Horizon Softwares

Tech signal // 2026-08-05

Cybersecurity Workforce Planning Beyond Job Counts

Effective cybersecurity workforce planning starts with business risk, required work, and labor-market evidence—not a single headcount target.

U.S. cybersecurity workforce planning dashboard with role maps, hiring data, and capability gaps

Why cybersecurity workforce planning needs more than a hiring target

For U.S. employers, cybersecurity workforce planning is often reduced to a simple question: how many people do we need? That is too narrow for a market where titles vary widely, responsibilities overlap, and demand signals come from different measurement systems. A more durable plan ties staffing decisions to business risk, security operations, product architecture, compliance obligations, and the work that must actually be performed.

That is also where cybersecurity recruitment gets more precise. Instead of treating every opening as interchangeable, companies can distinguish between roles focused on monitoring and response, secure design, governance, or platform hardening. The result is a hiring plan built around outcomes and capabilities rather than inflated job counts or title-based assumptions.

Official labor-market data support the case for disciplined planning. The Bureau of Labor Statistics projects strong growth for information security analysts in the United States over the 2024 to 2034 decade, indicating sustained demand for core security talent. But that occupation should not be mistaken for the entire cybersecurity workforce, which is broader than a single BLS category.

SOURCE A SOURCE F SOURCE G

Use BLS for the official occupation outlook, not for a total cybersecurity headcount

The clearest official benchmark in this market is the BLS projection for information security analysts. BLS reports 182,800 workers in 2024 and projects 234,900 in 2034, a gain of 52,100 jobs, or 28.5 percent. It also projects about 16,000 openings each year on average over the decade. Those figures make information security analysts one of the faster-growing technology occupations in the current projections cycle.

For employers, that matters in two ways. First, it confirms that competition for core security talent is likely to remain elevated. Second, it provides a grounded reference point for compensation planning, recruiting timelines, and internal training investment. BLS also lists the median annual wage for information security analysts at $124,910 in May 2024 and identifies a bachelor's degree as the typical entry education.

The editorial caution is important: these BLS figures apply to the occupation of information security analysts. They are not a count of every worker performing cybersecurity work across engineering, cloud, data, infrastructure, governance, or product environments. Workforce planning should use BLS as the official outlook for a defined occupation, not as a catchall measure of the whole cybersecurity labor market.

SOURCE A SOURCE B SOURCE F

Read broader market demand carefully: postings and supply are indicators, not headcounts

When companies want a broader view of cybersecurity recruitment conditions, CyberSeek is useful—but only if its measures are labeled correctly. CyberSeek's national 2025 dashboard reports 514,359 online openings, an estimated cybersecurity-related employed workforce of 1,337,400, and a supply-to-demand ratio of 74 percent. Those figures offer a market signal that demand remains substantial relative to available talent.

That broader lens is especially helpful for employers building teams across multiple functions rather than hiring only classic analyst roles. CyberSeek also maps openings into NICE-aligned categories, showing large volumes in Oversight and Governance, Implementation and Operation, Protection and Defense, and Design and Development. For workforce planners, that reinforces the point that security work is distributed across policy, operations, engineering, and architecture.

Still, these indicators should not be blended with BLS numbers as if they measure the same thing. CyberSeek's openings are online postings, not verified unique vacancies or hires, and its workforce figure is an estimate for cybersecurity-related employment rather than an official occupational count. For practical planning, use CyberSeek to understand market pressure and talent availability, while keeping BLS separate as the official occupational projection series.

SOURCE F

Build the plan around work roles, tasks, and capabilities

A better cybersecurity workforce plan starts by defining what the organization must protect and what work is required to do it. That may include cloud configuration review, identity controls, secure software development, incident response, vendor risk oversight, data protection, or product security architecture. Once those outcomes are clear, employers can map work to specific roles and capability requirements instead of defaulting to broad titles such as security engineer or security analyst.

The NICE Workforce Framework for Cybersecurity gives employers a common language for that process. NIST describes NICE as a framework for organizing cybersecurity work and the knowledge and skills needed to perform it. Its structure covers work role categories, work roles, tasks, knowledge, skills, and abilities, along with competency areas. That is far more useful for workforce planning than relying on titles alone, because the same title can represent very different responsibilities from one employer to another.

This approach is especially valuable for Horizon Softwares' client base of software engineering, cloud, data, AI, and product teams. In those environments, cybersecurity work is often embedded in delivery teams rather than isolated in a standalone security department. Planning by task and capability makes it easier to decide what should be hired externally, developed internally, automated, or covered through cross-functional team design.

SOURCE A

What a practical U.S. cybersecurity recruitment plan looks like

For most employers, the strongest workforce plan combines business context, role clarity, and labor-market evidence. Start with the security outcomes the business must achieve, then identify the tasks and capabilities required to deliver them. Next, compare those requirements with current staff capacity, likely attrition, internal mobility, and training potential. Only after that comparison should leaders finalize external hiring targets.

This sequence improves cybersecurity recruitment because it narrows the search to the work that matters most. A company scaling a cloud platform may need different talent from a regulated enterprise strengthening governance or a product organization embedding secure development practices. The labor-market evidence then helps set expectations: BLS shows a fast-growing core occupation, while broader market indicators point to continued competition for cybersecurity-related talent.

The practical implication is straightforward. U.S. workforce planning should move beyond job counts and toward capability coverage. Employers that define the work precisely, separate official occupation data from broader market indicators, and recruit against real tasks will make better hiring decisions than those chasing generic headcount goals.

SOURCE A SOURCE B SOURCE F SOURCE G

Cybersecurity workforce planning works best when companies stop treating the market as a single headcount problem. Official BLS projections show strong growth for information security analysts, but broader planning should also account for the range of cybersecurity work across engineering, cloud, data, AI, and product teams. For Horizon Softwares and its clients, the most credible path is to define the work, map the capabilities, and let evidence guide cybersecurity recruitment.

Sources

  1. Information Security Analysts 2025-08-28
  2. Occupational projections and worker characteristics 2025-08-28
  3. Employment Projections: 2024-2034 Summary 2025-08-28
  4. Artificial intelligence, information technology, and ... 2026-07-16