Jobs Report, 2026 through September

Cybersecurity Jobs Report

235,786
United States cybersecurity job postings, January to September 2026

Down 26.4% from 320,210 in the same months of 2025.

Job titles are noisy. This report reads every posting through the CyberSN Taxonomy, so demand is counted by the work being asked for, not by the title on the listing.

Data pulled October 7, 2026. Each dot is 200 postings.

Reading the dots

Postings, not people

Every number here counts job postings: what employers asked for, not jobs or people. United States only, with duplicate listings removed at the source. One dot is 200 postings.

The CyberSN taxonomy defines 45 cybersecurity functional roles. Reading the ten leadership roles as one CISO area gives 36 areas, 33 of which have a posting series here.

The same months, four years

The lowest January to September in four years

273,498 in 2023, 244,911 in 2024, 320,210 in 2025 and 235,786 in 2026.

Eight of the nine months ran below the same month of 2025.

Core postings, January to September of each year
YearPostings
2023273,498
2024244,911
2025320,210
2026235,786
The full year

At this pace, 2026 lands below every full year since 2023

Full years: 353,368 in 2023, 338,138 in 2024 and 392,356 in 2025.

Applying each prior year's share of postings after September to 2026 projects 288,918 to 325,536 for the full year. It is a seasonal pace estimate, not a prediction of any event.

Core postings by full year
YearPostings
2023353,368
2024338,138
2025392,356
2026 (projected)288,918 to 325,536
Where the postings sit

Defense holds 41.5% of postings

It is also the broadest function, with eleven tracked roles, so its volume is partly a measure of breadth. Each disc is one function, sized by its postings from January to September 2026.

Share of core postings by function, January to September 2026
FunctionShare
Defense41.5%
GRC14.8%
Product Security12.8%
Manage9.8%
Plan7.3%
Offense4.6%
Response3.6%
Sales2.3%
Research2.3%
Educate1.1%
Depth, not breadth

Per role, Product Security leads

10,082 postings per tracked role across three roles, against 8,887 in Defense and 6,965 in GRC. DevSecOps alone carries 24,317.

Each disc is now one role. A function with fewer, larger discs has employers competing for the same work.

Postings per tracked role by function, January to September 2026
FunctionPer role
Product Security10,082
Defense8,887
GRC6,965
Manage5,756
Sales5,397
Plan4,303
Offense3,648
Response2,112
Research1,334
Educate1,299
Monthly postings, by yearAll tracked roles, complete months through September 2026
010k20k30k40k50kJanFebMarAprMayJunJulAugSepOctNovDec2026202420232025

Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.

When postings peakAverage month = 100, from 2023 to 2025
6080100120140JanFebMarAprMayJunJul122AugSepOctNov74Decaverage month = 100

Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.

Share of postings by functionJanuary to September of 2023 against 2026

Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.

What moved last quarterQ2 2026 to Q3 2026
Gaining
  1. Cryptography / PKI Professionalone-month spikeResearch+72.3%
  2. Cyber Risk AnalystGRC+20.2%
  3. Chief Information Security Officer (CISO)Manage+19.5%
  4. Security ArchitectPlan+14.0%
  5. Application Security EngineerOffense+9.9%
  6. Governance Risk & Compliance AnalystGRC+9.5%
Losing ground
  1. Cybersecurity DirectorManage-38.9%
  2. Penetration TesterOffense-26.6%
  3. Data Security EngineerDefense-19.0%
  4. Cybersecurity Project Managerone-month spikePlan-19.0%
  5. Red TeamerOffense-12.4%
  6. Security AnalystDefense-11.3%

Q2 2026 to Q3 2026, roles with at least 300 postings in Q2 2026.

Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.

CISO postings, by yearInformation Security Officer titles, Chief and Business included
0200400600800JanFebMarAprMayJunJulAugSepOctNovDec2026202420252023

Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.

Inside the postingsMonthly share mentioning AI or machine learning terms, to September 2026
0%5%10%15%20%25%Jan2025AprJulOctJan2026AprJulSep20.0%

Share of postings by function, January to September, with the change in points against the same months of 2025
FunctionMentions AIRemoteContractEntry level
All tracked roles14.6% -0.5 pts22.9% 9.2% +1.4 pts9.5%
Defense11.3% -1.6 pts21.3% 12.1% +2.2 pts7.3%
GRC19.8% +2.2 pts31.2% 5.6% +0.1 pts24.1%
Manage13.5% +0.6 pts18.5% 3.9% +0.6 pts3.0%
Offense23.3% +4.8 pts24.7% 9.7% +4.5 pts10.4%
Response10.8% -1.4 pts19.5% 4.5% +1.3 pts12.8%
Plan18.9% +0.6 pts18.8% 15.1% +3.1 pts7.4%
Product Security13.8% -4.2 pts22.9% 8.3% +0.8 pts5.3%
Research32.7% +11.6 pts21.9% 6.6% +0.4 pts8.6%
Educate9.8% +0.3 pts22.8% 9.9% +2.7 pts18.1%
Sales9.5% -14.2 pts32.8% 0.5% +0.1 pts2.8%

Remote and Entry level have no change shown: JobSpikr changed how it labels them partway through the comparison.

Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.

Postings by company sizeEmployees at the hiring company, January to August 2026

No change against 2025 is shown: the split swings by several points from month to month, too much for a year-on-year comparison to hold.

Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.

Month by month

2026 is trending lower than every year since 2023

Each line is one year, January to December, so the same month lines up across years. Taken together, January to September 2026 is the lowest of the four years. Eight of the nine months ran below 2025, and four ran below every year since 2023.

Point at the chart, or focus it and use the arrow keys, to read any month.

Core postings by month, 2026 against 2025
Month2026 (2025)
January27,784 (35,459)
February27,069 (38,465)
March23,717 (35,980)
April22,619 (35,935)
May25,793 (34,964)
June29,929 (30,570)
July22,480 (38,744)
August28,766 (42,647)
September27,951 (27,582)
The calendar

August and January carry the most postings

Averaged over 2023 to 2025, August ran 22% above an average month and December 26% below it.

A search that is ready before the busiest months meets the most new postings.

Seasonal index of postings, average month = 100
MonthIndex
January115
February109
March102
April88
May99
June92
July108
August122
September92
October110
November91
December74
The mix is shifting

GRC gained 5.4 points of share since 2023

Defense gave up 5.6. Every share compares January to September of each year, so a seasonal swing cannot pass for a shift.

Demand is shifting as well as shrinking: the function mix a professional chooses from is not the one of three years ago.

Share of core postings by function, January to September of 2023 and 2026
Function2023 to 2026
GRC9.4% to 14.8% (+5.4 pts)
Sales1.0% to 2.3% (+1.3 pts)
Research1.3% to 2.3% (+1.0 pts)
Manage9.2% to 9.8% (+0.6 pts)
Offense4.7% to 4.6% (-0.1 pts)
Plan7.6% to 7.3% (-0.3 pts)
Educate1.4% to 1.1% (-0.3 pts)
Response4.1% to 3.6% (-0.5 pts)
Product Security14.3% to 12.8% (-1.5 pts)
Defense47.1% to 41.5% (-5.6 pts)
Last quarter

Cyber Risk Analyst led the gains, +20.2%

Q3 2026 against Q2 2026, for roles with at least 300 postings in Q2 2026. The steepest decline was Cybersecurity Director, -38.9%.

Cryptography / PKI Professional and Cybersecurity Project Manager moved on a single month, so they are marked as a spike rather than a trend.

Change in postings, Q2 2026 to Q3 2026
RoleChange
Cryptography / PKI Professional+72.3% (one-month spike)
Cyber Risk Analyst+20.2%
Chief Information Security Officer (CISO)+19.5%
Security Architect+14.0%
Application Security Engineer+9.9%
Governance Risk & Compliance Analyst+9.5%
Cybersecurity Director-38.9%
Penetration Tester-26.6%
Data Security Engineer-19.0%
Cybersecurity Project Manager-19.0% (one-month spike)
Red Teamer-12.4%
Security Analyst-11.3%
The CISO area

CISO postings in 2026 are back to 2024 levels

2,832 postings from January to September 2026 carried an Information Security Officer title, Chief and Business included, down 38.9% from 4,632 in the same months of 2025. The same months ran 3,322 in 2023 and 2,808 in 2024. 2025 was the high: 5,597 for the full year, up 44.3% on 2024.

The ten taxonomy leadership roles are read here as this one area.

CISO postings, January to September of each year
YearPostings
20233,322
20242,808
20254,632
20262,832
Inside the postings

14.6% of postings mention AI or machine learning terms

About level with 15.1% in the same months of 2025, but rising through the year. September's 20.0% was the highest of any month since January 2025. Terms searched: "artificial intelligence", "machine learning", "generative AI", "GenAI", "large language model" and "LLM".

JobSpikr infers 9.5% as entry level; 22.9% are flagged remote; 9.2% of postings with a recognized job type are contracts.

A contract posting can be a way to try a function first.

Share of postings, January to September 2026
MeasureShare
Mentions AI or machine learning14.6%
Flagged remote22.9%
Contract (of recognized job types)9.2%
Entry level (inferred)9.5%
Who is posting

52.6% of postings came from companies with 1,000 or fewer employees

Of postings with a known company size (87% of January to August 2026), 39.9% came from companies with 200 or fewer employees, 12.7% from 201 to 1,000 and 47.3% from more than 1,000.

Educate leans furthest toward smaller employers, 44.0% at 200 or fewer employees; Research toward the largest, 57.5% at more than 1,000 employees.

A search that watches only the largest employers sees 47% of postings. Size is the hiring company's as JobSpikr matches it, so a staffing firm posting for a client counts at the firm's size. September is left out: JobSpikr matches postings to companies after they appear, and only 61% had been matched when the data was pulled.

Share of postings by company size, January to August 2026: 1 to 200 employees, 201 to 1,000, 1,001 or more
Function1 to 200 employees / 201 to 1,000 / 1,001 or more
All tracked roles39.9% / 12.7% / 47.3%
Defense41.2% / 12.6% / 46.2%
GRC42.0% / 13.9% / 44.1%
Manage37.3% / 11.9% / 50.8%
Offense36.9% / 19.5% / 43.6%
Response40.7% / 10.3% / 49.0%
Plan37.9% / 11.5% / 50.6%
Product Security37.9% / 12.7% / 49.4%
Research35.6% / 6.9% / 57.5%
Educate44.0% / 13.1% / 42.9%
Sales39.0% / 10.2% / 50.8%
Explore the data

Find your role in the postings

Search by the title you hold or the one you want, or pick a function. Each role shows its postings month by month and how it moved last quarter, with links to its open roles on CyberSN and its guide in the Career Center. Add up to three roles to compare them.

Pick a role

Search by title or pick a role in the table to see its postings month by month, how it moved last quarter, and where to find its open roles on CyberSN. The + beside a role compares it with the one on this card.

Start with

Postings January to September 2026, against the same months of 2025

Postings by role, January to September 2026, with the change against the same months of 2025 and against Q2 2026. Select a role to show its details.
TrendCompare
Security EngineerDefense44,083-32.3%+7.9%
DevSecOpsProduct Security24,317-27.4%-2.8%
Cybersecurity / Privacy AttorneyGRC24,193+9.1%+3.1%
Security AnalystDefense24,095-30.5%-11.3%
Site Resiliency EngineerProduct Security · within DevSecOps18,657-33.5%n/a
Security ArchitectPlan14,967-25.1%+14.0%
Cybersecurity ManagerManage12,219-24.4%+2.2%
Identity & Access Management EngineerDefense9,105-14.7%-8.2%
Cybersecurity Sales EngineerSales5,397-7.1%-3.8%
Application Security EngineerOffense5,155-24.9%+9.9%
Cybersecurity SpecialistDefense4,709-29.7%-6.7%
Governance Risk & Compliance AnalystGRC4,697-26.6%+9.5%
Cybersecurity LeadManage4,688-41.0%-8.1%
Incident ResponderResponse4,197-33.1%-7.2%
SOC AnalystDefense · within Security Analyst4,161-5.1%n/a
Cyber Risk AnalystGRC4,031-51.5%+20.2%
Cloud Security EngineerDefense3,980-34.5%+8.9%
Cyber Threat Intelligence AnalystDefense3,821-31.7%-1.1%
Product Security EngineerProduct Security3,469-22.3%-2.3%
Cybersecurity DirectorManage3,284-32.5%-38.9%
Penetration TesterOffense3,063-45.9%-26.6%
Chief Information Security Officer (CISO)Manage2,832-38.9%+19.5%
Red TeamerOffense2,726-30.5%-12.4%
Cryptography / PKI ProfessionalResearch2,497+22.8%+72.3%spike
Cybersecurity Software EngineerProduct Security2,461-36.4%-6.7%
Cybersecurity AdministratorDefense2,446-22.7%-10.9%
AI Security EngineerDefense · within Security Engineer2,409+268.3%n/a
Cybersecurity Technical WriterEducate2,141-34.0%-2.5%
Data Security EngineerDefense2,080-18.9%-19.0%
Digital ForensicResponse1,635-10.4%-7.0%
Reverse Engineer / Malware AnalystResponse1,605-28.9%+7.2%
Cyber Data ScientistResearch1,493+203.5%n/a
Privacy AnalystGRC1,438-35.3%-1.6%
Data Loss Prevention EngineerDefense1,312+7.2%-10.1%
Cyber Insider Threat AnalystDefense1,088-55.6%-6.2%
Vulnerability / Threat Management AnalystDefense1,033+0.2%-2.3%
Threat HunterResponse1,013-40.0%+1.5%
Cybersecurity Program ManagerPlan875-22.4%n/a
Cybersecurity Project ManagerPlan783-39.4%-19.0%spike
Security Researcher (Software)Research763-18.6%n/a
Cybersecurity AdvisorPlan588-37.2%n/a
Security Researcher (Hardware)Research584-24.2%n/a
Data Privacy OfficerGRC466-16.0%n/a
Security Awareness SpecialistEducate457-38.8%n/a
Career guide

A guide to each function

What the work is in each function, the titles that carry it, and where to read each role in depth in the Career Center.

41.5% of postings · 11 tracked roles

Defense

Defense is the day-to-day work of securing enterprise environments: engineering and operating controls, watching for what gets through, and protecting data and identities. It has the most roles of any function, which is why it also has the most postings.

Two roles dominate the function and they are the widest doors into the field. Read the postings, not the titles: an engineer posting that leads with detection tooling is analyst-adjacent work, and an analyst posting that asks for automation is engineering in disguise.

Titles that carry this work: Security Engineer, Security Analyst, Cloud Security Engineer, Identity & Access Management Engineer, Threat Intelligence Analyst

14.8% of postings · 5 tracked roles

GRC

GRC governs cyber risk, regulatory obligations and privacy across the organization. Disclosure rules, privacy law and board scrutiny keep it steady, and it is the function where legal and security careers meet.

If your background is audit, law or policy, this is the function where that experience transfers directly. The attorney series is large because privacy and cyber counsel are posted under generic legal titles; the taxonomy finds them by what the posting asks for.

Titles that carry this work: Governance Risk & Compliance Analyst, Cyber Risk Analyst, Cybersecurity / Privacy Attorney, Privacy Analyst, Data Privacy Officer

9.8% of postings · 4 tracked roles

Manage

Manage covers leading security teams and owning strategy, budget and outcomes at every level. Its postings are fewer than the technical functions and each one represents a team.

Leadership postings reward evidence of accountability: programs delivered, budgets owned, risk reported upward. Watch the lead and manager series for the first rung; director and CISO postings move with how boards are treating cyber accountability.

Titles that carry this work: Cybersecurity Manager, Cybersecurity Director, Cybersecurity Lead, Chief Information Security Officer

4.6% of postings · 3 tracked roles

Offense

Offense tests defenses by finding and exploiting weaknesses before an adversary does, from application code to full adversary simulation.

Application security is the largest offense series by a distance and the most common way in, because it sits next to software teams. Penetration testing and red team postings are smaller and more specialized; certifications and public work matter more here than in most functions.

Titles that carry this work: Penetration Tester, Application Security Engineer, Red Teamer

3.6% of postings · 4 tracked roles

Response

Response investigates and contains security incidents and works out how attacks unfolded. It is a smaller function by postings and a deep one by skill.

Incident response is the entry point and the volume leader; forensics, reversing and hunting are the specializations that follow. Many of these roles are also filled from inside Defense teams, so the postings understate the paths in.

Titles that carry this work: Incident Responder, Digital Forensic, Reverse Engineer / Malware Analyst, Threat Hunter

7.3% of postings · 4 tracked roles

Plan

Plan designs security programs and architectures and runs the projects that deliver them. Architecture carries the function; program and project management are where delivery experience from other fields transfers into cybersecurity.

Architect postings expect years of engineering behind them. Program and project roles are the practical entry for people with delivery backgrounds, and advisor postings tend to come from consultancies and service providers.

Titles that carry this work: Security Architect, Cybersecurity Program Manager, Cybersecurity Project Manager, Cybersecurity Advisor

12.8% of postings · 3 tracked roles

Product Security

Product Security builds security into software and products from design through release. Its largest series, DevSecOps, sits at the boundary between engineering platforms and security, and the function carries more postings per role than any other.

Software engineers move into this function more easily than into any other. A DevSecOps or product security posting usually reads as an engineering job with a security mandate, so the pipeline, cloud and code skills you already have are the qualification.

Titles that carry this work: DevSecOps, Product Security Engineer, Cybersecurity Software Engineer, Site Resiliency Engineer

2.3% of postings · 4 tracked roles

Research

Research advances security knowledge through vulnerability research, cryptography and data science. It is the smallest technical function by postings and the most credential-sensitive.

Volume is low and the bar is high. Data science postings with a security mandate are the most accessible of the three; cryptography and PKI work rewards depth, and researcher postings cluster around vendors and large platforms.

Titles that carry this work: Security Researcher, Cryptography / PKI Professional, Cyber Data Scientist

1.1% of postings · 2 tracked roles

Educate

Educate teaches, trains and documents cybersecurity knowledge for teams and for the wider field. The postings are few, and many awareness and training roles are absorbed into broader positions.

Technical writing is the larger of the two tracked series and a route in for strong writers with a technical bent. Awareness roles are often part of a GRC or people team, so look at those postings too.

Titles that carry this work: Security Awareness Specialist, Cybersecurity Technical Writer, Cybersecurity Professor / Instructor

2.3% of postings · 1 tracked role

Sales

Sales connects organizations with the security products, services and coverage they need. Sales engineering is the tracked series: technical sellers who can demonstrate and design as well as close.

Sales engineering postings reward hands-on product depth over account management. For practitioners who like explaining and building, it is a well paid lateral move that keeps the technical work.

Titles that carry this work: Cybersecurity Sales Engineer, Cyber Sales Professional, Cyber Insurance Professional

Using the data

What to do with this

Search by the work, not the title

The titles employers use for the same work vary more than the work does. Take the taxonomy role that fits what you do, then use its aliases on the Career Center page as your search terms.

Read momentum, not spikes

A role that moved twenty percent in a quarter is a signal. A single month that doubled is usually a large employer's batch posting or an indexing artifact. This report flags those and keeps them out of the totals.

Use volume to plan, not to choose

High volume means more open doors, not better ones. Smaller functions such as Response and Research post less and compete harder for the postings they do have. Volume tells you how many chances you get; depth decides which ones you win.

Check the role page before you apply

Every role here links to a Career Center page with the responsibilities, common tools, certifications and the career path in and out of that work.

Plan around the calendar

Postings follow a seasonal pattern. Averaged over the last three full years, August and January carried the most new postings of any months and December the fewest; the seasonal chart in this report shows the whole year.

Workforce Intelligence

For leaders

External posting data shows you the weather. Workforce Intelligence shows you your own ground. The demand picture in this report is the market's; what it cannot tell you is whether the capabilities your strategy depends on are covered inside your own workforce ecosystem today. CyberSN reads both together: Workforce Intelligence to visualize capability coverage and workforce risk against your priorities, and Talent Solutions to act on the needs that visibility surfaces, matching people to capability rather than to a job title.

Sources

Method and notes

  1. Postings are aggregated from JobSpikr, restricted to the United States and to the job board and Fortune 500 datasets, with duplicate listings excluded at the source. Each series is a title query; three of them also filter on the job description or department to keep generic titles such as Counsel within cyber and privacy work.
  2. The CyberSN platform taxonomy defines 45 cybersecurity functional roles in ten categories (production export of September 17, 2026). Its ten leadership roles divide leadership by function, which job titles do not name, so this report reads them as one CISO functional area, counted with the query the CyberSN platform uses for that leadership work: postings with an Information Security Officer title, including Chief and Business Information Security Officer. That gives 36 areas, 33 of them with a series. Cybersecurity Director, Cybersecurity Lead and Cybersecurity Manager are tracked alongside it as leadership levels. Six more series (Cryptography / PKI Professional, Cybersecurity Administrator, Cybersecurity Specialist, Data Security Engineer, Reverse Engineer / Malware Analyst and Cybersecurity Technical Writer) are Career Center roles with no single platform counterpart: they count in totals but stand for no functional area.
  3. A month is complete when it is fully indexed; the trailing month is treated as partial. Totals, shares, year-over-year and momentum use complete months only.
  4. Year-over-year compares the current-year window with the same months of the prior year. Momentum compares the last complete quarter with the quarter before it and lists only roles with at least the stated floor of postings in the prior quarter. A mover whose change rests on one month (a month above twice its trailing median that carries at least half the change) is marked as a one-month spike.
  5. Postings per role divide a function's postings by the number of roles tracked in it, so functions of different breadth can be compared. The forecast applies each prior full year's share of postings after the data cutoff to this year's postings to date and reports the range.
  6. Anomalies: a month more than five times a series' trailing six-month median (with that median at least twenty) is shown on the trend at its raw value but replaced by the median inside every total and percentage. Any such month is listed below.
  7. Three series (AI Security Engineer, Site Resiliency Engineer and SOC Analyst) are title subsets of broader queries and are shown within their function for orientation without being added to totals, so each posting is counted once.
  8. Threat Hunter is counted under Response, following the taxonomy. Prior CyberSN reports grouped it under Defense, and prior figures were produced with an earlier method, so this edition's numbers supersede rather than extend them.
  9. Inside the postings: each cut adds one condition to the same role queries. AI mentions search the job description for "artificial intelligence", "machine learning", "generative AI", "GenAI", "large language model" and "LLM"; the bare letters AI are not searched, because they also match statements about AI in the application process. "LLM" can also name the Master of Laws degree that some Legal postings ask for, so that function's AI share may run slightly high. Remote uses JobSpikr's remote flag. Contract and entry level use the job type and the seniority JobSpikr infers from each posting, and their shares are of postings that carry a recognized value (73% and 100% of postings in the current window). A share built on fewer than 200 postings is not shown, and anomalous months are left out of both sides of every share.
  10. Company size uses the employee-count band JobSpikr attaches to the hiring company, grouped as 1 to 200 employees, 201 to 1,000 and 1,001 or more. Shares are of postings that carry a band (87% of January to August 2026). JobSpikr matches postings to companies after they appear, so a latest month with under four-fifths of the median month's matched share is left out: September 2026 (61% matched, against 85% for the median month). Size is the company JobSpikr matches to the posting, so a staffing firm posting for a client counts at the firm's size. The split swings by several points from one month to the next (a few large posters can move it), so it is shown for the current window only and not compared with 2025.
  11. The share flagged remote went from 18.4% of postings in August 2025 to 25.4% in September 2025 and the share JobSpikr infers as entry level went from 21.3% of postings in May 2025 to 4.7% in June 2025. A step that size in a single month reads as a change in how JobSpikr labels postings rather than in what employers post, so those measures are shown for the current window only and not compared with 2025.

Anomalous months in this edition

  • Cyber Data Scientist, April 2025: 164 posted against a trailing median of 28; 28 used in totals.
  • Cyber Data Scientist, May 2026: 379 posted against a trailing median of 57; 57 used in totals.
  • Cybersecurity Advisor, June 2023: 325 posted against a trailing median of 64; 64 used in totals.

Functional roles in the taxonomy, and which have a series

45 functional roles in the CyberSN platform taxonomy (export of September 17, 2026), 36 areas once the leadership roles are read as one, 33 with a series in this edition (3 of them charted within a broader role rather than added to totals).

CategoryTaxonomy rolesWith a seriesWithout a series
Defense1110Cyber IT Support
GRC44none
Manage10one CISO areanone
Offense33none
Response33none
Plan43Business Analyst
Product Security44none
Research43Research: Threats
Educate11none
Sales11none
Workforce Intelligence for Cyber & IT Leaders

See what your workforce can actually execute.

A 30-minute Discovery Call visualizes your top capability gaps against your strategic priorities, and shows how CyberSN matches people to capability, not to a title.

© 2026 CyberSN · All rights reservedworkforce intelligence · est. 2014