Pick a role
Search by title or pick a role in the table to see its postings month by month, how it moved last quarter, and where to find its open roles on CyberSN. The + beside a role compares it with the one on this card.
Down 26.4% from 320,210 in the same months of 2025.
Job titles are noisy. This report reads every posting through the CyberSN Taxonomy, so demand is counted by the work being asked for, not by the title on the listing.
Data pulled October 7, 2026. Each dot is 200 postings.
Every number here counts job postings: what employers asked for, not jobs or people. United States only, with duplicate listings removed at the source. One dot is 200 postings.
The CyberSN taxonomy defines 45 cybersecurity functional roles. Reading the ten leadership roles as one CISO area gives 36 areas, 33 of which have a posting series here.
273,498 in 2023, 244,911 in 2024, 320,210 in 2025 and 235,786 in 2026.
Eight of the nine months ran below the same month of 2025.
| Year | Postings |
|---|---|
| 2023 | 273,498 |
| 2024 | 244,911 |
| 2025 | 320,210 |
| 2026 | 235,786 |
Full years: 353,368 in 2023, 338,138 in 2024 and 392,356 in 2025.
Applying each prior year's share of postings after September to 2026 projects 288,918 to 325,536 for the full year. It is a seasonal pace estimate, not a prediction of any event.
| Year | Postings |
|---|---|
| 2023 | 353,368 |
| 2024 | 338,138 |
| 2025 | 392,356 |
| 2026 (projected) | 288,918 to 325,536 |
It is also the broadest function, with eleven tracked roles, so its volume is partly a measure of breadth. Each disc is one function, sized by its postings from January to September 2026.
| Function | Share |
|---|---|
| Defense | 41.5% |
| GRC | 14.8% |
| Product Security | 12.8% |
| Manage | 9.8% |
| Plan | 7.3% |
| Offense | 4.6% |
| Response | 3.6% |
| Sales | 2.3% |
| Research | 2.3% |
| Educate | 1.1% |
10,082 postings per tracked role across three roles, against 8,887 in Defense and 6,965 in GRC. DevSecOps alone carries 24,317.
Each disc is now one role. A function with fewer, larger discs has employers competing for the same work.
| Function | Per role |
|---|---|
| Product Security | 10,082 |
| Defense | 8,887 |
| GRC | 6,965 |
| Manage | 5,756 |
| Sales | 5,397 |
| Plan | 4,303 |
| Offense | 3,648 |
| Response | 2,112 |
| Research | 1,334 |
| Educate | 1,299 |
Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.
Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.
Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.
Q2 2026 to Q3 2026, roles with at least 300 postings in Q2 2026.
Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.
Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.
| Function | Mentions AI | Remote | Contract | Entry level |
|---|---|---|---|---|
| All tracked roles | 14.6% -0.5 pts | 22.9% | 9.2% +1.4 pts | 9.5% |
| Defense | 11.3% -1.6 pts | 21.3% | 12.1% +2.2 pts | 7.3% |
| GRC | 19.8% +2.2 pts | 31.2% | 5.6% +0.1 pts | 24.1% |
| Manage | 13.5% +0.6 pts | 18.5% | 3.9% +0.6 pts | 3.0% |
| Offense | 23.3% +4.8 pts | 24.7% | 9.7% +4.5 pts | 10.4% |
| Response | 10.8% -1.4 pts | 19.5% | 4.5% +1.3 pts | 12.8% |
| Plan | 18.9% +0.6 pts | 18.8% | 15.1% +3.1 pts | 7.4% |
| Product Security | 13.8% -4.2 pts | 22.9% | 8.3% +0.8 pts | 5.3% |
| Research | 32.7% +11.6 pts | 21.9% | 6.6% +0.4 pts | 8.6% |
| Educate | 9.8% +0.3 pts | 22.8% | 9.9% +2.7 pts | 18.1% |
| Sales | 9.5% -14.2 pts | 32.8% | 0.5% +0.1 pts | 2.8% |
Remote and Entry level have no change shown: JobSpikr changed how it labels them partway through the comparison.
Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.
No change against 2025 is shown: the split swings by several points from month to month, too much for a year-on-year comparison to hold.
Source: JobSpikr job postings, United States, deduplicated, aggregated monthly by CyberSN against the CyberSN Taxonomy. Complete months through September 2026.
Each line is one year, January to December, so the same month lines up across years. Taken together, January to September 2026 is the lowest of the four years. Eight of the nine months ran below 2025, and four ran below every year since 2023.
Point at the chart, or focus it and use the arrow keys, to read any month.
| Month | 2026 (2025) |
|---|---|
| January | 27,784 (35,459) |
| February | 27,069 (38,465) |
| March | 23,717 (35,980) |
| April | 22,619 (35,935) |
| May | 25,793 (34,964) |
| June | 29,929 (30,570) |
| July | 22,480 (38,744) |
| August | 28,766 (42,647) |
| September | 27,951 (27,582) |
Averaged over 2023 to 2025, August ran 22% above an average month and December 26% below it.
A search that is ready before the busiest months meets the most new postings.
| Month | Index |
|---|---|
| January | 115 |
| February | 109 |
| March | 102 |
| April | 88 |
| May | 99 |
| June | 92 |
| July | 108 |
| August | 122 |
| September | 92 |
| October | 110 |
| November | 91 |
| December | 74 |
Defense gave up 5.6. Every share compares January to September of each year, so a seasonal swing cannot pass for a shift.
Demand is shifting as well as shrinking: the function mix a professional chooses from is not the one of three years ago.
| Function | 2023 to 2026 |
|---|---|
| GRC | 9.4% to 14.8% (+5.4 pts) |
| Sales | 1.0% to 2.3% (+1.3 pts) |
| Research | 1.3% to 2.3% (+1.0 pts) |
| Manage | 9.2% to 9.8% (+0.6 pts) |
| Offense | 4.7% to 4.6% (-0.1 pts) |
| Plan | 7.6% to 7.3% (-0.3 pts) |
| Educate | 1.4% to 1.1% (-0.3 pts) |
| Response | 4.1% to 3.6% (-0.5 pts) |
| Product Security | 14.3% to 12.8% (-1.5 pts) |
| Defense | 47.1% to 41.5% (-5.6 pts) |
Q3 2026 against Q2 2026, for roles with at least 300 postings in Q2 2026. The steepest decline was Cybersecurity Director, -38.9%.
Cryptography / PKI Professional and Cybersecurity Project Manager moved on a single month, so they are marked as a spike rather than a trend.
| Role | Change |
|---|---|
| Cryptography / PKI Professional | +72.3% (one-month spike) |
| Cyber Risk Analyst | +20.2% |
| Chief Information Security Officer (CISO) | +19.5% |
| Security Architect | +14.0% |
| Application Security Engineer | +9.9% |
| Governance Risk & Compliance Analyst | +9.5% |
| Cybersecurity Director | -38.9% |
| Penetration Tester | -26.6% |
| Data Security Engineer | -19.0% |
| Cybersecurity Project Manager | -19.0% (one-month spike) |
| Red Teamer | -12.4% |
| Security Analyst | -11.3% |
2,832 postings from January to September 2026 carried an Information Security Officer title, Chief and Business included, down 38.9% from 4,632 in the same months of 2025. The same months ran 3,322 in 2023 and 2,808 in 2024. 2025 was the high: 5,597 for the full year, up 44.3% on 2024.
The ten taxonomy leadership roles are read here as this one area.
| Year | Postings |
|---|---|
| 2023 | 3,322 |
| 2024 | 2,808 |
| 2025 | 4,632 |
| 2026 | 2,832 |
About level with 15.1% in the same months of 2025, but rising through the year. September's 20.0% was the highest of any month since January 2025. Terms searched: "artificial intelligence", "machine learning", "generative AI", "GenAI", "large language model" and "LLM".
JobSpikr infers 9.5% as entry level; 22.9% are flagged remote; 9.2% of postings with a recognized job type are contracts.
A contract posting can be a way to try a function first.
| Measure | Share |
|---|---|
| Mentions AI or machine learning | 14.6% |
| Flagged remote | 22.9% |
| Contract (of recognized job types) | 9.2% |
| Entry level (inferred) | 9.5% |
Of postings with a known company size (87% of January to August 2026), 39.9% came from companies with 200 or fewer employees, 12.7% from 201 to 1,000 and 47.3% from more than 1,000.
Educate leans furthest toward smaller employers, 44.0% at 200 or fewer employees; Research toward the largest, 57.5% at more than 1,000 employees.
A search that watches only the largest employers sees 47% of postings. Size is the hiring company's as JobSpikr matches it, so a staffing firm posting for a client counts at the firm's size. September is left out: JobSpikr matches postings to companies after they appear, and only 61% had been matched when the data was pulled.
| Function | 1 to 200 employees / 201 to 1,000 / 1,001 or more |
|---|---|
| All tracked roles | 39.9% / 12.7% / 47.3% |
| Defense | 41.2% / 12.6% / 46.2% |
| GRC | 42.0% / 13.9% / 44.1% |
| Manage | 37.3% / 11.9% / 50.8% |
| Offense | 36.9% / 19.5% / 43.6% |
| Response | 40.7% / 10.3% / 49.0% |
| Plan | 37.9% / 11.5% / 50.6% |
| Product Security | 37.9% / 12.7% / 49.4% |
| Research | 35.6% / 6.9% / 57.5% |
| Educate | 44.0% / 13.1% / 42.9% |
| Sales | 39.0% / 10.2% / 50.8% |
Search by the title you hold or the one you want, or pick a function. Each role shows its postings month by month and how it moved last quarter, with links to its open roles on CyberSN and its guide in the Career Center. Add up to three roles to compare them.
Search by title or pick a role in the table to see its postings month by month, how it moved last quarter, and where to find its open roles on CyberSN. The + beside a role compares it with the one on this card.
Postings January to September 2026, against the same months of 2025
What the work is in each function, the titles that carry it, and where to read each role in depth in the Career Center.
Defense is the day-to-day work of securing enterprise environments: engineering and operating controls, watching for what gets through, and protecting data and identities. It has the most roles of any function, which is why it also has the most postings.
Two roles dominate the function and they are the widest doors into the field. Read the postings, not the titles: an engineer posting that leads with detection tooling is analyst-adjacent work, and an analyst posting that asks for automation is engineering in disguise.
Titles that carry this work: Security Engineer, Security Analyst, Cloud Security Engineer, Identity & Access Management Engineer, Threat Intelligence Analyst
GRC governs cyber risk, regulatory obligations and privacy across the organization. Disclosure rules, privacy law and board scrutiny keep it steady, and it is the function where legal and security careers meet.
If your background is audit, law or policy, this is the function where that experience transfers directly. The attorney series is large because privacy and cyber counsel are posted under generic legal titles; the taxonomy finds them by what the posting asks for.
Titles that carry this work: Governance Risk & Compliance Analyst, Cyber Risk Analyst, Cybersecurity / Privacy Attorney, Privacy Analyst, Data Privacy Officer
Manage covers leading security teams and owning strategy, budget and outcomes at every level. Its postings are fewer than the technical functions and each one represents a team.
Leadership postings reward evidence of accountability: programs delivered, budgets owned, risk reported upward. Watch the lead and manager series for the first rung; director and CISO postings move with how boards are treating cyber accountability.
Titles that carry this work: Cybersecurity Manager, Cybersecurity Director, Cybersecurity Lead, Chief Information Security Officer
Offense tests defenses by finding and exploiting weaknesses before an adversary does, from application code to full adversary simulation.
Application security is the largest offense series by a distance and the most common way in, because it sits next to software teams. Penetration testing and red team postings are smaller and more specialized; certifications and public work matter more here than in most functions.
Titles that carry this work: Penetration Tester, Application Security Engineer, Red Teamer
Response investigates and contains security incidents and works out how attacks unfolded. It is a smaller function by postings and a deep one by skill.
Incident response is the entry point and the volume leader; forensics, reversing and hunting are the specializations that follow. Many of these roles are also filled from inside Defense teams, so the postings understate the paths in.
Titles that carry this work: Incident Responder, Digital Forensic, Reverse Engineer / Malware Analyst, Threat Hunter
Plan designs security programs and architectures and runs the projects that deliver them. Architecture carries the function; program and project management are where delivery experience from other fields transfers into cybersecurity.
Architect postings expect years of engineering behind them. Program and project roles are the practical entry for people with delivery backgrounds, and advisor postings tend to come from consultancies and service providers.
Titles that carry this work: Security Architect, Cybersecurity Program Manager, Cybersecurity Project Manager, Cybersecurity Advisor
Product Security builds security into software and products from design through release. Its largest series, DevSecOps, sits at the boundary between engineering platforms and security, and the function carries more postings per role than any other.
Software engineers move into this function more easily than into any other. A DevSecOps or product security posting usually reads as an engineering job with a security mandate, so the pipeline, cloud and code skills you already have are the qualification.
Titles that carry this work: DevSecOps, Product Security Engineer, Cybersecurity Software Engineer, Site Resiliency Engineer
Research advances security knowledge through vulnerability research, cryptography and data science. It is the smallest technical function by postings and the most credential-sensitive.
Volume is low and the bar is high. Data science postings with a security mandate are the most accessible of the three; cryptography and PKI work rewards depth, and researcher postings cluster around vendors and large platforms.
Titles that carry this work: Security Researcher, Cryptography / PKI Professional, Cyber Data Scientist
Educate teaches, trains and documents cybersecurity knowledge for teams and for the wider field. The postings are few, and many awareness and training roles are absorbed into broader positions.
Technical writing is the larger of the two tracked series and a route in for strong writers with a technical bent. Awareness roles are often part of a GRC or people team, so look at those postings too.
Titles that carry this work: Security Awareness Specialist, Cybersecurity Technical Writer, Cybersecurity Professor / Instructor
Sales connects organizations with the security products, services and coverage they need. Sales engineering is the tracked series: technical sellers who can demonstrate and design as well as close.
Sales engineering postings reward hands-on product depth over account management. For practitioners who like explaining and building, it is a well paid lateral move that keeps the technical work.
Titles that carry this work: Cybersecurity Sales Engineer, Cyber Sales Professional, Cyber Insurance Professional
The titles employers use for the same work vary more than the work does. Take the taxonomy role that fits what you do, then use its aliases on the Career Center page as your search terms.
A role that moved twenty percent in a quarter is a signal. A single month that doubled is usually a large employer's batch posting or an indexing artifact. This report flags those and keeps them out of the totals.
High volume means more open doors, not better ones. Smaller functions such as Response and Research post less and compete harder for the postings they do have. Volume tells you how many chances you get; depth decides which ones you win.
Every role here links to a Career Center page with the responsibilities, common tools, certifications and the career path in and out of that work.
Postings follow a seasonal pattern. Averaged over the last three full years, August and January carried the most new postings of any months and December the fewest; the seasonal chart in this report shows the whole year.
External posting data shows you the weather. Workforce Intelligence shows you your own ground. The demand picture in this report is the market's; what it cannot tell you is whether the capabilities your strategy depends on are covered inside your own workforce ecosystem today. CyberSN reads both together: Workforce Intelligence to visualize capability coverage and workforce risk against your priorities, and Talent Solutions to act on the needs that visibility surfaces, matching people to capability rather than to a job title.
45 functional roles in the CyberSN platform taxonomy (export of September 17, 2026), 36 areas once the leadership roles are read as one, 33 with a series in this edition (3 of them charted within a broader role rather than added to totals).
| Category | Taxonomy roles | With a series | Without a series |
|---|---|---|---|
| Defense | 11 | 10 | Cyber IT Support |
| GRC | 4 | 4 | none |
| Manage | 10 | one CISO area | none |
| Offense | 3 | 3 | none |
| Response | 3 | 3 | none |
| Plan | 4 | 3 | Business Analyst |
| Product Security | 4 | 4 | none |
| Research | 4 | 3 | Research: Threats |
| Educate | 1 | 1 | none |
| Sales | 1 | 1 | none |
A 30-minute Discovery Call visualizes your top capability gaps against your strategic priorities, and shows how CyberSN matches people to capability, not to a title.