If the role requires candidates to arrive with the experience it is supposed to create, the front door is doing the rejecting for you.
Entry-level cyber hiring has developed a small definition problem.
We call the role entry level, then ask for three to five years of experience, a senior certification, exposure to half the security stack, and evidence that the person has already handled the incident we are supposedly hiring them to learn from.
Then we look at the applicant pool and conclude that junior talent is not ready.
Some candidates are not ready. That is what entry level means: they can perform defined work with appropriate supervision while still building range and judgment. The problem is that many job descriptions do not describe that job. They describe a mid-career employee at an entry-level salary and leave the market to sort out the contradiction.
Before we blame the pipeline, we should look at the front door. We built it.
Key takeaways
- Why are so many entry-level cyber jobs hard to enter? The requirements often combine a wish list, experienced-level credentials, and responsibilities that belong to several different roles.
- Does fixing entry-level hiring mean lowering the bar? No. It means attaching a clear, high bar to the work a beginner must perform, rather than to years and titles they cannot yet have.
- Why do candidates apply when they miss the requirements? When every preference is presented as mandatory, applicants learn that the job description is fiction and apply anyway. That creates more volume and less trust.
- What should employers change? Define the first six months, separate day-one needs from learnable skills, test role-relevant evidence early, and show how the person will grow into the full scope.
Entry Level Now Means Already Experienced
The data would be funny if it were not attached to somebody's rent.
ISC2 found that 38% of hiring managers require the CISA for entry-level cybersecurity positions. Over a third want the CISSP. These are respected credentials. They are also credentials built around professional experience.
ISC2 requires five years of cumulative work experience across at least two CISSP domains, with up to a one-year waiver. ISACA requires five years of relevant experience for the CISA, with waivers of up to three years. Candidates can take the exams earlier and follow an associate or experience-building route. That does not make the full credentials sensible default gates for a job intended to provide year one.
The role says entry level. The gate says come back when you are already established. There is a price problem hiding in there too. Five years of experience and a CISSP is a mid-level profile. Posting it at an entry-level salary does not create a shortage of junior talent. It creates a shortage of experienced people willing to take a pay cut, and then labels that shortage a pipeline failure.
Certifications are not the problem. Requiring a credential designed for experienced professionals without checking whether the actual work needs it is the problem. We have taken a useful signal, removed the context, and turned it into a polite way of saying no.
The Readiness Complaint Starts in the Job Description
Most impossible job descriptions are not written by one unreasonable person. They are assembled.
The hiring manager starts with the work the team needs covered. Somebody copies the last requisition. A stakeholder adds a tool. Compliance adds a credential. Recruiting asks for a clean experience threshold because the applicant tracking system needs something searchable. Nobody removes the older requirements, so the role quietly absorbs every anxiety the organization has about making a bad hire.
Each addition feels defensible on its own. The finished job is not.
Now the employer has a posting that asks one junior person to monitor alerts, investigate incidents, manage cloud risk, support audits, write policy, tune tools, and communicate with executives. If an actual entry-level candidate reads that and decides they are underqualified, the process has rejected them before the ATS gets the chance.
If they apply anyway, the volume problem gets worse. In The Numbers Game in Resume Submission Is Broken, I wrote about the loop: employers publish inflated requirements, candidates learn to ignore them, applications become more polished and less informative, and employers respond by tightening the filters again.
Automated screening did not invent the contradiction. As I argued in AI Resume Screening Is Filtering Out Your Best Cyber Candidates, it simply enforces the job description at a speed no human team could match.
A bad requirement does not become a good decision because software applied it consistently.

A High Bar Is Not the Same as an Impossible Gate
Entry-level does not mean consequence-free. Junior analysts touch real systems, sensitive data, customer trust, and incidents that do not become less urgent because somebody is new. The answer is not to lower the bar. It is to put the bar in the right place.
The NIST NICE Framework is built for exactly this. It breaks cyber work into tasks, then attaches the knowledge and skills each task requires. Nowhere does it ask how many years somebody has been near security. The question it forces is the right one: what must this person be able to do, at what level, and with how much supervision?
For a junior SOC analyst, the day-one standard might be to review a realistic alert, identify what information is missing, choose the right escalation path, and write a clean case note. It should not be to lead a major incident alone.
For a junior GRC analyst, it might be gathering evidence, mapping it to a control, spotting a gap, and explaining that gap clearly. It should not be owning the enterprise risk program by Friday.
For an identity and access role, it might be processing access changes against policy, recognizing an exception, and knowing when to stop and ask. It should not be owning the identity program before the badge photo is taken.
That distinction is the job description. The tasks define the standard. Supervision defines the level. Evidence tells you whether the candidate can begin.
Experience Is One Route to Readiness
Experience matters. It is also not created only inside a job with cybersecurity in the title.
CyberSeek's career pathways show multiple on-ramps into cyber work. An IT support analyst may already understand identity, endpoints, user behavior, and the difference between a technical problem and a suspicious one. A network or cloud engineer may understand architecture and access better than their title suggests. Someone in audit, fraud, risk, or compliance may bring the judgment and business context that a purely technical screen misses.
That does not make any adjacent candidate automatically ready. Adjacent skills still need to be mapped, gaps still need to be developed, and capability still needs evidence. But those are solvable questions. A title mismatch is not a verdict.
This is also where employers should look inside the business. The person closest to ready may already know your systems, customers, controls, and internal politics. They may be doing security-critical work under a title your recruiting filter would never recognize.
Internal mobility is not a substitute for opening doors to students, career changers, and other new entrants. It is proof that the pathway into cyber is wider than the list of people who have already held the exact job.
If the only acceptable candidate is someone who has done the same role elsewhere, you are not hiring entry-level talent. You are transferring experience between employers and calling it pipeline development.

Build the Role Before You Build the Filter
A credible entry-level role should answer five questions before it goes anywhere near a job board:
- First six months: What work will this person own, contribute to, or observe during the first six months?
- Day-one requirements: Which knowledge, behaviors, access conditions, or credentials are required before the person starts?
- Learnable scope: Which tools, processes, and tasks can be taught with reasonable supervision after hiring?
- Evidence: What short, fair work sample, lab, project, or structured scenario would show that the candidate can begin the work?
- Development path: What support, feedback, training, and milestones will take the person from beginner to independent contributor?
Then write the posting in the same order.
Put true requirements under required.
Put useful context under preferred. Put the skills you intend to teach under what you will learn. If a certification is mandatory because of a contract or control, say why. If it is simply familiar, stop pretending familiarity is necessity.
Bring evidence into the process early enough to matter. A focused screening conversation followed by a short, role-relevant task can tell you more than another paragraph of keywords. Score comparable candidates against the same rubric and keep the exercise short. An entry-level assessment that takes longer than the first week of onboarding is not measuring readiness. It is measuring who can afford to wait.
The NIST employer guidance on job descriptions and hiring rubrics makes the same operating point: describe the work, distinguish essential from preferred criteria, and evaluate people consistently against what the role requires.
And decide who owns the first ninety days. If nobody has time to supervise, give feedback, and build the missing skills, the organization may not be ready to hire at entry level. That is a resourcing decision. It should not be disguised as a candidate shortage.
Employers Own the Job They Publish
There is real work to do in education, training, and career preparation. Employers do not own every part of the cyber talent problem. They do own the job they publish, the evidence they accept, and the pathway they are prepared to support.
HiringIQ gives hiring teams a way to see entry-level readiness before the job description has already made the decision. Candidates demonstrate role-relevant skills early, and the team sees who can begin the work, who is one gap away, and what that gap actually is.
It does not decide what your entry-level bar should be. That judgment still belongs to the people who understand the work. The value is giving them a clearer view than years, titles, and keywords can provide on their own.
Entry-level talent does not arrive finished. If finished is the requirement, say so and stop calling the role entry level.
If the role is supposed to create year one, design it for somebody who is ready to begin year one.
Fix the entry-level hiring signal with HiringIQ.
Entry Level Cyber Hiring Quick Answers
What should an entry-level cybersecurity job description include?
Name the work the person will perform in the first six months, the few day-one requirements that matter, the skills that can be learned after hiring, the supervision available, and the evidence candidates can use to demonstrate readiness.
Should entry-level cybersecurity candidates already hold certifications?
Relevant certifications can show foundational knowledge and commitment. Require one only when it fits the actual work or a real contractual or compliance condition. Experienced-level credentials should not become default filters for roles intended to create experience.
How can employers assess candidates with limited experience?
Use short work samples, hands-on labs, completed projects, structured scenarios, and interviews tied to real tasks. Evaluate adjacent experience and learning ability with the same care as direct job-title experience.
Can internal mobility help fill entry-level cyber roles?
Yes. Employees in IT, networking, cloud, software, audit, fraud, risk, and compliance may already hold relevant adjacent skills and organizational knowledge. Assess the evidence, identify the gaps, and build a clear development path rather than assuming the title tells the whole story.
Sources
- ISC2, 2025 Cybersecurity Hiring Trends https://www.isc2.org/Insights/2025/06/cybersecurity-hiring-trends-study
- ISC2, CISSP Experience Requirements https://www.isc2.org/certifications/cissp/cissp-experience-requirements
- ISACA, CISA Certification Requirements https://www.isaca.org/credentialing/cisa/get-cisa-certified
- NIST NICE Framework Resource Center https://www.nist.gov/itl/applied-cybersecurity/nice/nice-framework-resource-center
- NIST, An Employer's Guide to Writing Effective Cybersecurity Job Descriptions and Hiring Rubrics https://www.nist.gov/system/files/documents/2023/09/22/MTM%20Guidance%20on%20Writing%20a%20Hiring%20Rubric.pdf
- CyberSeek, Cybersecurity Career Pathway https://www.cyberseek.org/pathway.html
- QuickStart, AI Resume Screening Is Filtering Out Your Best Cyber Candidates https://www.quickstart.com/blog/cyber-readiness/ai-resume-screening-is-filtering-out-your-best-cyber-candidates/
- QuickStart, The Numbers Game in Resume Submission Is Broken https://www.quickstart.com/blog/cyber-readiness/cybersecurity-hiring-volume-vs-signal/
About the Author
Launa Rich, Cyber Skills & Talent Intelligence Leader
10+ years building cybersecurity workforce pipelines, hiring intelligence programs, and go-to-market strategy for enterprise security teams. Focused on closing the gap between credentials and capability.
