
Why security hiring takes so long
Security roles routinely take three to six months to fill, and a meaningful proportion of searches end without a hire. That is expensive in a way that is easy to miss, because the cost lands as work not done rather than as money spent.
Understanding why it takes so long makes it possible to do something about it, and some of the causes are within your control.
The structural reasons
The experienced middle is thin. There are plenty of people entering security and a reasonable number of very senior practitioners. The band in between (five to ten years, capable of working independently, not yet expecting a leadership role) is where most demand sits and where supply is tightest.
Certification does not equal capability. The volume of certified candidates has grown considerably. The number who have run something in production, been on call for it, and made a bad decision and lived with the consequences has grown more slowly. Screening for the difference takes time.
Good candidates are rarely looking. People doing interesting security work in a functional team are not on job boards. Reaching them requires networks and outbound effort rather than advertising.
Notice periods are long. Two to three months is normal in India for experienced roles. A candidate accepted in March may start in June, and a counter-offer can arrive at any point in between.
The reasons that are your own doing
These are more actionable, and they account for more of the delay than most organisations acknowledge.
The job description asks for a team
A common posting wants someone who will run the SIEM, do incident response, manage vulnerabilities, handle compliance and audits, run awareness training, and advise on architecture. That is three or four distinct roles, and the people who can genuinely do all of them are at a level and price the posting does not reflect.
The effect is that strong candidates for the role you actually need most self-select out, because they read the list and conclude they are not qualified.
What helps: decide which two things matter most in the first year, write the role around those, and be explicit that the rest is shared or outsourced.
Requirements that are not requirements
Long lists of specific tools, a fixed number of years, and a degree requirement each remove candidates without improving the shortlist. Tool experience transfers between comparable products in weeks. Years of experience correlate weakly with capability.
What helps: separate genuine requirements from preferences, and keep the required list to three or four items.
The process takes too long
Five rounds over six weeks loses candidates. Security professionals in demand are usually running more than one process, and the slowest one loses regardless of how attractive the role is.
Delays between rounds are more damaging than the number of rounds. A week of silence after a good interview is read as disinterest.
What helps: three or four stages, scheduled close together, with a decision communicated within days rather than weeks.
Interviewing for trivia
Asking for port numbers, protocol details or the definition of a framework tests recall, not judgement. It also filters for people who prepare for interviews rather than people who are good at the work.
What helps: give a realistic scenario and discuss it. "Here is an alert and this is what we can see. Walk me through what you would do and what you would want to know." This surfaces reasoning, prioritisation and the ability to explain, all of which matter daily.
Compensation set from a stale benchmark
Security salaries have moved faster than general IT compensation. Bands set from data a year or two old sit below the market, and the search stalls without anyone identifying why.
What helps: check the band against current offers before opening the search, not after three months of no acceptances.
What to do while the search runs
The work does not pause. Three options, each suiting a different situation.
Cover the continuous functions with a managed service. Monitoring, alert triage and out-of-hours coverage do not wait for a hire, and they are the functions where a gap is most exposed.
Bring in contract capacity for the specific work. A specialist for the project that is stalled, without waiting for a permanent hire who may not be the right person for that project anyway.
Develop someone internal. The most underused option. Infrastructure and platform engineers frequently make strong security engineers, they already know your environment, and internal moves take weeks rather than months. The constraint is usually that nobody has offered.
That last point deserves emphasis. An internal candidate with three years of your estate in their head and a gap in security knowledge is often a faster route to capability than an external hire with security knowledge and no context, because environment knowledge is the slower of the two to acquire.
Retention is the cheaper problem
A search you do not have to run is the fastest one. Security professionals tend to leave for reasons that are consistent and largely addressable: no path to progression, being permanently reactive with no time for improvement work, being held accountable for risk without authority to change anything, and on-call arrangements that are unsustainable.
None of those are compensation problems, and all of them are cheaper to fix than a six-month vacancy.
Want this looked at in your own environment?
Talk to an expert →

