Cybersecurity Talent Needs to Understand How Things Get Built
The security team can’t inspect every finished product at the door. More cyber professionals need to understand what happens on the assembly line.

For years, cybersecurity careers have often been imagined around defense: monitor systems, detect suspicious activity, investigate incidents and fix vulnerabilities.
That work remains essential. But security is increasingly moving upstream.
ENISA’s current revision of the European Cybersecurity Skills Framework is explicitly aligning cybersecurity roles with the secure digital product lifecycle, emerging technologies such as AI and new regulatory requirements. The framework itself maps cybersecurity into 12 professional profiles with defined responsibilities, knowledge and competencies.
NIST has made an equally telling change. Version 2.2.0 of the NICE Framework Components added Cybersecurity Supply Chain Risk Management as a work role and DevSecOps as a competency area.
Those aren’t cosmetic additions. They reflect where cybersecurity work is going.
Security Is Becoming Part of the Build Process
Modern digital services rarely come from one neat stack of code written entirely inside one organization. They may depend on cloud infrastructure, open-source packages, APIs, external services, automated development pipelines and software supplied by third parties.
Every dependency creates another place where security decisions can be made well or badly.
That means cyber professionals increasingly benefit from understanding questions such as:
- Where do software dependencies come from and how are they verified?
- How are secrets and credentials handled during development?
- Can security testing become part of the development pipeline?
- What happens when a third-party component develops a vulnerability?
- Who owns the risk when several suppliers contribute to one digital service?
These questions sit somewhere between traditional security, software engineering, cloud operations and risk management. Job descriptions, as usual, have failed to respect departmental boundaries.
DevSecOps Changes What “Cyber Skills” Look Like
A SOC analyst and a DevSecOps practitioner may both work in cybersecurity, but their daily environments can look very different.
DevSecOps requires security thinking inside software delivery. A practitioner may need to understand development workflows, CI/CD pipelines, cloud configurations, automated testing and how developers actually work.
Supply chain security adds another dimension. NIST describes its new NICE work role around identifying, assessing and mitigating cybersecurity risks throughout supply chains.
For workforce development, this means cybersecurity training can’t stay isolated from the systems and processes learners will eventually protect.
Someone studying application security should see how software is assembled. Someone learning cloud security should work with configurations and deployment processes. Someone preparing for supply chain risk should understand how dependencies move through an organization.
Build It, Break It, Fix It
Practical training becomes especially useful here because the skills are procedural.
Give learners an application pipeline with an insecure dependency. Let them identify the problem, modify the process and test whether their control actually works. Introduce a cloud configuration mistake midway through deployment and see whether it gets caught before production.
The exercise becomes less about remembering security advice and more about applying it while something is being built.
That connection between technical knowledge and operational practice is central to ITSEC Cyber & AI Academy, where hands-on environments can help learners develop capabilities closer to the systems, workflows and security decisions they’ll encounter professionally.
Cybersecurity will always need people watching what comes through the door. Increasingly, it also needs people standing much closer to the factory floor.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: ENISA: European Cybersecurity Skills Framework, updated 7 September 2026 · ENISA: European Cybersecurity Skills Conference 2026 · NIST NICE Framework Components v2.2.0
.png)


