What 212 Cybersecurity Job Postings Actually Ask For

CISSP appears in 5.7% of them. Python appears in 53.3%.

51 companies · collected 2026-08-29 · method and limits below

We pulled every open posting from 51 companies' public job boards, kept the 212 whose title names a cybersecurity role, and counted how many mention each of 41 terms at least once.

The ± figure is a 95% confidence interval. At 212 postings, a reading of 30% means the true rate is roughly 23–37% — so trust the ordering, not small gaps.

The 15 most common terms

Share of the 212 postings mentioning each term.

01Python

53.3% ±6.7

02AWS

46.7% ±6.7

03incident response

37.7% ±6.5

04threat modeling

34.9% ±6.4

05GCP / Google Cloud

34% ±6.4

06Go

30.7% ±6.2

07SIEM

26.9% ±6

08IAM / identity

24.1% ±5.8

09Kubernetes

23.1% ±5.7

10Azure

21.7% ±5.5

11vulnerability management

19.8% ±5.4

12EDR / XDR

19.3% ±5.3

13penetration testing

19.3% ±5.3

14detection engineering

19.3% ±5.3

15on-call

18.9% ±5.3

What stands out

Certifications barely appear. CISSP is named in 5.7% of these postings, OSCP in 5.7%, Security+ in 2.4%, CISM in 2.8% and CEH in 0.9% — that last one in 2 postings out of 212. An entire training industry is built on credentials that this segment of the market almost never asks for by name.

They ask you to code instead. Python appears in 53.3% of postings and Go in 30.7% — Python alone in about 9 times as many postings as CISSP. Security work at these companies is engineering work, and a resume built around certifications rather than shipped code is answering a question they did not ask.

Cloud is the platform, not a specialty. AWS is in 46.7%, GCP in 34%, Azure in 21.7%. Naming the specific cloud you have secured matters more than the generic phrase “cloud security,” because that is the term recruiters search on.

Named frameworks are rarer than you would expect. SOC 2 and ISO 27001 sit at 10.8% each, NIST at 8.5%, and MITRE ATT&CK leads them all at 10.8%. Compliance vocabulary is worth including when you have it, but it is not what most of these roles are screening for.

Before you throw away your CISSP

This finding has a hard boundary, and it matters more here than anywhere else on this page.

These are 51 technology companies hiring through modern applicant tracking systems. Government agencies, defense contractors, and the firms that serve them are not in this sample — and that is exactly where security certifications are frequently mandatory rather than optional. US Department of Defense roles have long carried explicit certification requirements for security positions, and banking, healthcare and consulting each have their own conventions.

So the honest reading is narrow: if you are targeting security roles at technology companies, your resume should lead with the systems you have secured and the code you have written, not the credentials after your name. If you are targeting the public sector or a regulated industry, this data says nothing about you.

Every term, by category

Certifications

TermPostingsShare±95% CI
CISSP125.7%±3.1
OSCP125.7%±3.1
CISM62.8%±2.2
Security+52.4%±2.1
GIAC / SANS52.4%±2.1
CEH20.9%±1.3

Practice

TermPostingsShare±95% CI
incident response8037.7%±6.5
threat modeling7434.9%±6.4
IAM / identity5124.1%±5.8
vulnerability management4219.8%±5.4
penetration testing4119.3%±5.3
detection engineering4119.3%±5.3
on-call4018.9%±5.3
cryptography2913.7%±4.6
secure code review2612.3%±4.4
red team2411.3%±4.3
zero trust2210.4%±4.1

Cloud & infra

TermPostingsShare±95% CI
AWS9946.7%±6.7
GCP / Google Cloud7234%±6.4
Kubernetes4923.1%±5.7
Azure4621.7%±5.5
Terraform3617%±5.1
Linux2511.8%±4.3

Tools

TermPostingsShare±95% CI
SIEM5726.9%±6
EDR / XDR4119.3%±5.3
SAST / DAST2411.3%±4.3
Splunk146.6%±3.3
vulnerability scanning94.2%±2.7
Burp Suite52.4%±2.1

Frameworks & compliance

TermPostingsShare±95% CI
SOC 22310.8%±4.2
MITRE ATT&CK2310.8%±4.2
ISO 27001209.4%±3.9
NIST188.5%±3.8
FedRAMP136.1%±3.2
GDPR104.7%±2.8
PCI DSS73.3%±2.4
HIPAA20.9%±1.3

Languages

TermPostingsShare±95% CI
Python11353.3%±6.7
Go6530.7%±6.2
Bash / shell125.7%±3.1

Method

Source. The Greenhouse job board API, which companies expose so their listings can be embedded on their own sites. No scraping, no private data. Any figure here can be re-derived from that endpoint; the collector and analyzer are in the repository.

Selection. Titles naming a cybersecurity role — security engineer, application or product security, detection, incident response, red team, threat intelligence, appsec and related. Physical security roles are explicitly excluded: “Lead Physical Security Engineer” matches the same words and is a different profession.

Deduplication. The same role posted to several offices returns several near-identical records, so postings are deduped on company, normalized title and content length — the same rule used in the engineering and accounting studies.

Counting. Document frequency — the share of postings mentioning a term at least once, not how often it appears. Ambiguous words are matched case-sensitively with exclusions, because a bare match on “Go” also catches “go to market.”

Limits. 212 postings gives margins of error between ±5 and ±8 points, shown against every figure. Terms outside the 41-term list are uncounted, so absence here is not evidence of absence. And as above: technology companies only.

Companies included

affirm · anaplan · anthropic · asana · bitgo · braze · brex · chime · cloudflare · coinbase · databricks · datadog · discord · elastic · faire · figma · flexport · gemini · gitlab · gusto · gympass · hellofresh · instacart · intercom · justworks · klaviyo · launchdarkly · lyft · mixpanel · mongodb · okta · oscar · peloton · pinterest · postman · reddit · ridgeline · ripple · robinhood · samsara · smartsheet · sofi · squarespace · stripe · tide · tripadvisor · twilio · vercel · verkada · zocdoc · zscaler

See which of these your resume is missing

Paste your resume and a specific posting — the checker names the terms that posting uses and yours does not.

Check My Resume →

Or read the cybersecurity keyword guide · the same study for engineers · for accountants · for marketing

What 212 Cybersecurity Job Postings Actually Ask For