Cybersecurity hiring is shifting from headcount to skills
New workforce research says cybersecurity employers are more often missing specific capabilities than people, a shift that is reshaping hiring, credential checks and training priorities. Canadian job postings also rose to a seven-quarter high, but entry-level openings remained scarce.
Why it matters: - Cybersecurity hiring is moving away from a simple headcount problem and toward a skills problem. - That changes how employers screen candidates, what credentials they value and how training programs are being judged. - In Canada, job-posting data suggests demand remains solid, but entry-level access is still narrow.
What happened: - The 2026 SANS | GIAC Cybersecurity Workforce Research Report surveyed 947 security and talent-acquisition leaders across six regions. - Sixty per cent said skills gaps on existing teams are the bigger problem, compared with 40 per cent who pointed to staffing shortages. - The 20-point gap widened from four points a year earlier. - Twenty-seven per cent of organizations reported a breach tied directly to a capability gap. - The Canadian Cybersecurity Network's Workforce Intelligence Brief for the second quarter of 2026 recorded 663 cybersecurity job postings between April and June. - That was a seven-quarter high and 23.7 per cent above the first quarter.
The details: - The Canadian report warns that part of the increase reflects broader collection on its job board, not only new demand. - The report also says the figures reflect postings gathered on one Canadian job board, not the national labour market. - Protection and Defence roles made up 51.9 per cent of Canadian postings. - Those roles include security operations, incident response, vulnerability analysis and threat analysis. - Oversight and Governance roles accounted for another 25 per cent. - Entry-level and junior roles made up 4.1 per cent of postings. - The report says that share has been roughly unchanged across every quarter it has tracked. - Among credentials named in postings, CISSP appeared in 35.1 per cent, Azure in 27.1 per cent, ISO 27001 in 23.1 per cent and CompTIA Security+ in 16.3 per cent. - Ontario accounted for 62.1 per cent of postings. - Alberta had 43 postings, down 21.8 per cent from the previous quarter. - The SANS research found employers most often validate skills through certifications at 64 per cent and skills assessments at 49 per cent. - Academic credentials were used less often, at 17 per cent. - ABM College's cybersecurity diploma online in Canada runs 70 weeks and includes a five-week practicum placement. - Coursework covers PC hardware and software troubleshooting, Windows client and server administration, Linux fundamentals, Active Directory infrastructure, Cisco routing and switching, cryptology and data protection, network security, mobile device security and security analysis. - The program includes exam preparation for CompTIA A+, CompTIA Network+, CompTIA Security+ and Microsoft Windows administration. - Certification exam vouchers are purchased separately by students. - The program is available online, in person or in hybrid format. - Scheduling options include morning, evening and weekend classes. - The diploma is offered in Calgary, Toronto and Winnipeg. - Admission requires Grade 12 completion or equivalent, passing Wonderlic Scholastic Level Exam and Accuplacer scores, and an admissions interview. - Mature student admission is available to applicants aged 18 or over who have been out of high school for at least two years. - Government student aid and Windmill Microlending financing are available to qualifying students.
Between the lines: - The data point to a market that rewards proof of capability more than broad interest in cybersecurity. - The low share of entry-level postings suggests employers want candidates who can contribute quickly. - The credential mix also signals that employers are prioritizing recognized technical and governance standards. - Dr. Mohammad Baten, President and CEO of ABM College, said the findings show employers want people who can do specific tasks and demonstrate those abilities, not just more applicants. - Baten argued that training should build foundations and align with recognized credentials rather than offer shortcuts.
What's next: - Employers are likely to keep leaning on certifications and skills testing when filling cybersecurity roles. - Training providers that can map coursework to employer-recognized credentials may have an advantage with students and recruiters. - Canadian hiring data will be watched for whether the strong posting volume turns into more junior openings.
The bottom line: - Cybersecurity hiring is becoming less about filling seats and more about proving skills, and that is raising the bar for both job seekers and training programs.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Canada Education News Wire
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.