London Daily

Focus on the big picture.
Friday, Sep 19, 2025

How to get a lucrative job in cybersecurity

How to get a lucrative job in cybersecurity

One of Oscar Anaya's earliest successful hacks was in to a personal computer he shared with his older sister when he was 11 years old.

"My sister wanted to play some weird game on the computer and didn't want me to use it, so she locked it with a password," he says.

Undaunted, he began turning the machine off and on again, which led him to discover Safe Mode in Windows XP. "It allowed me to log in as the administrator of the personal computer and change the password," he says.

"My sister was baffled when she got home," he adds. "She wondered how I got in."

This early hack by Mr Anaya was just the beginning of his circuitous route into his career as an IT security, or cybersecurity, professional. His route took him from music producer to security alarm installer to an apprentice on a hacking programme.

"I've always looked at things and thought, 'How can someone abuse it?'" he says.

"That's the root of a hacker - to find how things can operate in ways they were not intended to."

As much as he wanted to work in cybersecurity, it seemed this would be an unfulfilled dream until he began actively looking for jobs in the field at the urging of his pregnant wife.

Eventually he ended up on a cybersecurity apprenticeship run by IBM in 2019. Based in Texas, he now has a full-time position with the company's X-Force Red team as a hardware hacker - hired to try to deliberately break into company systems and expose vulnerabilities.

Mr Anaya's journey is an example of one of the many diverse paths that might lead you in to a career in cybersecurity.

It's a well-paid profession. The average salary for a cybersecurity professional in Europe is around €62,000 (£54,000; $74,000), according to (ISC)², the US organisation which administers the Certified Information Systems Security Professional (CISSP) certification exam.

The sector is booming but there is still an acute shortage of cybersecurity staff

And there are still many many roles that need filling, although the workforce gap dropped from four million in 2019 to 3.1 million in 2020 according to (ISC)².

"The market is huge," says Ida Byrd-Hill, chief executive and founder of Automation Workz, a Detroit-based re-skilling and diversity consulting firm.

"With all the attacks and data breaches and data leaks, there's a lot of need for cybersecurity people," she says.

This acute demand has begun to drive hiring trends. "What recruiters are looking for is starting to shift," says Clar Rosso, chief executive of (ISC)².

"Organisations are facing the stark reality of the cybersecurity [skills] gap, so they've started thinking differently about who they're recruiting," she says.

"That starts with a mindset shift that is focused on the idea that technical skills can be taught, but there are other critical skills for cybersecurity professionals that are harder to teach," she continues. "Those are things like analytical and critical thinking, problem solving, and the ability to work well as both an individual and in a team."

Ms Rosso says a recent study found that more than half of individuals entering the cybersecurity profession now come from non-IT, or computer science, backgrounds.

A shift in approach to recruitment has been embraced by some very large companies.

"Paths into cybersecurity can vary hugely," says Wil Rockall, UK lead on cyber talent at Deloitte, a global professional services company.

"Some people have a technical education, degree courses and [training] programmes in cybersecurity, but the majority of our hires come from non-technical backgrounds," he says. "We focus on talent development. We have a path within the firm around how we can develop a person's soft skills and technical skills, as a person goes through their career."

He adds: "It's a broad industry. Security encompasses a whole number of different things so there's lots of different industries where people have transferrable skills."

Mr Rockall says the sector has changed a lot in the last two decades. "It's not about guys in hoodies tapping away on keyboards doing technical things. It's a business function so you need people with business skills."

Some common career paths from other industries in to the sector include people who have previously worked in penetration testing (ethical hacking); or as a compliance analyst; security consultant; security operations or threat intelligence analyst.

"These paths range in core competencies. From very technical roles that are a natural fit for someone with an engineering background, to roles that are more process, data and analytics oriented," explains Melanie Kruger, vice president of talent at Red Canary, a cloud-based security services provider.

"When considering which path is right for you," she says, "I would advise creating an inventory of the skills you are most energised using in your current role."

While the cybersecurity labour shortage isn't going to disappear any time soon, experts agree that broadening the candidate pool will be crucial in addressing the shortage.

"What that means now is pulling people out of adjacent disciplines and retraining them, or helping colleges improve their training so there's a better pipeline," explained Paul Farnsworth, Chief Technology Officer at the DHI Group, parent of the Dice high-tech job website.

Companies are retraining staff from other areas to go into cybersecurity says Paul Farnsworth

Jim Johnson, a senior vice president in the technology division of Robert Half, a national professional staffing firm, adds that businesses need to be more proactive in expanding their talent pool.

"Companies need to be engaged in their communities, with their local schools and networking groups and support them and help drive that audience, and help create the talent pool," he says.

"Part of that is offering internships or real world experience for students. It's going to help students ramp up much more quickly."

Heather Ricciuto, academic and talent outreach lead at IBM Security, says several years ago IBM came to the realisation that it could no longer keep looking for staff in the same old places.

IBM had to look in new places for cybersecurity staff says Heather Ricciuto

"We couldn't keep trying to hire folks with bachelors and masters degrees from top-tier universities. We recognised we had to start looking at the non-traditional talent pool," she says.

"We've been hiring people with college certificates, associate degrees, boot camp graduates, free online training, self-learning. And people who come in through apprenticeship programmes.

"There are so many unfilled cybersecurity jobs around the world, we couldn't possibly fill them all with university graduates. There just isn't enough people graduating with the right skills to fill all the open positions."

Diversity will also play an important role in expanding the pool much further and bridging the skills gap.

"Diversity is massively important," says Mr Rockall. "We're not solving a single problem that has a single answer."

"We work in dynamically evolving environment where attackers are trying to find diverse ways of disrupting our clients," he says. "So it's really important that we have a diversity of thought and a diversity of approach to think of new ways of combatting that."

Newsletter

Related Articles

0:00
0:00
Close
DeepSeek Claims R1 Model Trained for only $294,000, Sparking Global Debate Over China’s AI Capabilities
SoftBank Vision Fund to Cut Nearly Twenty Percent of Staff in Bold AI Strategy Shift
Intel’s Next-Gen Manufacturing Gets a Lifeline from Nvidia’s Strategic $5B Deal
Erika Kirk Elected CEO of Turning Point USA After Husband Charlie Kirk’s Assassination
Massive Strikes in France Pressure Macron and New PM on Austerity Proposals
Trump Seeks Supreme Court Permission to Remove Fed Governor Lisa Cook
Hillary Clinton’s Reckless Rhetoric Fuels Division After Charlie Kirk’s Assassination
NASDAQ Rises to Record as Intel Soars More Than 20%, Nvidia Gains 3%
Nvidia’s $5 Billion Bet on Intel Reshapes AI Hardware Landscape
Trump and Starmer Clash Over UK Recognition of Palestinian State Amid State Visit
Trump’s Quip on Biden and Google Lawsuit Revives Debate Over Antitrust Legacy
Macron and his wife to provide 'scientific photographic evidence' that she is a real woman
US Tech Giants Pledge Billions to UK AI Infrastructure Following Starmer's Call
Saudi Arabia cracks down on music ‘lounges’ after conservative backlash
DeepMind and OpenAI Achieve Gold at ‘Coding Olympics’ in AI Milestone
SEC Allows Public Companies to Block Investors from Class-Action Lawsuits
Saudi Arabia Signs ‘Strategic Mutual Defence’ Pact with Pakistan, Marking First Arab State to Gain Indirect Access to Nuclear Strike Capabilities in the Region
Federal Reserve Cuts Rates by Quarter Point and Signals More to Come
Effective and Impressive Generation Z Protest: Images from the Riots in Nepal
European manufacturers against ban on polluting cars: "The industry may collapse"
Sam Altman sells the 'Wedding Estate' in Hawaii for 49 million dollars
Trump: Cancel quarterly company reports and settle for reporting once every six months
Turkish car manufacturer Togg Enters German Market with 5-Star Electric Sedan and SUV to Challenge European EV Brands
US Launches New Pilot Program to Accelerate eVTOL Air Taxi Deployment
Christian Brueckner Released from German Prison after Serving Unrelated Sentence
World’s Longest Direct Flight China Eastern to Launch 29-Hour Shanghai–Buenos Aires Direct Flight via Auckland in December
New OpenAI Study Finds Majority of ChatGPT Use Is Personal, Not Professional
Hong Kong Industry Group Calls for HK$20 Billion Support Fund to Ease Property Market Stress
Joe Biden’s Post-Presidency Speaking Fees Face Weak Demand amid Corporate Reluctance
Charlie Kirk's murder will break the left's hateful cancel tactics
Kash Patel erupts at ‘buffoon’ Sen. Adam Schiff over Russiagate: ‘You are the biggest fraud’
Homeland Security says Emmy speech ‘fanning the flames of hatred’ after Einbinder’s ‘F— ICE’ remark
Charlie Kirk’s Alleged Assassin Tyler Robinson Faces Death Penalty as Charges Formally Announced
Actor, director, environmentalist Robert Redford dies at 89
The conservative right spreads westward: a huge achievement for 'Alternative for Germany' in local elections
JD Vance Says There Is “No Unity” with Those Who Celebrate Charlie Kirk’s Killing, and he is right!
Trump sues the 'New York Times' for an astronomical sum of 15 billion dollars
Florida Hospital Welcomes Its Largest-Ever Baby: Annan, Nearly Fourteen Pounds at Birth
U.S. and Britain Poised to Finalize Over $10 Billion in High-Tech, Nuclear and Defense Deals During Trump State Visit
China Finds Nvidia Violated Antitrust Laws in Mellanox Deal, Deepens Trade Tensions with US
US Air Force Begins Modifications on Qatar-Donated Jet Amid Plans to Use It as Air Force One
Pope Leo Warns of Societal Crisis Over Mega-CEO Pay, Citing Tesla’s Proposed Trillion-Dollar Package
Poland Green-Lights NATO Deployment in Response to Major Russian Drone Incursion
Elon Musk Retakes Lead as World’s Richest After Brief Ellison Surge
U.S. and China Agree on Framework to Shift TikTok to American Ownership
London Daily Podcast: London Massive Pro Democracy Rally, Musk Support, UK Economic Data and Premier League Results Mark Eventful Weekend
This Week in AI: Meta’s Superintelligence Push, xAI’s Ten Billion-Dollar Raise, Genesis AI’s Robotics Ambitions, Microsoft Restructuring, Amazon’s Million-Robot Milestone, and Google’s AlphaGenome Update
Le Pen Tightens the Pressure on Macron as France Edges Toward Political Breakdown
Musk calls for new UK government at huge pro-democracy rally in London, but Britons have been brainwashed to obey instead of fighting for their human rights
Elon Musk responds to post calling for the murder of Erika Kirk, widow of Charlie Kirk: 'Either we fight back or they will kill us'
×