All research

What do companies expect of entry-level security hires?A smaller share accepts zero to two years.

Confidence: Medium Representativeness: Medium

Written entirely by agents in the Research Factory, within guardrails and controls set by our team. Figures as of 1 October 2026.

v1.0.0 Published Fall 2026 Changelog
Asked by Lenny Zeltser
Read the full research paper

Among security postings that state a years-of-experience requirement, a smaller share is open to entry-level candidates, and the ones that are ask for different things. The comparison is between US-located LinkedIn security postings from spring 2024 and postings at US-headquartered companies in September 2026. Among postings stating an experience requirement, the share that accepts two years or less fell from 18% to 14%, a likely but borderline fall. Entry postings now mention Python about twice as often, and one in five expects the hire to use AI tools in their own work. In spring 2024 almost none did. Mentions of Security+ fell by 51% and of CISSP by 44%.

In 2026, entry postings require a degree with no alternative nearly twice as often as postings asking three years or more. The likely range of that gap is +8 to +27 percentage points. Security operations postings accept entry candidates more often than development and advisory postings.

The answer at a glance

The share of postings stating years that accept 0 to 2 fell from 18% to 14%, a likely but borderline fall

Confidence Medium. The fall is likely but borderline. The drop shows under each of the three models and on postings of similar length, though on one model alone it is borderline. At the companies present in both years, the drop is too small to tell apart from no change.
Representativeness Medium. Government, staffing and managed-security postings are under-covered in this data.

Entry postings mention Python about twice as often, and expect AI tool use where 2024 postings almost never did

Confidence High. Python is a literal keyword match. AI tool use counts when at least two of the three models agree, and each model alone puts it at 18% to 23% of 2026 entry postings.
Representativeness Medium.

Mentions of Security+ in entry postings fell by 51% and of CISSP by 44%

Confidence High. Both falls are real changes: too large to be explained by which postings happened to be collected.
Representativeness Medium.

Entry postings list a degree as a firm requirement more often than postings asking three years or more

Confidence High for 2026: the gap is clear under each of the three models. Low for any change since 2024: the change in the gap is not measurable.
Representativeness Medium.

Security operations postings accept entry candidates more often than development and advisory postings

Confidence High. The lead is clear against both. Over offensive security it is likely but borderline. Against privacy and governance, risk and compliance (GRC) it is not measurable.
Representativeness Low. One specialty, and government and managed-security operations center (SOC) postings are under-covered in this data.

The numbers

Share of postings, spring 2024 → September 2026. Three AI models, one of them a local model, each read every posting for its minimum years of experience and its degree requirement, and we use the answer at least two agree on. A posting is entry level when at least two of them put that minimum at 0 to 2 years. Skills and certifications count any mention in the description, not only a requirement. Whether the hire is expected to use AI tools is read by the models the same way. The last column is the range of likely values for the change, in percentage points.

Measure20242026Change, likely range (95%), points
Accepts 0 to 2 years (of postings that state years)18.3%13.6%−8.5 to −1.0
Asks 8 years or more (of postings that state years)18.6%26.7%+4.2 to +11.8
Degree required with no alternative, all postings23.0%15.8%−11.0 to −3.3
Degree required with no alternative, postings asking 3+ years25.3%18.8%−11.2 to −1.9
Degree required with no alternative, 0 to 2-year postings32.4%36.2%−8.3 to +15.9 (no measurable change)
Among 0 to 2-year postings: mentions Python22.7%46.6%+13.4 to +34.4
Expected to use AI tools0.7%20.4%+12.8 to +28.3
Mentions CTF, bug bounty, home lab or personal projects0.7%8.4%+4.6 to +11.0
Mentions Security+22.7%11.1%−20.1 to −3.3
Mentions CISSP22.0%12.3%−17.9 to −1.6
Mentions cloud (AWS, Azure, GCP)25.5%29.5%−6.0 to +14.0 (no measurable change)
Mentions a SIEM, security monitoring software (Splunk, Sentinel and similar)24.1%23.2%−10.0 to +8.3 (no measurable change)
Each bar is a range of likely values against zero, the dashed line. A hollow bar includes zero: we can’t tell the change from no change.

Source: AKA Security analysis of 1,038 US security postings from the public LinkedIn Job Postings dataset (5 to 19 April 2024) and 4,587 postings at US-headquartered companies in AKA's job-board data (1 October 2026). 141 postings in 2024 and 431 in 2026 accept 0 to 2 years. A change in bold is a clear change.

A smaller share of postings accepts two years or less

The share accepting two years or less, 2024 and 2026

Among postings that state an experience requirement, 18.3% accepted two years or less in spring 2024 and 13.6% in September 2026. The fall is likely but borderline (likely range −8.5 to −1.0 percentage points). Postings asking eight years or more rose from 18.6% to 26.7%. Most postings state a requirement at all: 69.2% in 2026, against 74.1% in 2024.

Within specialties, the drop is not measurable

If 2024 had 2026's mix of specialties, its share would be 17.0%, against the actual 18.3%. Within specialties, general security engineer and analyst roles went from 24.4% to 18.3% of postings stating years, a change too small to tell apart from no change. For detection and response (28.6% in 2024, 15.6% in 2026) the fall is likely but borderline. For application security (AppSec, 20.7% and 12.7%), GRC (18.3% and 16.1%) and infrastructure security (7.1% and 14.1%) the change is not measurable.

A quarter of security operations postings accept two years or less

Security operations roles, as the job-board data tags them, are 14% of the 4,369 tagged 2026 postings and 26% of the tagged 0 to 2-year postings. Within security operations, 24.1% of postings that state years accept two or less. The other role families sit at 15.4% for GRC, 13.8% for offensive security, 15.1% for privacy, 10.1% for advisory and 10.4% for development.

Security operations' lead over development has a likely range of 7 to 22 percentage points, and over advisory 3 to 25. Over offensive security the range is 0 to 20, so the lead is likely but borderline. Against privacy (−1 to 19) and GRC (−3 to +20) the range includes zero, so there is no clear lead. Development is still the largest source of entry postings in absolute terms, at 40%. It is also 50% of all tagged postings.

What entry postings ask for now

Python and AI tools rose as certifications fell

Python appears in 46.6% of 2026 entry postings, up from 22.7%. The expectation that the hire uses AI tools in their own work went from almost nothing to 20.4%. That is about the same as the 21.1% among 2026 postings asking three years or more. Each model alone puts it at 18% to 23%. Mentions of Security+ fell from 22.7% to 11.1%, a drop of 51%, and of CISSP from 22.0% to 12.3%, a drop of 44%. Mentions of cloud (likely range −6.0 to +14.0 points) and SIEM (−10.0 to +8.3) showed no measurable change, at about a quarter of postings each.

In 2024, a Booz Allen Hamilton Cybersecurity Test Engineer posting open to under two years of experience required the "Ability to obtain DoD IAT Level II Compliant Security+ CE Certification within 120 days of start date." In 2026, FIS's Risk and Cybersecurity university programme "begins 2027 with a series of AI-Enabled Learning Sprints," and tells candidates to "Learn how to leverage AI alongside human judgment."

Visible work entered the postings

Capture-the-flag (CTF) competitions, bug bounties, home labs and personal projects, work a candidate can show, appear in 8.4% of 2026 entry postings, against 0.7% in 2024. Saronic's Security Operations Analyst posting lists "Hands-on learning signals such as a home lab, CTF participation, personal detection/hunting projects, or public writeups/blogs." Hover's Security Software Engineer posting asks for "Demonstrated curiosity in security through CTF competitions, open-source contributions, or personal projects."

A change in entry degree requirements is not measurable

Across all postings, requiring a degree with no alternative fell from 23.0% to 15.8%. Postings asking three years or more fell from 25.3% to 18.8%, a clear fall. For entry postings, at 32.4% and 36.2%, the change is not measurable. In 2026, an entry posting requires a degree with no alternative nearly twice as often as one asking three years or more (36.2% against 18.8%, a gap with a likely range of +8 to +27 percentage points). In 2024 the gap was 32.4% against 25.3% (likely range −2 to +16). The gap grew by +10.3 points between the two years, but the likely range of that growth is −2 to +23, so the change is not measurable.

Where the data comes from, the stress tests and the version history Method and tests Read the full research paper

The question as asked

What expectations do companies have of entry level personnel? Can we uncover anything useful as advice people who want to enter the industry or those still early in their career journey?

Asked by Lenny Zeltser

Where the data comes from

The 2024 postings come from the LinkedIn Job Postings dataset on Hugging Face (datastax/linkedin_job_listings): US postings listed between 5 and 19 April 2024. The 2026 postings come from AKA's daily read of company job boards, limited to US-headquartered companies. Both sets are US postings, but defined differently: 2024 by where the job is, 2026 by where the company is headquartered. Both years are filtered the same way: by job title, by a local model's check that each posting is a security role, and by keeping one posting per company and title. Job aggregators, which repost other employers' jobs, are left out in both years. The 2026 postings are those open on or after 23 September 2026.

The minimum years of experience and the degree requirement were read from each posting by three models, and this piece uses the value at least two of them agree on. Postings where no two models agree on the degree are left out of the degree shares. Skills and certifications are keyword matches. Whether the posting expects the hire to use AI tools in their own work is also read by the three models, and this piece uses the answer at least two agree on.

Each likely range (95%) covers the plausible values for the change. Postings from one company tend to resemble each other, so the ranges were found by resampling whole companies, not single postings. They allow for chance in which postings were collected, but not for the two years coming from different sources, locations and seasons, so the comparison mixes change over time with differences between sources.

How this answer was stress-tested

Tests marked "earlier run" used an earlier day's data and only the local model's answers. Their dates are in the changelog. The rest use the figures in this piece.

TestWhat it found
Three models on both years. Two of the models each read all 5,625 postings for minimum years and degree requirement, alongside the local model.Those two agree on the experience band at 0.98, and each agrees with the local model at 0.91, on an agreement score (kappa) where 1 is perfect. The entry drop holds for every model: 19.1% → 13.7% and 17.8% → 13.4% (likely but borderline) for the two, and 22.0% → 15.2% for the local model.
Degree label recall. The local model's degree answer was checked against the other two.The other two agree at 0.97 on degree requirements, and the local model agrees with each at 0.79 and 0.78. The local model caught 74% of the firm degree requirements that both of the other two found. On its own labels, 25% of 2026 entry postings require a degree with no alternative, against 36% when at least two models agree. Every model shows entry postings requiring degrees more than postings asking three years or more in 2026.
The 2024 degree pattern. Degree requirements in entry postings against postings asking three years or more, 2024.The local model alone had shown no 2024 gap (25% against 20%) and called the 2026 gap new. The three-model majority finds a 2024 gap of 32.4% against 25.3%. The change in the gap between years is not measurable (likely range −2 to +23 points), and this piece reports no trend in it.
Specialty mix. 2024 recalculated as if it had 2026's mix of specialties.17.0%, against the actual 18.3%.
Same companies. The 74 companies in both years.20.8% → 13.3% of postings stating years accept 0 to 2, a change too small to tell apart from no change.
Description length. Postings of 3,000 to 6,000 characters in both years.22.3% → 15.7%.
New postings only. 2026 postings first published in the 30 days before the figures date.16.0%, against 18.3% for all 2024 postings. The 2024 set has no matching restriction.
Non-technology industries. 2026 postings outside technology companies.17.5% accept 0 to 2 years, against 21.0% for all 2024 postings on the same local labels. The 2024 set has no matching restriction. (earlier run)
Title markers. Titles carrying junior, associate, new grad, "I" or tier 1.2.8% of 2026 security postings at companies headquartered in any country, not only the US-headquartered set used elsewhere, carry an entry marker in the title. Most postings at US-headquartered companies that accept 0 to 2 years carry none.
A fresh run on 28 September. The full pipeline rebuilt from that day's data.On the local model's labels, 2024 was unchanged and the 2026 share moved by less than half a point with 110 more postings. (earlier run)

What would strengthen this answer

TestWhat it would settleWhy it has not run
Government, managed-security and staffing postingsThe SOC and entry shares across postings under-covered in this dataUSAJobs and staffing boards are not in the collection yet.
A second LinkedIn sample from 2026, collected the way the 2024 one wasRemoves the two-source questionLinkedIn restricts automated collection. Buying a comparable feed is the realistic route.
Licensed postings data spanning years (Lightcast, Revelio Labs, Indeed Hiring Lab)Year-by-year entry shares from 2019, with seasonal patternsPaid data.
A re-read of our own data in three to six monthsA direct trend under stable collectionCollection widened on 18 September and 22 September. The earliest read on stable collection is late December 2026.
Hires, not postingsWhether fewer entry postings means fewer entry hires, or hiring through internships and programmes that never post publiclyHiring outcomes are not visible in postings.

Other formats

The same findings and figures, laid out as a research paper with numbered sections, references and a citation.

Read the full research paper

Source (Markdown)

Version history

Every change to this piece is tagged and logged. When a figure moves or a finding no longer holds, it is recorded here rather than edited in silence.

v1.0.01 October 2026
Corrected
  • The degree shares now leave out postings where the readers split on the degree, as the piece's own rule says. Each share moved by half a point or less.
Added
  • What do companies expect of entry-level security hires? Figures as of 1 October 2026, one test 23 September.

Series changelog and versioning rules

Corrections

The rating scales and the standard checks are the same for every piece. How the research is made.

Ask the Research Factory a question.

This is not a live chat. Accepted questions become new pieces, published in a later release.

  1. 01 You ask, with the decision it would inform You
  2. 02 We check job postings can answer it Our team
  3. 03 Approved questions join the reader queue Our team
  4. 04 Agents write the analysis, ratings and piece Research Factory
  5. 05 Every answer runs our standard controls Our controls
  6. 06 Published and tagged, credited if you want Research Factory
Ask the Research Factory a question
Answers come as published pieces, not replies. Not every question can be answered from job postings.