Cybersecurity Firms Have Limited Junior Hiring

Managers struggle with skills decay as they move toward short-form training to close gaps.

Updated on Sept. 29, 2026 in Job Search

Bold flat-color editorial illustration of stacked server components and a padlock, representing institutional security training and hiring constraints.
Cybersecurity firms are significantly limiting junior-level hiring while pivoting toward intensive, short-form training to combat persistent organizational skill decay. AI Illustration. Upload story photo >

Live Poll

Should companies prioritize job experience over practical skills assessments when hiring for technical roles?

Seventy percent of organizations now report having few or no junior cybersecurity roles available for candidates with under two years of experience. This hiring constraint persists even as 57% of executives report that new hires require six months to reach full proficiency.

Why it matters

Skills decay, affecting 39% of teams and 60% of large enterprises, is forcing security leaders to reevaluate traditional training methods. Urgent daily operational tasks often prevent staff from completing long-form development, driving a shift toward more consistent, shorter training intervals.

Seventy-one percent of security leaders now prefer 20-minute weekly training sessions over longer programs, while 57% of executives report that new hires take six months to reach full proficiency. Additionally, 60% of companies with at least 50,000 employees are currently facing skills decay.

The details

Organizations are shifting away from traditional training models, with 71% of leaders now prioritizing 20-minute weekly online or interactive lab sessions. Meanwhile, internal hiring remains restrictive, as firms prioritize experienced talent to mitigate the 39% of teams reporting skill loss. Leaders are attempting to measure readiness more objectively by reporting audit results, performance reviews, and certification counts to their boards.

Timeline

  1. 2025 marked the period when over 80% of surveyed executives fully exhausted their training budgets.

Market Landscape

This trend toward micro-learning follows the documented shift within large organizations to combat pervasive skills decay. It marks a departure from traditional, long-form training programs that historically failed to keep pace with rapid shifts in general IT and cybersecurity processes.

Operators should evaluate if their current training budget is being misallocated to long-form programs that staff struggle to complete during daily operations. Consider auditing team readiness through objective metrics like certification counts and performance reviews rather than relying on tenure alone.

The takeaway

The move toward micro-training suggests that consistency in development is becoming more valuable than traditional long-form instruction. Managers should track the effectiveness of 20-minute learning sprints against the six-month proficiency delay currently standard for new hires.

Further reading

For more context on navigating talent acquisition hurdles, see Job Search.

Source note: This article includes information reported by Help Net Security.

Live Poll

Should companies prioritize job experience over practical skills assessments when hiring for technical roles?

Cybersecurity Firms Have Limited Junior Hiring | Highwise Business