The security leaders you’ll need in 2031 are applying for entry-level jobs right now
Nearly every tech leader I talk to tells me that they need more cybersecurity talent, with one caveat: they want someone senior, with years of experience. Fortinet’s 2026 Cybersecurity Skills Gap Report makes it clear that this is becomi…
- 01One-third said mid-level.
- 02Just 13% said entry-level.
- 03Set that beside two other findings from the report: 71% say the skills shortage is creating additional risk for their organization, and for the third year running, the most-cited cause of breaches is a lack of cybersecurity skills and trained staff.
- 04In other words, CIOs know there’s a shortage of experienced cybersecurity professionals and are responding by competing harder for them.
Nearly every tech leader I talk to tells me that they need more cybersecurity talent, with one caveat: they want someone senior, with years of experience. Fortinet’s 2026 Cybersecurity Skills Gap Report makes it clear that this is becoming standard: slightly more than half of IT decision-makers said they need senior-level skills the most. One-third said mid-level. Just 13% said entry-level.
Read the full article at cio.comShow the full text · 5 min readHide the full text
Nearly every tech leader I talk to tells me that they need more cybersecurity talent, with one caveat: they want someone senior, with years of experience. Fortinet’s 2026 Cybersecurity Skills Gap Report makes it clear that this is becoming standard: slightly more than half of IT decision-makers said they need senior-level skills the most. One-third said mid-level. Just 13% said entry-level. Thirteen percent. Set that beside two other findings from the report: 71% say the skills shortage is creating additional risk for their organization, and for the third year running, the most-cited cause of breaches is a lack of cybersecurity skills and trained staff. In other words, CIOs know there’s a shortage of experienced cybersecurity professionals and are responding by competing harder for them. That’s not a talent strategy; it’s a bidding war. AI is removing the bottom rung, not the ladder The explanation I hear for why senior-level talent is in such high demand is the same as the reason cited for most hiring decisions these days: AI. AI can handle entry-level tasks; ergo, no need for entry-level talent. But AI is actually making the job harder, not easier. In the eighth annual ISSA/Omdia study of cybersecurity professionals , 83% of organizations are using or planning to adopt AI for security, while 68% of practitioners say the job has gotten harder over the past two years. AI, after all, is behind a lot of the breaches practitioners are trying to prevent. According to CrowdStrike , attacks from AI-enabled adversaries have risen 89% year-over-year, and the average window between initial compromise and lateral movement is down to 29 minutes. 82% of detections were malware-free. Here’s why that 82% is striking: malware-free means there’s no signature to match, no file to quarantine. Someone has to look at valid credentials doing superficially plausible things and determine, inside a 29-minute window, if it’s an intruder. That’s a judgment call, and that judgement is built by seeing enough “normal” to recognize “wrong.” It’s acquired by doing exactly the kind of work that’s now being automated. ISC2’s 2025 Workforce Study found that 56% of today’s cybersecurity professionals entered through IT, and the largest single group (36%) got there by picking up security responsibilities inside an IT role that may not exist anymore. Removing that path without designing a replacement doesn’t make junior analysts redundant. It means there’s no longer a way to produce the judgment you need, while the speed at which it has to be deployed only increases. The problem isn’t necessarily with AI’s output. It’s in losing the capacity to tell when the output is wrong, fast. The new entry-level requirement is AI fluency The senior-versus-junior framing assumes the skills you need are the ones seniority produces. But no one has years of experience doing identity and access management re-architected around AI agents. Or with no-code tools spawning rogue automations. The most important skills (and ones that junior hires are likely to have) are fluency with AI and a growth mindset. You want people who are always learning, because the threat landscape is always changing. An entry-level analyst in 2026 needs to arrive with an understanding of both halves of the problem: what the defensive tooling can and can’t do, and what the adversary is doing with the same tech. They should be able to tell when a model is overconfident, how prompt injection and data poisoning work against the systems they’re monitoring, and what an AI-generated phishing lure looks like without obvious red flags such as bad grammar. A comprehensive understanding of AI cybersecurity risks and defenses requires up-to-date, deliberate training. Stackable credentials (like CompTIA’s security track, vendor certifications, Google’s IT and AI certificate programs, etc.) can be earned in weeks by someone already working at an IT help desk or participating in a program like Per Scholas. What it looks like when organizations build the on ramp together Most CIOs I speak with support investing in apprenticeships and internships as a way to bring in talent, especially talent that’s underrepresented in tech. Their main question is how to find an intern or apprentice who’s eager to learn on the job and able to contribute from day one. The answer: partner with other organizations that specialize in providing just that. For example, we’ve built a custom cybersecurity pipeline with the public benefit corporation PeopleShores and Accenture. One alumna participated in a year-long cybersecurity analyst apprenticeship and spent that year working on real enterprise security infrastructure at Accenture while earning her CompTIA CySA+ and Splunk Core Certified User certifications. She was then hired permanently as a Cybersecurity Associate at Accenture, on the same enterprise data compliance project she had supported as an apprentice. She’s currently studying to become a Splunk Power User. We provided the initial training; PeopleShores hired our graduate as an apprentice; Accenture supplied input on the curriculum to meet industry needs, real production work, oversight, coaching and funding. At the end, Accenture had a security associate already trained on its own systems and compliance environment. Fortinet’s report found that 71% of organizations have formal targets for hiring from underutilized talent pools. Targets produce reporting. Structured apprenticeships and internships with a named enterprise partner produce staff. 4 things you can do this quarter: Rewrite one requisition. Most “entry-level” security postings are mid-level postings with entry-level pay attached. Strip the degree floor and the years-of-experience requirement from a single role. CIOs already prefer certifications over degrees; the job descriptions need to catch up. Specify AI fluency as an entry requirement, and fund it. Name the AI competencies a first-year analyst must demonstrate (on both the defensive tooling and the adversary’s use of the same tech) and accept stackable certificates as evidence of those skills. Then build the training regime to upskill new hires and existing staff as needed. Find an intermediary rather than working alone. The Accenture–PeopleShores structure works because no single party carries the whole apprenticeship. Fifty-one percent of organizations Fortinet surveyed already use internships and apprenticeships to reach broader talent pools, and 49% partner with nonprofits or training programs. The infrastructure exists. Measure progression and retention instead of time-to-fill. A senior hire who leaves in eighteen months costs more than a junior hire who stays five years. The top retention challenge in Fortinet’s data isn’t compensation but lack of training and upskilling opportunities. The investment that develops junior talent is the same one that keeps senior talent. The vast majority of organizations will need to expand their security team in the next twelve months. The best time to develop new cybersecurity talent is now, not when you’re facing a 29-minute window.
Don't miss tomorrow's
The Daily Pulse in your inbox each morning — sourced and linked.