Join our Newsletter — 33% off our NHI Course

Why does the shift toward cloud and software-defined security make cybersecurity hiring more difficult?

Cloud and software-defined security require people who understand both security and software development, which narrows the hiring pool. As security controls become more code-driven, organisations need practitioners who can design, implement, and maintain controls inside fast-changing environments. That combination of skills is scarce, expensive, and highly contested across the market.

Why cloud and software-defined security changes the hiring profile

Cloud and software-defined security shift security work away from static appliances and toward controls expressed in code, policy, templates, and automation. That changes the profile from mostly configuring boxes to understanding how security behaves inside delivery pipelines, infrastructure-as-code, identity layers, and continuously changing service boundaries. The hiring challenge is not just volume, it is the rare overlap of security judgment and software fluency.

That overlap matters because practitioners now have to reason about how controls are deployed, versioned, tested, and inherited across environments. In practice, organisations are not only competing for security engineers, but also for people who can translate risk into code, review implementation details, and keep pace with fast-moving cloud services.

It also means traditional experience signals can be weaker than before. A candidate may know network segmentation or perimeter design well, yet still struggle with declarative policy, CI/CD integration, or cloud-native control drift. Hiring gets harder because the role is broader, more technical, and less likely to be covered by a single conventional security background.

Why the talent pool narrows in software-defined environments

Cloud security work often spans architecture, engineering, operations, and governance at the same time. Teams need people who can evaluate a control as both a security requirement and a deployable software artifact, which reduces the number of candidates who are credible on day one. CISA Secure by Design reflects this shift toward building security into systems rather than bolting it on later.

The market is tighter because these skills are transferable across high-demand domains. A strong cloud security engineer can often choose between security, platform engineering, DevSecOps, and infrastructure roles, so security teams compete against a wider set of employers. That competition raises salary pressure and makes retention harder as well as hiring.

The most difficult hires are usually people who can do more than operate tools. Organisations want practitioners who can design controls, automate them, and diagnose failure when the environment changes underneath them. That is a narrower profile than either classic security administration or generic software development alone.

What changes in the hiring process and role design

Hiring becomes more effective when the role is described as a hybrid security-engineering function rather than a traditional analyst post. Candidates need evidence that they can work with cloud services, infrastructure-as-code, pipelines, and version-controlled policy, not just talk about cloud concepts. NIST Cybersecurity Framework 2.0 is useful here because it frames security as a lifecycle that includes governance, protection, detection, response, and recovery.

Assessment should therefore focus on practical demonstrations. A strong interview process will test whether a candidate can read configuration, explain blast radius, identify misapplied controls, and reason about how security behaves when infrastructure is recreated or scaled. For software-defined security, that is often more predictive than relying on certifications alone.

Role design also matters. If one job description asks for cloud architecture, application security, policy-as-code, incident response, and platform automation, the hiring pool will shrink sharply. Better results usually come from splitting responsibilities into clear capability areas and being explicit about which skills are mandatory versus trainable.

Why cloud security hiring is harder to sustain over time

Once a team hires successfully, the same market forces make long-term staffing fragile. Skills in cloud platforms, DevSecOps, and security engineering age quickly as vendors, services, and patterns change. Continuous learning becomes part of the job, so organisations that do not fund training, hands-on practice, and career progression lose people to employers that do.

The challenge is also organisational maturity. If engineering teams own most of the technical environment, security hires must be able to influence design without becoming a bottleneck. That requires trust, technical credibility, and enough automation to avoid turning every change into a manual review.

In that sense, the difficulty is not a shortage of all security talent, but a shortage of people who can operate comfortably in code-driven environments and still make sound security decisions. NIST SP 800-53 Rev. 5 Security and Privacy Controls remains relevant because cloud hiring increasingly involves proving that controls can be consistently implemented, not merely described.

Risk and Threat Considerations

The hiring gap creates real security exposure because understaffed teams tend to rely on fragmented ownership, incomplete reviews, and inconsistent control implementation. In cloud environments, that can leave misconfigurations, privilege sprawl, and weak change control unnoticed until an incident or audit reveals them.

Failure mechanism: When organisations cannot recruit or retain people who understand both security and software delivery, they often ship controls that are technically present but operationally brittle, poorly tested, or not maintained as environments change.

Impact: The result is a higher chance of configuration drift, delayed remediation, weak governance over automated change, and security controls that fail precisely because they were not built for a code-driven operating model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organisational Context Cloud hiring hinges on defining security roles against business and delivery context.
PR.PS-01 — Secure Development Practices Software-defined security requires controls built into code and pipelines.
Recommendation — Define cloud-security responsibilities against the organisation’s operating context and delivery model. Embed security checks into code, templates, and CI/CD workflows.
CIS Controls v8 CIS-5 — Account Management Cloud security teams often need stronger control over identities and access paths in software-defined environments.
Recommendation — Standardise account and access ownership for cloud and platform roles.
NIST SP 800-53 Rev 5 SA-8 — Security and Privacy Engineering Principles Hybrid security-engineering roles require design and implementation discipline.
CM-2 — Baseline Configuration Software-defined security depends on controlled, repeatable configuration states.
Recommendation — Apply engineering principles when designing cloud security controls. Maintain approved baselines for cloud and infrastructure configurations.

Practitioner Guidance

What to prioritise: Define the role around the security decisions that actually need expertise, not around every cloud platform or tool in use. If the job needs policy-as-code, deployment review, and cloud architecture judgement, make those the core criteria and treat niche platform depth as secondary.

What to verify: In interviews and probation, verify that the candidate can explain how a control is deployed, changed, and checked over time. The key signal is whether they can connect design intent to operational reality when infrastructure and services are constantly moving.

Common mistake: Hiring only for security vocabulary or only for cloud administration. That often produces people who can discuss the environment but cannot reliably implement or sustain controls inside it.

Practitioner takeaway: The hiring problem is really a capability-composition problem, organisations need fewer pure generalists and more people who can translate security intent into maintainable software and cloud control.