For years, the cybersecurity industry has blamed its hiring struggles on a skills shortage. Organizations complain they can't find qualified people. Candidates complain they can't get interviews. Recruiters complain every job seems impossible to fill.
According to Deidre Diamond, founder and CEO of CyberSN, everyone is looking at the wrong problem.
During a recent episode of the CYBR.SEC.CAST podcast, Diamond argued that cybersecurity's hiring system has been fundamentally broken for years, not because there aren't enough practitioners, but because employers continue to describe jobs in ways that make good matches nearly impossible.
Full episode and related article:


"The job searching and matching system has been broken well before all these recent challenges," Diamond said. "We can only do so much with poor content. AI still matches garbage content to garbage content and creates garbage."
That observation cuts through much of today's hype around AI-powered recruiting. While vendors promise that artificial intelligence will revolutionize hiring, Diamond says the technology is only as good as the information organizations feed into it.
The problem starts with job titles
Ask a hiring manager what they're looking for, and the answer is often deceptively simple.
"We need a security engineer."
"We need a security analyst."
"We need a cloud architect."
Those titles sound straightforward, but Diamond says they hide enormous complexity.
A security engineer at one organization may spend most of the day building cloud infrastructure. At another company, the same title might focus on endpoint security, vulnerability management, DevSecOps or identity. The title alone says almost nothing about the actual work.
"Security engineer... it could be 10 to 20 different types of profiles," she explained.
Instead of describing responsibilities, organizations often build job postings around an idealized candidate, a certain number of years of experience, a list of technologies and a collection of certifications. The result is a document that describes a person instead of the work that needs to be accomplished.
That disconnect ripples throughout the hiring process.
Recruiters search for the wrong candidates. AI matches the wrong resumes. Hiring managers interview people who were never good fits to begin with.
Related:


A better way to define cybersecurity work
CyberSN has spent years developing a cybersecurity job taxonomy designed to solve that problem.
Rather than beginning with titles, the taxonomy breaks cybersecurity into dozens of functional areas, then drills into the specific tasks and projects that make up each role. Hiring managers build job descriptions by selecting the work that actually needs to be performed instead of relying on generic labels.
"The job function is just the beginning," Diamond said. "Underneath the job function is all the tasks and the projects."
That approach also acknowledges a reality every security team understands: very few practitioners perform just one job.
A security architect may spend time reviewing cloud deployments, mentoring junior staff, supporting compliance initiatives and helping incident responders. A SOC analyst may split time between threat hunting, engineering work and automation projects.
Traditional job descriptions rarely capture that complexity.
AI won't solve bad inputs
Diamond isn't dismissing AI. She's questioning the industry's expectation that AI can rescue a fundamentally flawed process.
Whether the technology relies on keyword searches, machine learning or large language models, the underlying challenge remains the same. If organizations describe jobs poorly and candidates describe themselves inconsistently, automation simply scales those mistakes.
It's the classic "garbage in, garbage out" problem.
That also helps explain why so many experienced cybersecurity professionals report submitting hundreds of applications with little response despite an industry that insists it desperately needs talent.
The matching process itself remains unreliable.
A document that should never be static
Diamond believes organizations should think about job descriptions differently.
Instead of treating them as administrative paperwork created once during a hiring cycle, they should become living operational documents that describe the capabilities an organization actually possesses.
As AI agents, contractors, consultants and managed service providers increasingly become part of the cybersecurity workforce, understanding who—or what—is performing each function becomes even more important.
"The job description is... the source of truth," Diamond said. "It should be a living, breathing document."
If she's right, cybersecurity's hiring challenges won't be solved simply by adding more AI.
They'll be solved when organizations finally become precise about the work they actually need people to do.



