AI & Emerging Tech
Cybersecurity career pathways remain fragmented as workforce shortages persist: Report

The findings suggest many employers are looking beyond qualifications and certifications when hiring cybersecurity professionals.
Unclear career pathways, inconsistent job definitions and the high cost of entering the profession are making it harder to build Australia's cybersecurity workforce, according to findings from the CyberPath Professionalisation Pilot.
The research, conducted in partnership with Evolved Group, found that while demand for cybersecurity talent continues to grow, the absence of a nationally consistent career framework is creating barriers for job seekers, employers and education providers alike.
Based on a survey of 300 respondents, the report found that cybersecurity now encompasses more than 60 distinct job roles.
However, many professionals still struggle to understand where they fit, the skills they need to develop, or how to progress their careers.
Employers, meanwhile, face challenges assessing candidates' capabilities, while education providers are finding it difficult to align training with industry requirements.
Career pathways need clearer direction
The report found strong support for a more practical, capability-based approach to professional recognition, backed by clearer role definitions, stronger collaboration between education providers and employers, and more accessible entry pathways.
Clint Thomson, Director at TechConnect said, “Our own graduate and work-experience programs show the talent is there; what's missing is a structured pathway to bring it in.”
“It needs clearer career pathways, stronger links between education providers and employers, and more chances for graduates to get hands-on experience in live customer environments,” he added.
Employers seek practical capability over credentials
The findings suggest many employers are looking beyond qualifications and certifications when hiring cybersecurity professionals.
While certifications provide a useful benchmark, organisations increasingly value practical problem-solving skills, communication and adaptability over formal credentials alone.
“Cybersecurity demands a mix of technical skill, problem-solving, communication and a security mindset that's hard to assess from a resume alone,” Thomson commented.
“We've found aptitude and attitude are often better predictors of success than years on the job. Curiosity, a willingness to keep learning, and the ability to work through real problems tend to matter more than a tick-box list of prior study or basic experience,” he further mentioned.
Building a stronger talent pipeline
The CyberPath Professionalisation Pilot is a government-funded initiative led by a consortium including the Australian Computer Society (ACS), the Australian Information Security Association (AISA) and the Australian Women in Security Network (AWSN).
The programme is now developing a national capabilities framework to define the skills, knowledge and behaviours required across cybersecurity roles.
The report also recommends closer collaboration between industry and education providers, broader recognition of skills-based pathways alongside traditional certifications, and greater investment in internships, apprenticeships, graduate programmes and work-integrated learning to help bridge the experience gap.
Thomson also noted that smaller cybersecurity firms face increasing competition for talent from government agencies and large consultancies, which often have greater resources to attract skilled graduates.
“Australia isn't short on people who want to work in cybersecurity; it's short on accessible, structured ways for them to get in, develop and stay,” he concluded..
The findings reinforce growing calls for a more coordinated approach to developing cybersecurity talent, with clearer career pathways and stronger industry collaboration seen as critical to addressing persistent workforce shortages.
Author
Loading...
Loading...





