Logo
Cybersecurity

Your Cybersecurity Skills Gap Might Be a Job Design Problem

If one vacancy asks for incident response, cloud architecture, penetration testing, compliance and threat intelligence, finding the right candidate may not be the real problem.

ITSEC AsiaITSEC Asia
|
Sep 22, 2026
Your Cybersecurity Skills Gap Might Be a Job Design Problem

Cybersecurity job descriptions can become ambitious documents.

An organization needs someone who understands cloud security, investigates incidents, tests applications, manages risk, explains regulations, tunes security tools and perhaps briefs senior management when something goes wrong.

Five years of experience preferred.

The candidate sounds excellent. Finding this person may take a while.

ENISA’s European Cybersecurity Skills Framework offers a useful reminder that cybersecurity isn’t one profession wearing several different badges. The framework separates the field into 12 professional profiles, including Cyber Incident Responder, Cybersecurity Architect, Penetration Tester, Cybersecurity Risk Manager, Digital Forensics Investigator and Cyber Threat Intelligence Specialist.

Each profile has different tasks, knowledge and competencies. They also depend on one another.

That changes how organizations should think about a “skills shortage.”

Check the Job Before Blaming the Talent Pool

Some roles will naturally overlap, particularly in smaller teams. ENISA’s own user manual treats the framework as flexible and shows how organizations can combine responsibilities according to their circumstances.

The problem starts when overlap becomes accumulation.

A useful workforce review can ask:

  • Which tasks genuinely need to sit with this role?
  • Which capabilities belong elsewhere in the team?
  • Which skills are essential on day one and which can be developed?
  • Where does this person depend on an architect, responder, tester or risk specialist?
  • Are we hiring one role or quietly describing three?

That last question can save a surprising amount of recruitment time.

Cybersecurity Works as a System of Roles

ENISA places its 12 profiles across a management cycle covering planning, implementation, operations and improvement. Strategy, architecture and risk sit around planning. Implementation and education turn plans into capability. Incident response, forensics and threat intelligence support operations. Penetration testing, research and audit help organizations find weaknesses and improve.

The model makes interdependency visible.

A penetration tester can find a weakness, but someone must decide how it affects risk. An architect may redesign the control. An implementer has to deploy the change. Later, an auditor may need to verify that it works.

Expecting one person to perform every step doesn’t necessarily create an efficient team. Sometimes it creates a very long Tuesday.

Training Gets Better When Roles Get Clearer

Clearer role design also makes development more precise.

Instead of sending the entire security function through the same curriculum, organizations can map training to actual responsibilities. Incident responders can practise investigation and containment. Penetration testers can deepen application, API and infrastructure testing. Architects can work through secure design decisions. Risk professionals can practise translating technical findings into business consequences.

ENISA says the ECSF is intended to help HR teams and non-specialists with resource planning, recruitment and career development, while also helping training providers connect learning with workplace requirements.

That same principle fits practical learning at ITSEC Cyber & AI Academy. Hands-on development becomes more useful when the target capability is defined first, then practised through scenarios relevant to the participant’s role.

Cybersecurity still needs more skilled people.

It could also use fewer vacancies looking for one person who apparently contains an entire security department.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ENISA: European Cybersecurity Skills Framework, updated 21 September 2026 · ENISA: ECSF Role Profiles · ENISA: ECSF User Manual

Share this post

You may also like

Human + AI: Why the Future of Offensive Security Isn't Human vs Machine
Cybersecurity

Human + AI: Why the Future of Offensive Security Isn't Human vs Machine

Artificial intelligence is transforming cybersecurity. From threat detection and vulnerability management to attack simulations and security operations, AI is enabling organizations to process information faster and automate tasks that once required significant manual effort. As AI adoption accelerates, a common question continues to emerge: Will AI replace cybersecurity professionals? The short answer is no. In reality, the future of offensive security is not about humans competing against machines. It is about combining the strengths of both to create a more effective and sustainable approach to cybersecurity. WHY OFFENSIVE SECURITY IS BECOMING MORE CHALLENGING Modern environments are more complex than ever. Organizations are embracing cloud computing, APIs, remote work and AI-driven applications. At the same time, threat actors are leveraging automation and AI to identify and exploit vulnerabilities faster. Security teams face several challenges: * Expanding attack surfaces. * Increasing volumes of vulnerabilities. * Limited cybersecurity resources. * Alert fatigue. * Time-consuming manual processes. * Growing compliance requirements. As environments continue to evolve, relying exclusively on traditional approaches becomes increasingly difficult. This is where

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 4 minutes read
Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside
Cybersecurity

Why Threat Hunting Is the Only Way to Stop Attackers Who Are Already Inside

INTRODUCTION Here is a question every security leader should sit with: if an attacker entered your network six months ago, would you know? According to IBM's Cost of a Data Breach Report 2024, the average time to identify a breach now stands at 194 days, nearly half a year of undetected attacker activity operating freely within enterprise infrastructure. Prevention tools, no matter how sophisticated, have already demonstrated they cannot close that window on their own. Firewalls, antivirus software, and multi-factor authentication are necessary. They are not sufficient. The organizations that understand this distinction are the ones investing in threat hunting: the proactive, intelligence-driven practice of searching for adversaries who have already bypassed the perimeter and are operating in silence. ITSEC Asia, the cybersecurity leader in Indonesia with operations across Singapore, Australia, and the UAE, works with organizations across these regions to build this exact capability before the next breach makes it urgent. Sources: IBM Cost of a Data Breach Report 2024 [https://www.ibm.com/reports/data-breach] THE GAP THAT REACTIVE SECURITY CANNOT CLOSE The fundamental flaw in

|
Mei 12, 2026 5 minutes read
What Is Cloud Security? A First Introduction for Modern Enterprises
Cybersecurity

What Is Cloud Security? A First Introduction for Modern Enterprises

INTRODUCTION: CLOUD ADOPTION IS ACCELERATING, SO ARE THE RISKS Cloud computing has been part of enterprise IT for years, but the risk landscape around it is changing faster than ever. As organizations embrace AI, remote work, and digital transformation, cloud environments have become the backbone of business operations and a prime target for attackers. Today, breaches are no longer limited to traditional data centers. Misconfigured cloud resources, stolen credentials, and unmanaged identities are now among the most common root causes of security incidents. This is why understanding what cloud security is and what it is not matters deeply for enterprises today. At its core, cloud security refers to the policies, technologies, configurations, and responsibilities that protect cloud-based systems, data, and services. This concept is inseparable from how cloud computing itself is defined:an on demand, shared,and externally managed computing model, as outlined in the NIST [https://csrc.nist.gov/pubs/sp/800/145/final]Cloud Computing Definition (SP 800-145), where responsibility is inherently distributed between the provider and the user. WHAT IS CLOUD COMPUTING? A SIMPLE ENTERPRISE PERSPECTIVE Cloud computing is not

ITSEC AsiaITSEC Asia
|
Feb 12, 2026 7 minutes read

Receive weekly
updates on new posts

Subscribe