Your Cybersecurity Skills Gap Might Be a Job Design Problem
If one vacancy asks for incident response, cloud architecture, penetration testing, compliance and threat intelligence, finding the right candidate may not be the real problem.

Cybersecurity job descriptions can become ambitious documents.
An organization needs someone who understands cloud security, investigates incidents, tests applications, manages risk, explains regulations, tunes security tools and perhaps briefs senior management when something goes wrong.
Five years of experience preferred.
The candidate sounds excellent. Finding this person may take a while.
ENISA’s European Cybersecurity Skills Framework offers a useful reminder that cybersecurity isn’t one profession wearing several different badges. The framework separates the field into 12 professional profiles, including Cyber Incident Responder, Cybersecurity Architect, Penetration Tester, Cybersecurity Risk Manager, Digital Forensics Investigator and Cyber Threat Intelligence Specialist.
Each profile has different tasks, knowledge and competencies. They also depend on one another.
That changes how organizations should think about a “skills shortage.”
Check the Job Before Blaming the Talent Pool
Some roles will naturally overlap, particularly in smaller teams. ENISA’s own user manual treats the framework as flexible and shows how organizations can combine responsibilities according to their circumstances.
The problem starts when overlap becomes accumulation.
A useful workforce review can ask:
- Which tasks genuinely need to sit with this role?
- Which capabilities belong elsewhere in the team?
- Which skills are essential on day one and which can be developed?
- Where does this person depend on an architect, responder, tester or risk specialist?
- Are we hiring one role or quietly describing three?
That last question can save a surprising amount of recruitment time.
Cybersecurity Works as a System of Roles
ENISA places its 12 profiles across a management cycle covering planning, implementation, operations and improvement. Strategy, architecture and risk sit around planning. Implementation and education turn plans into capability. Incident response, forensics and threat intelligence support operations. Penetration testing, research and audit help organizations find weaknesses and improve.
The model makes interdependency visible.
A penetration tester can find a weakness, but someone must decide how it affects risk. An architect may redesign the control. An implementer has to deploy the change. Later, an auditor may need to verify that it works.
Expecting one person to perform every step doesn’t necessarily create an efficient team. Sometimes it creates a very long Tuesday.
Training Gets Better When Roles Get Clearer
Clearer role design also makes development more precise.
Instead of sending the entire security function through the same curriculum, organizations can map training to actual responsibilities. Incident responders can practise investigation and containment. Penetration testers can deepen application, API and infrastructure testing. Architects can work through secure design decisions. Risk professionals can practise translating technical findings into business consequences.
ENISA says the ECSF is intended to help HR teams and non-specialists with resource planning, recruitment and career development, while also helping training providers connect learning with workplace requirements.
That same principle fits practical learning at ITSEC Cyber & AI Academy. Hands-on development becomes more useful when the target capability is defined first, then practised through scenarios relevant to the participant’s role.
Cybersecurity still needs more skilled people.
It could also use fewer vacancies looking for one person who apparently contains an entire security department.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: ENISA: European Cybersecurity Skills Framework, updated 21 September 2026 · ENISA: ECSF Role Profiles · ENISA: ECSF User Manual
.png)


