Are security specialties turning into engineering jobs?Detection, identity and general security roles are.
Written entirely by agents in the Research Factory, within guardrails and controls set by our team. Figures as of 1 October 2026.
Read the full research paperMost of them are. Comparing US security job postings from spring 2024 with postings at US-headquartered companies in September 2026, the analyst specialties (detection and response, vulnerability management, identity, threat intelligence) moved toward engineering. GRC (governance, risk and compliance) picked up automation without becoming a coding job. AppSec (application security) and cloud security were engineering jobs already. In architecture, a change in decision work is not measurable, and privacy moved toward governance instead. Each change we report comes with a range of likely values. If that range includes zero, we can't tell the change from no change.
Across all security postings, asks for a programming language rose from 22% to 43%. The 2026 postings lean more senior. If 2026 had the same mix of seniority levels as 2024, the 2026 share would be 42%. The rise holds within each individual contributor and manager level.
In detection and response, asks for a programming language rose more than asks to write code or do software engineering. And a change in the amount of hands-on work is not measurable. What changed is the kind of work the postings describe.
The answer at a glance
Postings asking for a programming language rose from 22% to 43%
Detection and response, identity and the general security role moved toward engineering
Threat intelligence moved the same way, and vulnerability management probably did, but only just
GRC automated without becoming a coding job
AppSec and cloud security were already engineering jobs. AppSec's change is AI
Architecture postings naming a programming language went from 10% to 25%. A change in decision work is not measurable
A move toward engineering in privacy is not measurable. It moved toward decision and governance work
A change in the amount of hands-on work is not measurable. The kind changed
Source: AKA Security analysis of 1,038 US security postings from the public LinkedIn Job Postings dataset (5 to 19 April 2024) and 4,587 postings at US-headquartered companies in AKA's job-board data (1 October 2026).
The numbers by specialty
Selected specialties, spring 2024 → September 2026: posting counts, then the share of each specialty's postings. "Engineer title" means the title contains engineer or developer. Leadership, program, offensive, AI security and infrastructure postings make up the rest of the totals.
| Specialty | Postings, 2024 → 2026 | Engineer title | Asks for a programming language | Asks for automation | Names a certification |
|---|---|---|---|---|---|
| Detection and response | 74 → 484 | 19% → 50% | 18% → 48% | 42% → 67% | 51% → 34% |
| Vulnerability management | 22 → 86 | 27% → 50% | 23% → 44% | 32% → 71% | 36% → 50% |
| Identity and access (IAM) | 64 → 148 | 41% → 65% | 30% → 45% | 33% → 71% | 13% → 35% |
| Threat intelligence | 13 → 58 | 0% → 34% | 0% → 38% | 23% → 66% | 23% → 19% |
| General security analyst or engineer | 340 → 1,128 | 42% → 61% | 21% → 41% | 26% → 53% | 40% → 32% |
| GRC | 137 → 309 | 4% → 24% | 3% → 15% | 18% → 47% | 68% → 52% |
| AppSec and product security | 85 → 730 | 81% → 87% | 62% → 64% | 59% → 63% | 28% → 19% |
| Cloud security | 31 → 173 | 68% → 78% | 35% → 52% | 45% → 75% | 19% → 30% |
| Architecture | 81 → 232 | 2% → 13% | 10% → 25% | 21% → 44% | 41% → 48% |
| Privacy | 20 → 101 | 25% → 45% | 40% → 25% | 55% → 35% | 20% → 16% |
Source: AKA Security analysis of 1,038 US security postings from the public LinkedIn Job Postings dataset (5 to 19 April 2024) and 4,587 postings at US-headquartered companies in AKA's job-board data (1 October 2026).
Programming language asks by level
| Level | Postings, 2024 → 2026 | Share of postings, 2024 → 2026 | Asks for a programming language, 2024 → 2026 | Likely range of the change (95%), percentage points |
|---|---|---|---|---|
| Executive | 39 → 245 | 4% → 5% | 8% → 16% | −4 to +18 |
| Manager | 80 → 310 | 8% → 7% | 9% → 20% | +3 to +20 |
| Senior individual contributor | 274 → 2,146 | 26% → 47% | 27% → 50% | +17 to +30 |
| Individual contributor | 645 → 1,886 | 62% → 41% | 22% → 43% | +15 to +26 |
| Each bar is a range of likely values against zero, the dashed line. A hollow bar includes zero: we can’t tell the change from no change. | ||||
Source: AKA Security analysis, same postings. Senior individual contributors went from 26% to 47% of postings. If 2026 had 2024's mix of levels, the 2026 share asking for a language would be 42% rather than 43%, so the shift in levels accounts for a small part of the rise. The executive change is too small to tell apart from no change.
Analyst specialty postings ask for engineering
Detection and response
Detection and response has more postings than the other analyst specialties, 74 in 2024 and 484 in 2026. Engineer titles went from 19% to 50% of postings (likely range of the change: +20 to +41 percentage points) and asks for a programming language from 18% to 48% (+19 to +41). Certifications fell from 51% to 34%.
In 2024, scripting showed up as an add-on to monitoring. A Sr. SOC Analyst posting at Consumer Cellular asked the hire to "write scripts to query systems for security purposes using PowerShell or Python." In 2026, the build is the job. Roblox's Senior Security Engineer, Detection and Response, will "design and build the detections, automation and tooling that let a lean team monitor and protect players, developers, employees and the platform at global scale." Samsara's Senior Security Engineer, Threat Detection, will "advance our detection-as-code platform through version control, peer review, automated testing, CI/CD."
Vulnerability management
Engineer titles rose from 27% to 50%, a likely but borderline rise (−1 to +44), and automation asks from 32% to 71%. The 2024 base is 22 postings, and the direction is surer than the size. A 2024 CrowdStrike Vulnerability Management Analyst posting listed scripting under "Bonus Points." A 2026 Danaher posting for a Lead Engineer, Vulnerability and Exposure Management, describes a hire who "engineers the scanning, ingestion, normalization, prioritization, ticketing, reporting, and automation workflows."
Identity and threat intelligence
Identity postings with an engineer title went from 41% to 65%, and asks for a language from 30% to 45%, a likely but borderline rise. IAM is the one specialty with a clear rise in certification asks, from 13% to 35% (likely range +11 to +34). Threat intelligence went from no engineer titles in 2024 to 34%, on a small 2024 base of 13 postings.
The general security role
The broadest bucket moved too. Among general security analyst and engineer postings, the share with an engineer title went from 42% to 61%, and asks for automation doubled, from 26% to 53%.
The kind of hands-on work changed
2024 detection and response postings already asked the hire to do the work personally. Three AI models each read every posting in both years and labelled whether the hire mainly does the technical work, and we use the answer at least two agree on. By that answer, 76% of 2024 detection and response postings were mainly hands-on, and 74% in 2026 (likely range −12 to +10, no measurable change). AppSec went from 85% to 79% (−13 to +3), GRC from 68% to 67% (−12 to +10). The general security role went from 89% to 85%, no clear change (−8 to +1).
Two of the models agree with each other at a kappa of 0.74 on this label and 0.79 on each posting's main activity. Kappa is a standard agreement score: one is perfect agreement and zero is what chance alone would give. The local model agrees with them at 0.56 and 0.63 on hands-on work, so this section rests on the answer at least two models agree on. The result holds for each model on its own.
In detection and response, asks naming a language rose more than asks to write code or do software engineering: from 18% to 48% (+19 to +41) against 18% to 30% (+1 to +24, a likely but borderline rise). The difference between the two rises is +6 to +30 percentage points, a clear difference. The 2026 postings describe building detections, pipelines and automation, with Python scripting, SOAR (security orchestration, automation and response) playbooks and detection-as-code.
GRC postings ask for automation, not code
GRC postings asking for automation went from 18% to 47%, and a GRC engineer title appeared, from 4% of postings to 24% (likely range +14 to +26). Coding stayed rare at 15%. Certifications fell from 68% to 52%.
Plaid's Security Engineer, GRC posting puts it directly: "Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable." Mattermost's GRC Manager posting adds: "You will do the hands-on compliance work."
AppSec and cloud security postings already asked for engineering
AppSec postings already asked for engineering in 2024, with 81% engineer titles and 62% asking for a language. Engineer titles were 87% in 2026, a change that is not measurable (−2 to +14). Its change since is AI. Terms such as LLM (large language model), generative AI, agents and prompt injection went from no 2024 AppSec postings to 41% in 2026 (+35 to +46). Certification asks went from 28% to 19%, a drop too small to tell apart from no change (−21 to +1 percentage points). Cloud security postings asked for more automation, from 45% to 75% (+9 to +49), while the change in engineer titles, 68% to 78%, is not measurable (−7 to +29).
More architecture postings name a programming language
25% of architecture postings name a programming language, up from 10%. Deciding is the main activity in 31% of 2026 architecture postings and 20% in 2024 (likely range −1 to +24 percentage points, no clear change). With one of those two models alone there is no clear change either (−1 to +22). With the other alone it is a likely but borderline rise (+1 to +26). In detection and response the share is 8%, and in AppSec 12%.
Privacy postings shift toward decision work
A move toward engineering in privacy is not measurable. Asks for a programming language went from 40% to 25% and engineer titles from 25% to 45%, on a small 2024 base of 20 postings, and neither change is clear (−41 to +8 and −6 to +41). Privacy postings more often name deciding and governance duties instead. No 2024 privacy posting had deciding as its main activity. In 2026, 19% do (likely range +12 to +27). Each model on its own shows the rise: one of the two at 23% (+15 to +31), the other at 15% (+8 to +22) and the local model (+13 to +29). No 2024 privacy posting carried AI policy, risk or compliance duties, against 24% in 2026 (+16 to +33).
The question as asked
How are different specialties evolving, like AppSec, Security Architecture, Vuln Management, etc. I imagine those roles are shaped differently than previously. For example, are they all trending to more hands-on engineering?
Asked by Jamie Dicken
Where the data comes from
This piece measures moves by specialty. For the overall split of engineering and non-engineering titles across all security postings, see How Do Engineering and Non-Engineering Titles Split Across Security Job Openings?.
The 2024 postings come from the LinkedIn Job Postings dataset on Hugging Face (datastax/linkedin_job_listings): US postings listed between 5 and 19 April 2024. The 2026 postings come from AKA's daily read of company job boards, limited to US-headquartered companies. The two sets match on country but not on exact definition.
Job aggregators, which repost other employers' jobs, are left out in both years, and the 2026 postings are those open on or after 23 September 2026. Both years go through one set of rules. A posting counts when its title passes the series' security title rules, a local model rules it a security role, and it is the only posting with that title at that company. Title level, specialty and description terms follow identical rules in both years. The likely ranges are 95% ranges for the change, found by resampling whole companies many times rather than single postings.
How this answer was stress-tested
Tests marked earlier run were run on an earlier day's data, dated in the changelog. The rest were run on the figures in this piece.
| Test | What it found |
|---|---|
| Scope check of every posting, both years. A local model read all 1,405 2024 postings and 5,196 2026 postings that pass the title rules. | It ruled 26% of 2024 postings and 12% of 2026 postings not security roles: financial auditors, physical security, alarm installers, lawyers. Removing them raised 2024 detection and response automation from 28% to 42%. |
| Population matching. Read samples from every bucket in both years. | 2024 carried guards, trades advertised "with security clearance" and psychiatric nurses. 2026 carried chip-design "SoC" titles. Both removed by title rule. (earlier run) |
| Title rules against another model. A separate AI model labelled 192 titles blind, spread across specialties and both years. | Level agreement started at a kappa of 0.94. The misses exposed a bug: "Directory Services" matched "director" and counted engineers as executives. Fixed, 0.975. Specialty agrees at 0.76. (earlier run) |
| Keyword precision. 48 keyword hits read by hand across both years. | Language asks were genuine 16 times out of 16. Automation hits were genuine 13 of 17 times in 2026 and 11 of 15 in 2024. Automation levels run about a quarter high in both years. (earlier run) |
| Description length. 2026 descriptions are 60% longer. Measures repeated on postings of 3,000 to 6,000 characters in both years. | Language asks: all postings 25% → 41% (+10 to +22), detection and response 24% → 40% (a likely but borderline rise, 0 to +32), vulnerability management 18% → 41% (no clear change, −7 to +50), architecture 3% → 30%. Same direction in all three specialties, and similar size in architecture. |
| Company mix. For the specialties, 2026 postings outside technology companies against 2024 without staffing firms and government contractors. The 2024 postings file has no industry field, so the two years are cut differently. For all postings, staffing firms and government contractors removed in both years. | All postings: language asks 22% → 44% (+18 to +27). Language asks in detection and response reach 39% among 2026 non-technology employers. Identity engineer titles reach 55%, no clear change (−6 to +30), GRC automation 41%. Architecture language asks fall to 18%, below its 25% overall, and the change from 2024 is too small to tell apart from no change (−6 to +19). |
| Same companies. 74 companies with US-headquartered postings appear in both years. | All postings: language asks 32% → 41%, no clear change (−4 to +22). Detection and response language asks 23% → 52%, a likely but borderline rise (0 to +56). Identity engineer titles 33% → 73%, no clear change (−24 to +85). GRC automation 23% → 31%, no clear change (−13 to +32). AppSec language 77% → 68%, no measurable change. General role engineer titles 48% → 50%, no clear change (−22 to +25). |
| Title level. The language share at each title level. | It rose within individual contributor, senior and manager titles. Held to the 2024 level mix, the 2026 share is 42%. |
| Two hosted models on both years. Two hosted models each read all 5,625 postings in both years for hands-on work, main activity and people management. | They agree with each other at kappa 0.74, 0.79 and 0.93. The hands-on finding held for each model separately. |
| Same labeller on both years. A local model read both years with the same instructions. | It first showed the hands-on share barely moving, which reframed the answer from "more hands-on" to "the kind of hands-on work changed". Tuning it against the other two models' labels lifted its people-management agreement from 0.69 to 0.82 on postings kept back from the tuning, but not its hands-on agreement. On 28 September it relabelled both years with the tuned prompt, and it now agrees with one of the other two models at 0.56 on hands-on work. |
| A fresh run on 28 September. The full pipeline rebuilt from that day's data. | 110 more 2026 postings than on 25 September. Every share in the specialty table moved by two points or less. With the relabelled local model, the likely range for the architecture deciding change now starts at −1, so it is too small to tell apart from no change, but only just. |
| An outside source. The SANS Institute and Anvilogic State of Detection Engineering Report 2026, a practitioner survey. | It points the same way. 62% of teams keep detection rules in version control and 42% run them through CI/CD, while 13% of detection engineers report high proficiency in software engineering. That fits postings asking for detection-as-code and scripting more than software development. It measures practitioners, not job postings. |
What would strengthen this answer
| Test | What it would settle | Why it has not run |
|---|---|---|
| A second LinkedIn sample from 2026, collected the way the 2024 one was | Removes the two-source question | LinkedIn restricts automated collection. Buying a comparable feed is the realistic route. |
| Licensed longitudinal postings (Lightcast, Revelio Labs, Indeed Hiring Lab) | Year-by-year specialty shares from 2019, with seasonality | Paid data. |
| A re-read of our own data in three to six months | A direct trend under stable collection | Collection widened on 18 and 22 September. The earliest clean read is late December 2026. |
| A practitioner read of 100 specialty postings | Whether "engineering shift" matches how a security leader reads the jobs | Needs practitioner time. |
Other formats
The same findings and figures, laid out as a research paper with numbered sections, references and a citation.
Read the full research paperVersion history
Every change to this piece is tagged and logged. When a figure moves or a finding no longer holds, it is recorded here rather than edited in silence.
- The summary is now the overall rise in postings asking for a programming language, from 22% to 43%.
- , Q4, Q8 and Q9 The industries counted as outside technology were listed differently across pieces. They now match everywhere, and telecommunications counts as technology. Only test results moved. No answer or rating changed.
- Are security specialties turning into engineering jobs? Figures as of 1 October 2026, some tests 23 September.
Corrections
Received. The Research Factory rechecks the figure against the source, and any fix appears in the changelog.
The rating scales and the standard checks are the same for every piece. How the research is made.
Ask the Research Factory a question.
This is not a live chat. Accepted questions become new pieces, published in a later release.
- 01 You ask, with the decision it would inform You queued
- 02 We check job postings can answer it Our team queued
- 03 Approved questions join the reader queue Our team queued
- 04 Agents write the analysis, ratings and piece Research Factory queued
- 05 Every answer runs our standard controls Our controls queued
- 06 Published and tagged, credited if you want Research Factory queued
- 01 You ask, with the decision it would inform You done
- 02 We check job postings can answer it Our team next
- 03 Approved questions join the reader queue Our team queued
- 04 Agents write the analysis, ratings and piece Research Factory queued
- 05 Every answer runs our standard controls Our controls queued
- 06 Published and tagged, credited if you want Research Factory queued