The job market for IT and cybersecurity roles is much larger than the number of people trained to fill them

The U.S. Bureau of Labor Statistics tracks job openings in computer and information technology occupations, which includes cybersecurity specialists, network administrators, systems analysts, and database administrators. The actual number of open positions varies by month and region, but consistently exceeds the number of people entering the field with relevant training. This gap means employers often struggle to fill roles, which affects both hiring timelines and salary ranges.

The shortage is not uniform across all IT roles or all locations. Major tech hubs like the San Francisco Bay Area, Seattle, and Northern Virginia (near Washington, D.C.) have dense clusters of cybersecurity jobs. Rural areas and smaller cities have fewer openings overall, though the ratio of jobs to may have access to candidates may still favor job seekers. The type of role matters too: entry-level help desk positions are more plentiful than senior security architect roles, but even senior positions often go unfilled for months.

Key Takeaways

  • Computer and information technology job openings consistently outnumber the people trained to fill them, creating a persistent gap between demand and supply.
  • Cybersecurity roles specifically face acute shortages because the field requires both technical skills and security-specific training that takes time to build.
  • Job availability and salary vary significantly by geography, with major tech corridors and government centers offering more positions and higher pay.
  • Entry-level positions are more common than senior roles, but employers often struggle to fill both because they cannot find candidates with the right combination of skills and certifications.
  • The number of open positions changes seasonally and with economic conditions, so the market today may differ from the market six months from now.

Why cybersecurity has the most acute shortage

Cybersecurity is the subset of IT with the most severe talent gap. The (ISC)² Cybersecurity Workforce Study, conducted annually, consistently reports that organizations cannot find enough people with the right security credentials and experience. This is because cybersecurity roles typically require both foundational IT knowledge and specialized security training—you cannot usually move into a security role straight from a bootcamp without some hands-on IT experience first.

The barrier to entry is real. Most cybersecurity positions ask for at least two years of IT experience plus a relevant certification like Security+, CISSP, or CEH. This means the pipeline is longer than it is for general IT roles. Someone starting from zero might spend a year in help desk or network support, then another year or two building security skills before they are competitive for a mid-level security position. During that time, they are not counted as a cybersecurity worker, even though they are training to become one.

Government and defense contractors face even tighter constraints because they require security clearances, which add months to the hiring process and limit the candidate pool further. A role that might take three weeks to fill in the private sector can take six months or longer in the federal space.

How job openings are measured and what the numbers actually mean

Job openings are tracked through several sources, each with different coverage and timing. The Bureau of Labor Statistics publishes the Job Openings and Labor Turnover Survey (JOLTS) monthly, which counts positions employers are actively trying to fill. LinkedIn, Indeed, and Glassdoor publish their own job market reports based on postings on their platforms. Government agencies like the Office of Personnel Management track federal IT and cybersecurity vacancies separately.

These numbers do not all measure the same thing. A job posting on Indeed counts as one opening. If the same role is posted on LinkedIn, Glassdoor, and a company's own website, it may be counted as three or four openings depending on which source you check. Some positions are posted but not actively recruiting—they are placeholders for future hires. Others are reposted repeatedly because the employer's requirements are unrealistic or the salary is too low to attract candidates.

The most useful number for someone considering a career shift is not the total openings, but the ratio of openings to job seekers. When there are more openings than may have access to candidates, you have leverage: employers will negotiate on salary, offer training, or hire people with slightly less experience than they originally wanted. When the ratio reverses, competition increases and employers become more selective.

Regional differences in IT and cybersecurity job density

The concentration of IT and cybersecurity jobs is not evenly distributed. Northern Virginia (Arlington, Alexandria, Fairfax County) has the highest density of cybersecurity positions in the country because of the proximity to federal agencies, the Department of Defense, and defense contractors. The San Francisco Bay Area, Seattle, Austin, and Denver also have large clusters. Washington, D.C. itself has significant federal IT hiring, though the hiring process is slower and more bureaucratic than in the private sector.

If you are in a smaller city or rural area, you have fewer local options, but remote work has changed this calculation. Many cybersecurity and IT roles are now fully remote or hybrid, which means you can compete for positions based anywhere. However, remote roles often attract candidates from across the country, which increases competition. Salaries for remote positions are sometimes adjusted based on the cost of living in the candidate's location, so a remote role may pay less than the same role filled locally in a high-cost area.

State and local government IT positions are another category worth considering. These roles often have less competition than private sector positions, more stable employment, and good benefits, though salaries are typically lower than in tech companies or defense contractors.

Entry-level versus experienced-level openings

The job market looks different depending on where you are in your career. Entry-level IT positions—help desk, junior network administrator, junior systems administrator—are plentiful. These roles have high turnover because they are often stepping stones rather than long-term positions. Employers know this and hire more aggressively at the entry level.

Mid-level positions (three to seven years of experience) are where the real shortage appears. There are fewer of these roles than entry-level ones, but the shortage of people with the right experience is more acute. Someone with five years of IT experience and a Security+ certification is in high demand and can often negotiate significantly on salary and benefits.

Senior and specialized roles (architect, principal engineer, CISO) are rare and highly competitive, even in a shortage market. These positions require a combination of technical depth, business acumen, and leadership experience that takes years to develop. The number of openings is small, but so is the pool of may have access to candidates.

How economic conditions and industry trends affect job openings

The number of IT and cybersecurity openings fluctuates with the broader economy and with shifts in technology spending. During recessions, hiring slows across the board. During periods of rapid growth, companies expand their IT teams faster. The tech sector is also more volatile than many others—a single company's decision to hire or lay off thousands of people can shift the regional job market noticeably.

Specific events also drive hiring surges. Major data breaches or regulatory changes (like new privacy laws) cause organizations to invest in security, which creates temporary spikes in hiring. The shift to remote work during 2020 and 2021 created urgent demand for cloud infrastructure, network security, and identity management roles. As that transition stabilized, some of that demand normalized.

Industry trends matter too. Cloud computing, artificial intelligence, and zero-trust security are areas where employers are actively hiring. Legacy system maintenance and support roles are declining. If you are training for a role in a growing area, you will find more openings. If you are training for a role in a declining area, you may face more competition despite the overall shortage.

What the shortage means for someone entering the field

The persistent gap between job openings and may have access to candidates is good news for people entering IT and cybersecurity. It means employers are more willing to hire people with non-traditional backgrounds, bootcamp training, or certifications instead of four-year degrees. It means you can often negotiate on salary, remote work options, and training budgets. It means you do not have to wait for the perfect job to appear—you can take a stepping-stone role and move up relatively quickly.

The shortage also means that the skills you develop matter more than the specific path you take to develop them. A help desk role at a financial services company, a junior network administrator role at a hospital, and a junior security analyst role at a tech company are all viable entry points. The key is to build foundational IT knowledge, get relevant certifications, and develop the ability to troubleshoot and learn independently.

That said, the shortage does not mean every role is easy to land. Employers still screen for basic competence, and they still prefer candidates with some relevant experience or demonstrated learning. The shortage means you have more opportunities and more room to negotiate, not that standards have disappeared.

Frequently Asked Questions

How many cybersecurity jobs are open right now?

The exact number changes monthly, but cybersecurity and information security analyst roles consistently rank in the top 20 fastest-growing occupations in the U.S. The (ISC)² Cybersecurity Workforce Study reports a global shortage of over 700,000 cybersecurity professionals, though this figure includes all countries and all experience levels. In the U.S. specifically, the number of open cybersecurity positions typically exceeds the number of available candidates by a significant margin.

Do I need a degree to get an IT or cybersecurity job?

No. Many IT and cybersecurity roles can be entered with certifications, bootcamp training, and relevant experience instead of a four-year degree. Help desk and junior network administrator roles often require only a high school diploma plus relevant certifications. Cybersecurity roles typically require some IT experience first, but that experience can come from a help desk role rather than a degree program. Some employers still prefer degrees, but the shortage has made alternatives more acceptable.

Which IT and cybersecurity roles have the most job openings?

Help desk and technical support roles are the most plentiful. Network administrator, systems administrator, and junior security analyst roles are also consistently in demand. Cloud infrastructure and DevOps roles are growing rapidly. Senior and specialized roles (architect, CISO, penetration tester) have fewer openings but also fewer may have access to candidates, so competition is different but not necessarily easier.

Will the IT and cybersecurity job shortage continue?

The shortage is expected to persist for at least the next several years. The number of people entering the field through bootcamps, certifications, and degree programs is increasing, but it has not yet caught up with demand. As long as organizations continue to invest in digital infrastructure and security, the shortage is likely to remain.

Does location matter for finding an IT or cybersecurity job?

Location matters less than it did before remote work became common, but it still affects your options and salary. Major tech hubs and government centers have more openings and higher salaries. Remote roles let you compete nationally but often attract more competition. If you are in a smaller city, remote work expands your options significantly, though you may see salary adjustments based on your location.