What Do Companies Expect of Entry-Level Security Hires? A Smaller Share Accepts Zero to Two Years
Abstract
US security job postings, 2024 against 2026: a smaller share accepts two years or less. Entry postings mention Python about twice as often as in 2024, and firmly require degrees more often than postings asking three years or more.
*Written entirely by agents in the Research Factory, within guardrails and controls set by our team. Figures as of 1 October 2026.
1Introduction
Among security postings that state a years-of-experience requirement, a smaller share is open to entry-level candidates, and the ones that are ask for different things. The comparison is between US-located LinkedIn security postings from spring 2024 and postings at US-headquartered companies in September 2026. Among postings stating an experience requirement, the share that accepts two years or less fell from 18% to 14%, a likely but borderline fall. Entry postings now mention Python about twice as often, and one in five expects the hire to use AI tools in their own work. In spring 2024 almost none did. Mentions of Security+ fell by 51% and of CISSP by 44%.
In 2026, entry postings require a degree with no alternative nearly twice as often as postings asking three years or more. The likely range of that gap is +8 to +27 percentage points. Security operations postings accept entry candidates more often than development and advisory postings.
2The answer at a glance
| Finding | Confidence | Representativeness |
|---|---|---|
| The share of postings stating years that accept 0 to 2 fell from 18% to 14%, a likely but borderline fall | Medium. The fall is likely but borderline. The drop shows under each of the three models and on postings of similar length, though on one model alone it is borderline. At the companies present in both years, the drop is too small to tell apart from no change. | Medium. Government, staffing and managed-security postings are under-covered in this data. |
| Entry postings mention Python about twice as often, and expect AI tool use where 2024 postings almost never did | High. Python is a literal keyword match. AI tool use counts when at least two of the three models agree, and each model alone puts it at 18% to 23% of 2026 entry postings. | Medium. |
| Mentions of Security+ in entry postings fell by 51% and of CISSP by 44% | High. Both falls are real changes: too large to be explained by which postings happened to be collected. | Medium. |
| Entry postings list a degree as a firm requirement more often than postings asking three years or more | High for 2026: the gap is clear under each of the three models. Low for any change since 2024: the change in the gap is not measurable. | Medium. |
| Security operations postings accept entry candidates more often than development and advisory postings | High. The lead is clear against both. Over offensive security it is likely but borderline. Against privacy and governance, risk and compliance (GRC) it is not measurable. | Low. One specialty, and government and managed-security operations center (SOC) postings are under-covered in this data. |
3The numbers
Share of postings, spring 2024 → September 2026. Three AI models, one of them a local model, each read every posting for its minimum years of experience and its degree requirement, and we use the answer at least two agree on. A posting is entry level when at least two of them put that minimum at 0 to 2 years. Skills and certifications count any mention in the description, not only a requirement. Whether the hire is expected to use AI tools is read by the models the same way. The last column is the range of likely values for the change, in percentage points.
| Measure | 2024 | 2026 | Change, likely range (95%), points |
|---|---|---|---|
| Accepts 0 to 2 years (of postings that state years) | 18.3% | 13.6% | −8.5 to −1.0 |
| Asks 8 years or more (of postings that state years) | 18.6% | 26.7% | +4.2 to +11.8 |
| Degree required with no alternative, all postings | 23.0% | 15.8% | −11.0 to −3.3 |
| Degree required with no alternative, postings asking 3+ years | 25.3% | 18.8% | −11.2 to −1.9 |
| Degree required with no alternative, 0 to 2-year postings | 32.4% | 36.2% | −8.3 to +15.9 (no measurable change) |
| Among 0 to 2-year postings: mentions Python | 22.7% | 46.6% | +13.4 to +34.4 |
| Expected to use AI tools | 0.7% | 20.4% | +12.8 to +28.3 |
| Mentions CTF, bug bounty, home lab or personal projects | 0.7% | 8.4% | +4.6 to +11.0 |
| Mentions Security+ | 22.7% | 11.1% | −20.1 to −3.3 |
| Mentions CISSP | 22.0% | 12.3% | −17.9 to −1.6 |
| Mentions cloud (AWS, Azure, GCP) | 25.5% | 29.5% | −6.0 to +14.0 (no measurable change) |
| Mentions a SIEM, security monitoring software (Splunk, Sentinel and similar) | 24.1% | 23.2% | −10.0 to +8.3 (no measurable change) |
Source: AKA Security analysis of 1,038 US security postings from the public LinkedIn Job Postings dataset (5 to 19 April 2024) and 4,587 postings at US-headquartered companies in AKA's job-board data (1 October 2026). 141 postings in 2024 and 431 in 2026 accept 0 to 2 years. A change in bold is a clear change.
Bars show each range of likely values against zero (dashed). Solid: the whole range is above or below zero. Grey: it ends at zero. Hollow: it includes zero.
4A smaller share of postings accepts two years or less
4.1The share accepting two years or less, 2024 and 2026
Among postings that state an experience requirement, 18.3% accepted two years or less in spring 2024 and 13.6% in September 2026. The fall is likely but borderline (likely range −8.5 to −1.0 percentage points). Postings asking eight years or more rose from 18.6% to 26.7%. Most postings state a requirement at all: 69.2% in 2026, against 74.1% in 2024.
4.2Within specialties, the drop is not measurable
If 2024 had 2026's mix of specialties, its share would be 17.0%, against the actual 18.3%. Within specialties, general security engineer and analyst roles went from 24.4% to 18.3% of postings stating years, a change too small to tell apart from no change. For detection and response (28.6% in 2024, 15.6% in 2026) the fall is likely but borderline. For application security (AppSec, 20.7% and 12.7%), GRC (18.3% and 16.1%) and infrastructure security (7.1% and 14.1%) the change is not measurable.
4.3A quarter of security operations postings accept two years or less
Security operations roles, as the job-board data tags them, are 14% of the 4,369 tagged 2026 postings and 26% of the tagged 0 to 2-year postings. Within security operations, 24.1% of postings that state years accept two or less. The other role families sit at 15.4% for GRC, 13.8% for offensive security, 15.1% for privacy, 10.1% for advisory and 10.4% for development.
Security operations' lead over development has a likely range of 7 to 22 percentage points, and over advisory 3 to 25. Over offensive security the range is 0 to 20, so the lead is likely but borderline. Against privacy (−1 to 19) and GRC (−3 to +20) the range includes zero, so there is no clear lead. Development is still the largest source of entry postings in absolute terms, at 40%. It is also 50% of all tagged postings.
5What entry postings ask for now
5.1Python and AI tools rose as certifications fell
Python appears in 46.6% of 2026 entry postings, up from 22.7%. The expectation that the hire uses AI tools in their own work went from almost nothing to 20.4%. That is about the same as the 21.1% among 2026 postings asking three years or more. Each model alone puts it at 18% to 23%. Mentions of Security+ fell from 22.7% to 11.1%, a drop of 51%, and of CISSP from 22.0% to 12.3%, a drop of 44%. Mentions of cloud (likely range −6.0 to +14.0 points) and SIEM (−10.0 to +8.3) showed no measurable change, at about a quarter of postings each.
In 2024, a Booz Allen Hamilton Cybersecurity Test Engineer posting open to under two years of experience required the "Ability to obtain DoD IAT Level II Compliant Security+ CE Certification within 120 days of start date." In 2026, FIS's Risk and Cybersecurity university programme "begins 2027 with a series of AI-Enabled Learning Sprints," and tells candidates to "Learn how to leverage AI alongside human judgment."
5.2Visible work entered the postings
Capture-the-flag (CTF) competitions, bug bounties, home labs and personal projects, work a candidate can show, appear in 8.4% of 2026 entry postings, against 0.7% in 2024. Saronic's Security Operations Analyst posting lists "Hands-on learning signals such as a home lab, CTF participation, personal detection/hunting projects, or public writeups/blogs." Hover's Security Software Engineer posting asks for "Demonstrated curiosity in security through CTF competitions, open-source contributions, or personal projects."
5.3A change in entry degree requirements is not measurable
Across all postings, requiring a degree with no alternative fell from 23.0% to 15.8%. Postings asking three years or more fell from 25.3% to 18.8%, a clear fall. For entry postings, at 32.4% and 36.2%, the change is not measurable. In 2026, an entry posting requires a degree with no alternative nearly twice as often as one asking three years or more (36.2% against 18.8%, a gap with a likely range of +8 to +27 percentage points). In 2024 the gap was 32.4% against 25.3% (likely range −2 to +16). The gap grew by +10.3 points between the two years, but the likely range of that growth is −2 to +23, so the change is not measurable.
6Where the data comes from
The 2024 postings come from the LinkedIn Job Postings dataset on Hugging Face (datastax/linkedin_job_listings [2]): US postings listed between 5 and 19 April 2024. The 2026 postings come from AKA's daily read of company job boards, limited to US-headquartered companies. Both sets are US postings, but defined differently: 2024 by where the job is, 2026 by where the company is headquartered. Both years are filtered the same way: by job title, by a local model's check that each posting is a security role, and by keeping one posting per company and title. Job aggregators, which repost other employers' jobs, are left out in both years. The 2026 postings are those open on or after 23 September 2026.
The minimum years of experience and the degree requirement were read from each posting by three models, and this piece uses the value at least two of them agree on. Postings where no two models agree on the degree are left out of the degree shares. Skills and certifications are keyword matches. Whether the posting expects the hire to use AI tools in their own work is also read by the three models, and this piece uses the answer at least two agree on.
Each likely range (95%) covers the plausible values for the change. Postings from one company tend to resemble each other, so the ranges were found by resampling whole companies, not single postings. They allow for chance in which postings were collected, but not for the two years coming from different sources, locations and seasons, so the comparison mixes change over time with differences between sources.
7How this answer was stress-tested
Tests marked "earlier run" used an earlier day's data and only the local model's answers. Their dates are in the changelog. The rest use the figures in this piece.
| Test | What it found |
|---|---|
| Three models on both years. Two of the models each read all 5,625 postings for minimum years and degree requirement, alongside the local model. | Those two agree on the experience band at 0.98, and each agrees with the local model at 0.91, on an agreement score (kappa) where 1 is perfect. The entry drop holds for every model: 19.1% → 13.7% and 17.8% → 13.4% (likely but borderline) for the two, and 22.0% → 15.2% for the local model. |
| Degree label recall. The local model's degree answer was checked against the other two. | The other two agree at 0.97 on degree requirements, and the local model agrees with each at 0.79 and 0.78. The local model caught 74% of the firm degree requirements that both of the other two found. On its own labels, 25% of 2026 entry postings require a degree with no alternative, against 36% when at least two models agree. Every model shows entry postings requiring degrees more than postings asking three years or more in 2026. |
| The 2024 degree pattern. Degree requirements in entry postings against postings asking three years or more, 2024. | The local model alone had shown no 2024 gap (25% against 20%) and called the 2026 gap new. The three-model majority finds a 2024 gap of 32.4% against 25.3%. The change in the gap between years is not measurable (likely range −2 to +23 points), and this piece reports no trend in it. |
| Specialty mix. 2024 recalculated as if it had 2026's mix of specialties. | 17.0%, against the actual 18.3%. |
| Same companies. The 74 companies in both years. | 20.8% → 13.3% of postings stating years accept 0 to 2, a change too small to tell apart from no change. |
| Description length. Postings of 3,000 to 6,000 characters in both years. | 22.3% → 15.7%. |
| New postings only. 2026 postings first published in the 30 days before the figures date. | 16.0%, against 18.3% for all 2024 postings. The 2024 set has no matching restriction. |
| Non-technology industries. 2026 postings outside technology companies. | 17.5% accept 0 to 2 years, against 21.0% for all 2024 postings on the same local labels. The 2024 set has no matching restriction. (earlier run) |
| Title markers. Titles carrying junior, associate, new grad, "I" or tier 1. | 2.8% of 2026 security postings at companies headquartered in any country, not only the US-headquartered set used elsewhere, carry an entry marker in the title. Most postings at US-headquartered companies that accept 0 to 2 years carry none. |
| A fresh run on 28 September. The full pipeline rebuilt from that day's data. | On the local model's labels, 2024 was unchanged and the 2026 share moved by less than half a point with 110 more postings. (earlier run) |
8What would strengthen this answer
| Test | What it would settle | Why it has not run |
|---|---|---|
| Government, managed-security and staffing postings | The SOC and entry shares across postings under-covered in this data | USAJobs and staffing boards are not in the collection yet. |
| A second LinkedIn sample from 2026, collected the way the 2024 one was | Removes the two-source question | LinkedIn restricts automated collection. Buying a comparable feed is the realistic route. |
| Licensed postings data spanning years (Lightcast, Revelio Labs, Indeed Hiring Lab) | Year-by-year entry shares from 2019, with seasonal patterns | Paid data. |
| A re-read of our own data in three to six months | A direct trend under stable collection | Collection widened on 18 September and 22 September. The earliest read on stable collection is late December 2026. |
| Hires, not postings | Whether fewer entry postings means fewer entry hires, or hiring through internships and programmes that never post publicly | Hiring outcomes are not visible in postings. |
Acknowledgements
Question asked by Lenny Zeltser.
References
- [1]AKA Security Research Factory. Security Hiring Research: What Job Postings Say About Security Work. AKA Security, 2026. akasecurity.io/research/security-hiring-research
- [2]DataStax. LinkedIn Job Postings (datastax/linkedin_job_listings). Hugging Face dataset, 2024. huggingface.co/datasets/datastax/linkedin_job_listings
Cite as
@techreport{aka-rz-2026-03,
title = {What Do Companies Expect of Entry-Level Security Hires? A Smaller Share Accepts Zero to Two Years},
author = {{AKA Security Research Factory}},
institution = {AKA Security},
type = {Research report},
number = {AKA-RZ:2610.03v1},
version = {1.0.0},
year = {2026},
month = oct,
url = {https://akasecurity.io/research/entry-level-security-hiring}
}