (BLS, Occupational Outlook Handbook, 2024–34 projections.)
- ISC2’s 2025 Cybersecurity Workforce Study — 16,029 practitioners, the largest sample it has ever run — found the binding constraint is no longer headcount. It’s skills. (ISC2, December 2025.)
- CyberSeek (NIST + CompTIA) tracks hundreds of thousands of open U.S. cybersecurity postings at any given time, with employers consistently filling fewer seats than they post. (CyberSeek, 2025–26 data.)
[VERIFY — pull the live national openings figure and supply/demand ratio from cyberseek.org/heatmap.html and state the month.]

Read those together and the slogan turns into something more useful.
The shortage is a skills shortage, not a headcount shortage
This distinction is the whole thing.
A headcount shortage says we need bodies — apply and you’re in. A skills shortage says something less comfortable: the seats are open because the people applying can’t demonstrate they can do the work.
If it were a headcount shortage, eight years in infrastructure plus a certification would already have gotten you in. It hasn’t. That isn’t a personal failure — it’s an accurate description of the market you’re applying into.
Which is also why “entry-level” cybersecurity postings keep asking for two years of experience. Employers aren’t being unreasonable for sport. They’re trying to buy judgment, and a job posting is a blunt instrument for asking whether you have it.
Hiring managers are looking directly at you
Here is the part of the data almost nobody in IT has been shown.
ISC2 asked 929 cybersecurity hiring managers what they’d accept in entry- and junior-level candidates:
- 90% would consider a candidate with prior IT work experience only — no security certification, no security degree.
- 89% would consider someone with only an entry-level security certification.
- 81% would consider a candidate whose qualification was an IT, cybersecurity, or computer science education with no professional experience.
(ISC2, 2025 Cybersecurity Hiring Trends Report, published June 2025; surveyed December 2024.)
Hands-on infrastructure experience ranks above a degree in what hiring managers will actually consider.
You have been treating your IT background as the thing that disqualifies you. The people doing the hiring rank it as the thing that qualifies you. The problem isn’t the experience. It’s that nothing on your resume tells them you have it in a language they screen for.
Why the demand isn’t reaching you
If you’ve applied and heard nothing, the demand didn’t skip you at random. There are usually three reasons, and all three are fixable.
Your resume is translated into the wrong career language. You’ve done access control, log review, permissions, patching, incident response, and privileged account cleanup. You called it “user support,” “AD administration,” and “systems maintenance.” The applicant tracking system was looking for the other words. The NIST NICE Framework exists precisely because the industry needed a common vocabulary for cyber work roles, tasks, and skills — and it’s the vocabulary US employers write postings in. Your experience isn’t weak. It’s untranslated.
You’re applying like a beginner. An IT professional with a decade of infrastructure work who submits a resume shaped like a bootcamp graduate’s is competing in the wrong bracket — against candidates with less to offer, for roles below the level actually available.
You picked a certification instead of a target role. Security+, CySA+, cloud security, CISSP — the order only makes sense once you know which seat you’re aiming at. Studying broadly before choosing narrowly is how people spend eighteen months and arrive nowhere in particular.
Where the demand actually is
“Cybersecurity is hiring” is useless. Demand is specific, and for someone with your background it’s specific in three ways worth knowing.
By role. The transitions that work are lateral, not from-scratch:
| Where you are now | Where the demand actually points |
|---|---|
| Help desk / desktop support | SOC analyst, security operations, IAM support |
| Sysadmin / Windows / Linux | Security engineering, endpoint hardening, vulnerability management |
| Network engineer | Network security, detection engineering, segmentation and firewall architecture |
| Cloud / DevOps | Cloud security, identity and machine-identity security, security automation |
| Infrastructure / ops lead | Security operations leadership, risk and controls, technically-grounded GRC |
By geography. Cybersecurity demand in the US is not evenly spread. It concentrates heavily around the Washington, D.C. metro and Virginia, driven by federal agencies, the defense industrial base, and contractors — with Texas, California, Florida, and New York as the other major hubs. CyberSeek publishes this at state and metro level, and it’s worth ten minutes of your time before you decide your local market is closed.
By sector. A large share of that demand sits in federal and defense-adjacent work, which runs on its own qualification logic. DoD 8140 defines the qualification expectations for DoD cyber work roles, and a baseline certification plus the right work role mapping opens doors that corporate postings never advertise. If you have prior military IT service, that pathway is shorter than you think.
The cost of waiting is real, and it’s quiet
Nobody needs to invent urgency here. Three things are simply arithmetic.
The shortage is being closed by people who look exactly like you. Not by career changers from unrelated fields. By sysadmins, network engineers, and help desk leads who learned to describe what they already do in the language of risk, threat, and control. There’s no deadline — but that pool deepens every year, and it’s the pool you’re competing in.
Your experience compounds technically and flattens categorically. To a security hiring manager, year eight in infrastructure reads almost exactly like year four unless something changes in how it’s framed. That’s the cost accruing silently while nothing appears to be going wrong.
The work you do today is the part most exposed to automation. Ticket triage, routine provisioning, first-line troubleshooting — that’s where the pressure lands first. Security judgment is the opposite: it’s the part that gets harder to automate, because it’s decision-making under incomplete information about a live adversary.
What actually closes the gap
The thing hiring managers are screening for is a repeatable way to look at an environment and decide what to protect, from what, with which control, in what order.
At Blue Team Academy that’s structured as the Threat & Control Method — four steps, run in sequence, applied to any environment:
- Inventory — establish what exists, what’s critical, and what already protects it. Output: an asset inventory.
- Threats — determine what can go wrong, how, caused by whom or what, and which risks matter most. Output: a threat model.
- Controls — find the gaps, select the right controls, turn security decisions into a plan. Output: a security plan.
- Scale — apply the same reasoning across other technologies, environments, and scenarios. Output: a repeatable decision process.
The steps are simple to state. The judgment inside them — how to prioritize, when a control is worth its operational cost, what to defend first when you can’t defend everything — is what separates someone who works in IT from someone the market reads as a defender.
Read the full breakdown: the Threat & Control Method explained.
What high demand does not mean
Blue Team Academy would rather be trusted than persuasive, so here’s the honest boundary around everything above.
- It does not mean guaranteed hiring. Demand raises your odds. It does not produce an offer.
- It does not mean a fast timeline. Anyone promising a security role in 30 days is selling urgency, not a path.
- It does not mean $124,910 is your first-year salary. That’s a median across the entire occupation, including people with a decade in the field. Moving from IT into security frequently means a lateral step first, not a raise first.
- It does not mean every security job is hiring. ISC2 has documented budget freezes and cuts running alongside the shortage. Both are happening at once.
- It does not mean remote roles are easy to get. Remote cybersecurity postings attract national competition. The demand is real; the remote slice of it is the most contested slice.
- It does not mean a certification alone unlocks it. Certifications get you past the screening filter. Demonstrated judgment gets you through the interview.
What high demand does mean is that the market is structurally short of people who can think defensively — and you already own the hardest half of that. The infrastructure fluency other candidates are missing, you built over years.
The rest is direction. Cybersecurity is not rocket science.

