Are Security Specialties Turning Into Engineering Jobs? Detection, Identity and General Security Roles Are
Abstract
US security job postings, spring 2024 against 2026: detection and response, identity and general security roles moved toward engineering. GRC picked up automation without becoming a coding job. Privacy shows no measurable move toward engineering.
*Written entirely by agents in the Research Factory, within guardrails and controls set by our team. Figures as of 1 October 2026.
1Introduction
Most of them are. Comparing US security job postings from spring 2024 with postings at US-headquartered companies in September 2026, the analyst specialties (detection and response, vulnerability management, identity, threat intelligence) moved toward engineering. GRC (governance, risk and compliance) picked up automation without becoming a coding job. AppSec (application security) and cloud security were engineering jobs already. In architecture, a change in decision work is not measurable, and privacy moved toward governance instead. Each change we report comes with a range of likely values. If that range includes zero, we can't tell the change from no change.
Across all security postings, asks for a programming language rose from 22% to 43%. The 2026 postings lean more senior. If 2026 had the same mix of seniority levels as 2024, the 2026 share would be 42%. The rise holds within each individual contributor and manager level.
In detection and response, asks for a programming language rose more than asks to write code or do software engineering. And a change in the amount of hands-on work is not measurable. What changed is the kind of work the postings describe.
2The answer at a glance
| Finding | Confidence | Representativeness |
|---|---|---|
| Postings asking for a programming language rose from 22% to 43% | Medium. A clear rise (likely range +17 to +26 percentage points). It stays clear without staffing firms and government contractors in either year, and on postings of similar length. At the same companies in both years, there is no clear change (−4 to +22). With the 2024 mix of seniority levels, the 2026 share is 42%. | Medium. 1,038 postings in 2024 and 4,587 in 2026, from two collection methods. |
| Detection and response, identity and the general security role moved toward engineering | High for detection and response. Its rises are clear, and they hold at the same companies (the language rise only just) and outside technology companies. Medium for identity and the general role, which show no clear change at the same companies. | Medium. Two collection methods, US only, technology-leaning in 2026. |
| Threat intelligence moved the same way, and vulnerability management probably did, but only just | Medium on direction, Low on size. 22 and 13 postings in 2024. For vulnerability management engineer titles, the likely range reaches just past no change (−1 to +44). | Medium. |
| GRC automated without becoming a coding job | High for the engineer title (4% → 24%), a clear rise. Medium for automation, which shows no clear change at the same companies. | Medium. At the same companies, the change in automation asks is too small to tell apart from no change. |
| AppSec and cloud security were already engineering jobs. AppSec's change is AI | High for AI, a clear rise. Low for AppSec titles and certifications and for cloud engineer titles, which show no clear change. | Medium. |
| Architecture postings naming a programming language went from 10% to 25%. A change in decision work is not measurable | Medium for language asks, which show no clear change outside technology companies. Low for the decision role, which shows no clear change on the answer at least two of three AI models agree on (−1 to +24). | Low. Part of the move is technology-company mix. |
| A move toward engineering in privacy is not measurable. It moved toward decision and governance work | Low on the engineering measures (20 postings in 2024). Medium on the rise in decision work, a clear rise for each of the three models on its own, but resting on 20 postings in 2024. | Low. |
| A change in the amount of hands-on work is not measurable. The kind changed | Low. For detection and response the likely range runs from −12 to +10 percentage points, reaching more than ten points below no change. Two of the models labelled all 5,625 postings in both years. The result holds for each model and for the answer at least two agree on. | Medium. |
3The numbers by specialty
Selected specialties, spring 2024 → September 2026: posting counts, then the share of each specialty's postings. "Engineer title" means the title contains engineer or developer. Leadership, program, offensive, AI security and infrastructure postings make up the rest of the totals.
| Specialty | Postings, 2024 → 2026 | Engineer title | Asks for a programming language | Asks for automation | Names a certification |
|---|---|---|---|---|---|
| Detection and response | 74 → 484 | 19% → 50% | 18% → 48% | 42% → 67% | 51% → 34% |
| Vulnerability management | 22 → 86 | 27% → 50% | 23% → 44% | 32% → 71% | 36% → 50% |
| Identity and access (IAM) | 64 → 148 | 41% → 65% | 30% → 45% | 33% → 71% | 13% → 35% |
| Threat intelligence | 13 → 58 | 0% → 34% | 0% → 38% | 23% → 66% | 23% → 19% |
| General security analyst or engineer | 340 → 1,128 | 42% → 61% | 21% → 41% | 26% → 53% | 40% → 32% |
| GRC | 137 → 309 | 4% → 24% | 3% → 15% | 18% → 47% | 68% → 52% |
| AppSec and product security | 85 → 730 | 81% → 87% | 62% → 64% | 59% → 63% | 28% → 19% |
| Cloud security | 31 → 173 | 68% → 78% | 35% → 52% | 45% → 75% | 19% → 30% |
| Architecture | 81 → 232 | 2% → 13% | 10% → 25% | 21% → 44% | 41% → 48% |
| Privacy | 20 → 101 | 25% → 45% | 40% → 25% | 55% → 35% | 20% → 16% |
Source: AKA Security analysis of 1,038 US security postings from the public LinkedIn Job Postings dataset (5 to 19 April 2024) and 4,587 postings at US-headquartered companies in AKA's job-board data (1 October 2026).
4Programming language asks by level
| Level | Postings, 2024 → 2026 | Share of postings, 2024 → 2026 | Asks for a programming language, 2024 → 2026 | Likely range of the change (95%), percentage points |
|---|---|---|---|---|
| Executive | 39 → 245 | 4% → 5% | 8% → 16% | −4 to +18 |
| Manager | 80 → 310 | 8% → 7% | 9% → 20% | +3 to +20 |
| Senior individual contributor | 274 → 2,146 | 26% → 47% | 27% → 50% | +17 to +30 |
| Individual contributor | 645 → 1,886 | 62% → 41% | 22% → 43% | +15 to +26 |
Source: AKA Security analysis, same postings. Senior individual contributors went from 26% to 47% of postings. If 2026 had 2024's mix of levels, the 2026 share asking for a language would be 42% rather than 43%, so the shift in levels accounts for a small part of the rise. The executive change is too small to tell apart from no change.
Bars show each range of likely values against zero (dashed). Solid: the whole range is above or below zero. Grey: it ends at zero. Hollow: it includes zero.
5Analyst specialty postings ask for engineering
5.1Detection and response
Detection and response has more postings than the other analyst specialties, 74 in 2024 and 484 in 2026. Engineer titles went from 19% to 50% of postings (likely range of the change: +20 to +41 percentage points) and asks for a programming language from 18% to 48% (+19 to +41). Certifications fell from 51% to 34%.
In 2024, scripting showed up as an add-on to monitoring. A Sr. SOC Analyst posting at Consumer Cellular asked the hire to "write scripts to query systems for security purposes using PowerShell or Python." In 2026, the build is the job. Roblox's Senior Security Engineer, Detection and Response, will "design and build the detections, automation and tooling that let a lean team monitor and protect players, developers, employees and the platform at global scale." Samsara's Senior Security Engineer, Threat Detection, will "advance our detection-as-code platform through version control, peer review, automated testing, CI/CD."
5.2Vulnerability management
Engineer titles rose from 27% to 50%, a likely but borderline rise (−1 to +44), and automation asks from 32% to 71%. The 2024 base is 22 postings, and the direction is surer than the size. A 2024 CrowdStrike Vulnerability Management Analyst posting listed scripting under "Bonus Points." A 2026 Danaher posting for a Lead Engineer, Vulnerability and Exposure Management, describes a hire who "engineers the scanning, ingestion, normalization, prioritization, ticketing, reporting, and automation workflows."
5.3Identity and threat intelligence
Identity postings with an engineer title went from 41% to 65%, and asks for a language from 30% to 45%, a likely but borderline rise. IAM is the one specialty with a clear rise in certification asks, from 13% to 35% (likely range +11 to +34). Threat intelligence went from no engineer titles in 2024 to 34%, on a small 2024 base of 13 postings.
5.4The general security role
The broadest bucket moved too. Among general security analyst and engineer postings, the share with an engineer title went from 42% to 61%, and asks for automation doubled, from 26% to 53%.
6The kind of hands-on work changed
2024 detection and response postings already asked the hire to do the work personally. Three AI models each read every posting in both years and labelled whether the hire mainly does the technical work, and we use the answer at least two agree on. By that answer, 76% of 2024 detection and response postings were mainly hands-on, and 74% in 2026 (likely range −12 to +10, no measurable change). AppSec went from 85% to 79% (−13 to +3), GRC from 68% to 67% (−12 to +10). The general security role went from 89% to 85%, no clear change (−8 to +1).
Two of the models agree with each other at a kappa of 0.74 on this label and 0.79 on each posting's main activity. Kappa is a standard agreement score: one is perfect agreement and zero is what chance alone would give. The local model agrees with them at 0.56 and 0.63 on hands-on work, so this section rests on the answer at least two models agree on. The result holds for each model on its own.
In detection and response, asks naming a language rose more than asks to write code or do software engineering: from 18% to 48% (+19 to +41) against 18% to 30% (+1 to +24, a likely but borderline rise). The difference between the two rises is +6 to +30 percentage points, a clear difference. The 2026 postings describe building detections, pipelines and automation, with Python scripting, SOAR (security orchestration, automation and response) playbooks and detection-as-code.
7GRC postings ask for automation, not code
GRC postings asking for automation went from 18% to 47%, and a GRC engineer title appeared, from 4% of postings to 24% (likely range +14 to +26). Coding stayed rare at 15%. Certifications fell from 68% to 52%.
Plaid's Security Engineer, GRC posting puts it directly: "Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable." Mattermost's GRC Manager posting adds: "You will do the hands-on compliance work."
8AppSec and cloud security postings already asked for engineering
AppSec postings already asked for engineering in 2024, with 81% engineer titles and 62% asking for a language. Engineer titles were 87% in 2026, a change that is not measurable (−2 to +14). Its change since is AI. Terms such as LLM (large language model), generative AI, agents and prompt injection went from no 2024 AppSec postings to 41% in 2026 (+35 to +46). Certification asks went from 28% to 19%, a drop too small to tell apart from no change (−21 to +1 percentage points). Cloud security postings asked for more automation, from 45% to 75% (+9 to +49), while the change in engineer titles, 68% to 78%, is not measurable (−7 to +29).
9More architecture postings name a programming language
25% of architecture postings name a programming language, up from 10%. Deciding is the main activity in 31% of 2026 architecture postings and 20% in 2024 (likely range −1 to +24 percentage points, no clear change). With one of those two models alone there is no clear change either (−1 to +22). With the other alone it is a likely but borderline rise (+1 to +26). In detection and response the share is 8%, and in AppSec 12%.
10Privacy postings shift toward decision work
A move toward engineering in privacy is not measurable. Asks for a programming language went from 40% to 25% and engineer titles from 25% to 45%, on a small 2024 base of 20 postings, and neither change is clear (−41 to +8 and −6 to +41). Privacy postings more often name deciding and governance duties instead. No 2024 privacy posting had deciding as its main activity. In 2026, 19% do (likely range +12 to +27). Each model on its own shows the rise: one of the two at 23% (+15 to +31), the other at 15% (+8 to +22) and the local model (+13 to +29). No 2024 privacy posting carried AI policy, risk or compliance duties, against 24% in 2026 (+16 to +33).
11Where the data comes from
This piece measures moves by specialty. For the overall split of engineering and non-engineering titles across all security postings, see How Do Engineering and Non-Engineering Titles Split Across Security Job Openings?.
The 2024 postings come from the LinkedIn Job Postings dataset on Hugging Face (datastax/linkedin_job_listings [2]): US postings listed between 5 and 19 April 2024. The 2026 postings come from AKA's daily read of company job boards, limited to US-headquartered companies. The two sets match on country but not on exact definition.
Job aggregators, which repost other employers' jobs, are left out in both years, and the 2026 postings are those open on or after 23 September 2026. Both years go through one set of rules. A posting counts when its title passes the series' security title rules, a local model rules it a security role, and it is the only posting with that title at that company. Title level, specialty and description terms follow identical rules in both years. The likely ranges are 95% ranges for the change, found by resampling whole companies many times rather than single postings.
12How this answer was stress-tested
Tests marked earlier run were run on an earlier day's data, dated in the changelog. The rest were run on the figures in this piece.
| Test | What it found |
|---|---|
| Scope check of every posting, both years. A local model read all 1,405 2024 postings and 5,196 2026 postings that pass the title rules. | It ruled 26% of 2024 postings and 12% of 2026 postings not security roles: financial auditors, physical security, alarm installers, lawyers. Removing them raised 2024 detection and response automation from 28% to 42%. |
| Population matching. Read samples from every bucket in both years. | 2024 carried guards, trades advertised "with security clearance" and psychiatric nurses. 2026 carried chip-design "SoC" titles. Both removed by title rule. (earlier run) |
| Title rules against another model. A separate AI model labelled 192 titles blind, spread across specialties and both years. | Level agreement started at a kappa of 0.94. The misses exposed a bug: "Directory Services" matched "director" and counted engineers as executives. Fixed, 0.975. Specialty agrees at 0.76. (earlier run) |
| Keyword precision. 48 keyword hits read by hand across both years. | Language asks were genuine 16 times out of 16. Automation hits were genuine 13 of 17 times in 2026 and 11 of 15 in 2024. Automation levels run about a quarter high in both years. (earlier run) |
| Description length. 2026 descriptions are 60% longer. Measures repeated on postings of 3,000 to 6,000 characters in both years. | Language asks: all postings 25% → 41% (+10 to +22), detection and response 24% → 40% (a likely but borderline rise, 0 to +32), vulnerability management 18% → 41% (no clear change, −7 to +50), architecture 3% → 30%. Same direction in all three specialties, and similar size in architecture. |
| Company mix. For the specialties, 2026 postings outside technology companies against 2024 without staffing firms and government contractors. The 2024 postings file has no industry field, so the two years are cut differently. For all postings, staffing firms and government contractors removed in both years. | All postings: language asks 22% → 44% (+18 to +27). Language asks in detection and response reach 39% among 2026 non-technology employers. Identity engineer titles reach 55%, no clear change (−6 to +30), GRC automation 41%. Architecture language asks fall to 18%, below its 25% overall, and the change from 2024 is too small to tell apart from no change (−6 to +19). |
| Same companies. 74 companies with US-headquartered postings appear in both years. | All postings: language asks 32% → 41%, no clear change (−4 to +22). Detection and response language asks 23% → 52%, a likely but borderline rise (0 to +56). Identity engineer titles 33% → 73%, no clear change (−24 to +85). GRC automation 23% → 31%, no clear change (−13 to +32). AppSec language 77% → 68%, no measurable change. General role engineer titles 48% → 50%, no clear change (−22 to +25). |
| Title level. The language share at each title level. | It rose within individual contributor, senior and manager titles. Held to the 2024 level mix, the 2026 share is 42%. |
| Two hosted models on both years. Two hosted models each read all 5,625 postings in both years for hands-on work, main activity and people management. | They agree with each other at kappa 0.74, 0.79 and 0.93. The hands-on finding held for each model separately. |
| Same labeller on both years. A local model read both years with the same instructions. | It first showed the hands-on share barely moving, which reframed the answer from "more hands-on" to "the kind of hands-on work changed". Tuning it against the other two models' labels lifted its people-management agreement from 0.69 to 0.82 on postings kept back from the tuning, but not its hands-on agreement. On 28 September it relabelled both years with the tuned prompt, and it now agrees with one of the other two models at 0.56 on hands-on work. |
| A fresh run on 28 September. The full pipeline rebuilt from that day's data. | 110 more 2026 postings than on 25 September. Every share in the specialty table moved by two points or less. With the relabelled local model, the likely range for the architecture deciding change now starts at −1, so it is too small to tell apart from no change, but only just. |
| An outside source. The SANS Institute and Anvilogic State of Detection Engineering Report 2026 [3], a practitioner survey. | It points the same way. 62% of teams keep detection rules in version control and 42% run them through CI/CD, while 13% of detection engineers report high proficiency in software engineering. That fits postings asking for detection-as-code and scripting more than software development. It measures practitioners, not job postings. |
13What would strengthen this answer
| Test | What it would settle | Why it has not run |
|---|---|---|
| A second LinkedIn sample from 2026, collected the way the 2024 one was | Removes the two-source question | LinkedIn restricts automated collection. Buying a comparable feed is the realistic route. |
| Licensed longitudinal postings (Lightcast, Revelio Labs, Indeed Hiring Lab) | Year-by-year specialty shares from 2019, with seasonality | Paid data. |
| A re-read of our own data in three to six months | A direct trend under stable collection | Collection widened on 18 and 22 September. The earliest clean read is late December 2026. |
| A practitioner read of 100 specialty postings | Whether "engineering shift" matches how a security leader reads the jobs | Needs practitioner time. |
Acknowledgements
Question asked by Jamie Dicken.
References
- [1]AKA Security Research Factory. Security Hiring Research: What Job Postings Say About Security Work. AKA Security, 2026. akasecurity.io/research/security-hiring-research
- [2]DataStax. LinkedIn Job Postings (datastax/linkedin_job_listings). Hugging Face dataset, 2024. huggingface.co/datasets/datastax/linkedin_job_listings
- [3]State of Detection Engineering Report 2026. anvilogic.com/report/state-of-detection-engineering
Cite as
@techreport{aka-rz-2026-01,
title = {Are Security Specialties Turning Into Engineering Jobs? Detection, Identity and General Security Roles Are},
author = {{AKA Security Research Factory}},
institution = {AKA Security},
type = {Research report},
number = {AKA-RZ:2610.01v1},
version = {1.0.0},
year = {2026},
month = oct,
url = {https://akasecurity.io/research/security-specialties-engineering-jobs}
}