Nonprofit cybersecurity member organisation ISC2, has today published its 2025 Cybersecurity Hiring Trends Report.
Based on insights from 929 hiring managers across organisations of all sizes in the UK, Canada, Germany, India, Japan and the U.S., the report provides guidance for reassessing recruitment, hiring and retention strategies to better attract entry- and junior-level talent and build more resilient cybersecurity teams.
The report found when evaluating candidates, managers prioritise those with hands-on IT experience or cybersecurity certifications over those with education in IT, cybersecurity and computer science that lack professional experience.
According to the research, 90% of respondents would consider candidates with prior IT work experience only and 89% would consider those with only entry-level cybersecurity certifications.
In contrast, only 81% would consider candidates who only have an education in IT, cybersecurity or computer science.
Investing in Early Career Talent
The majority of hiring managers surveyed (56%) said that training entry-level cybersecurity team members to handle tasks independently typically takes 4–9 months, while 45% said the same for junior-level practitioners.
Moreover, hiring managers reported spending between U.S. $1,000 and $4,999 to train entry- (45%) and junior-level (38%) team members to handle tasks independently.
Most hiring managers surveyed also recognise the importance of supporting the long-term growth of entry- and junior-level employees. In fact, 91% of hiring managers reported providing professional development opportunities for these team members during work hours.
Skill Expectations
Hiring managers also reported specific expectations around the tasks typically assigned and handled proficiently by entry- and junior-level cybersecurity talent.
Top tasks for entry-level professionals include:
- Documentation (Processes, Procedures) (43%)
- Alert and Event Management (35%)
- Reporting (Developing, Producing) (32%)
- Physical Access Controls (30%)
- User Awareness Training (29%)
Top tasks for junior-level professionals include:
- Backup, Recovery and Business Continuity (53%)
- Intrusion Detection (53%)
- Alert and Event Management (51%)
- Relevant Frameworks (50%)
- Penetration Testing (50%)
Other key findings from report show that nearly a quarter of hiring managers who recruit from education programs – specifically, 25% of the 55% who do so – have sourced candidates from disciplines outside of computer science, IT, or cybersecurity, effectively expanding the talent pool.
Internships and apprenticeships are also proving valuable, with 55% and 46% of respondents respectively seeing them as effective ways to identify early-career talent. These approaches are gaining traction across sectors such as education, healthcare, and government.
Hiring managers are increasingly emphasising non-technical skills, too. In fact, three of the top five most prioritised competencies are soft skills like teamwork, problem-solving, and analytical thinking.
Recommended reading
- Can Europe ‘Trump-Proof’ Its Cloud Services?
- What Top Trends Are Shaping the Future of Cloud?
- Growing Adoption of Zero-trust and Multi-cloud Environments
When it comes to attracting top talent, collaboration with HR is key. While hiring managers typically set job requirements – covering everything from skills and education to certifications and security clearances – HR teams are often responsible for defining non-technical skill needs. Screening candidates is a shared task between both.
In evaluating applicants, 84% of hiring managers report using skills-based assessments or tests for entry- and junior-level cybersecurity roles. Notably, 54% say they have rejected candidates due to concerns stemming from their social media activity.
“Entry- and junior-level roles are critical for the future of the cybersecurity profession,” said ISC2 Chief Qualifications Officer Casey Marks.
“Investment in people and career-long learning will always be essential components of resilient cybersecurity teams.
“This year’s Hiring Trends Report reveals how cybersecurity hiring managers recognize the importance of providing opportunities to the next generation of cybersecurity professionals and our research can help others managing cyber teams create a roadmap for hiring and developing entry- and junior-level team members.”





