Hiring alone rarely fixes a security talent gap because demand is broad and competition is intense. Organisations also need internal development, tuition support, and clearer pathways into specialist roles. When they rely only on external recruitment, they miss candidates who can grow into the work and struggle to build durable capability across the security function.
Why This Matters for Security Teams
Hiring is only one part of security capacity, and it is often the slowest path to impact. Organisations underestimate how much of the shortage is really a pipeline problem: too few candidates with hands-on experience, too much competition for the same profiles, and too little internal mobility into specialist roles. The result is a persistent gap between open reqs and operational coverage, even when budgets increase.
For NHI-heavy environments, the issue is sharper because the work is tied to service accounts, secrets, rotation, and workload visibility rather than just headcount. NHIs outnumber human identities by 25x to 50x in modern enterprises, and only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs — Why NHI Security Matters Now. That means a new hire cannot compensate for weak process, weak tooling, or unclear ownership.
Security teams also get trapped by the assumption that external recruitment will automatically create durable capability. In practice, many organisations discover the shortage only after incident response, audit findings, or a privileged access review has already exposed the gap, rather than through intentional workforce planning.
How It Works in Practice
Effective talent strategy treats hiring as an input, not the solution. The strongest programmes combine external recruiting with apprenticeship-style development, cross-training from adjacent IT and engineering functions, and role ladders that let practitioners move from generalist work into IAM, cloud security, detection engineering, or NHI operations. That matters because security work is increasingly specialised, and the operational skills required to manage secrets, identity lifecycle, and access policy rarely appear fully formed in the market.
This is especially true where identity and workload security intersect. Current guidance suggests teams should pair staffing decisions with concrete operating controls: inventory the identities that matter, assign clear ownership, and make rotation, offboarding, and exception handling routine. For broader context, see Top 10 NHI Issues and the CISA cyber threat advisories for the kinds of identity-driven attack patterns that keep recurring.
- Use hiring to fill near-term gaps, but build internal progression paths for analysts, administrators, and developers who already understand the business.
- Fund certifications, lab time, and tuition support so employees can move into specialist work without leaving the organisation.
- Map each role to a small set of operational outcomes, such as secrets rotation, access reviews, or alert triage, instead of vague “security support.”
- Measure time-to-productivity, not just time-to-fill, because a fast hire without domain context can still leave controls weak.
For NHI security specifically, the operational goal is to reduce dependence on individual heroics by building repeatable controls around credential inventory, rotation, and access governance, as described in the Ultimate Guide to NHIs — Key Challenges and Risks. These controls tend to break down when teams hire into a fragmented operating model because no one owns the full lifecycle of identities and secrets.
Common Variations and Edge Cases
Tighter hiring plans often increase short-term cost and manager overhead, requiring organisations to balance speed against capability-building. That tradeoff becomes more visible in smaller teams, regulated environments, and distributed enterprises where the same person may cover IAM, cloud, and compliance work at once.
There is no universal standard for how much should be solved by hiring versus development, but current guidance suggests the right mix depends on how specialised the work is and how much institutional knowledge is embedded in the stack. In some organisations, the bottleneck is not talent availability but the absence of a training path that turns junior staff into effective operators. In others, external recruitment is necessary for niche roles, but it must be paired with documentation, mentorship, and backfill planning so knowledge does not sit with one person.
The edge case to watch is a team that keeps adding specialists without fixing operational clarity. If secrets live in code, ownership is ambiguous, or access reviews are manual, new hires spend their time compensating for process debt instead of reducing risk. That is why workforce planning and control design have to move together, not in sequence.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Identity inventory and ownership are central to building repeatable NHI capability. |
| OWASP Agentic AI Top 10 | Autonomous workloads need operational governance, not just extra headcount. | |
| CSA MAESTRO | MAESTRO aligns workforce design with secure operating models for AI systems. | |
| NIST CSF 2.0 | GV.OC-01 | Cybersecurity talent strategy should support organisational roles and responsibilities. |
| NIST AI RMF | GOVERN | AI RMF governance emphasizes capability, accountability, and role clarity for complex systems. |
Staff to support runtime identity control, policy enforcement, and incident response for agentic systems.
Related resources from NHI Mgmt Group
- What do organisations get wrong when they secure AI only at the model layer?
- What do organisations get wrong when they let AI assistants handle privacy lookups?
- What do organisations get wrong when they treat identity verification as a pilot project?
- What do organisations get wrong when they treat human, machine, and AI identities the same?