CISSP appears in 5.7% of them. Python appears in 53.3%.
51 companies · collected 2026-08-29 · method and limits below
We pulled every open posting from 51 companies' public job boards, kept the 212 whose title names a cybersecurity role, and counted how many mention each of 41 terms at least once.
The ± figure is a 95% confidence interval. At 212 postings, a reading of 30% means the true rate is roughly 23–37% — so trust the ordering, not small gaps.
Share of the 212 postings mentioning each term.
01Python
53.3% ±6.7
02AWS
46.7% ±6.7
03incident response
37.7% ±6.5
04threat modeling
34.9% ±6.4
05GCP / Google Cloud
34% ±6.4
06Go
30.7% ±6.2
07SIEM
26.9% ±6
08IAM / identity
24.1% ±5.8
09Kubernetes
23.1% ±5.7
10Azure
21.7% ±5.5
11vulnerability management
19.8% ±5.4
12EDR / XDR
19.3% ±5.3
13penetration testing
19.3% ±5.3
14detection engineering
19.3% ±5.3
15on-call
18.9% ±5.3
Certifications barely appear. CISSP is named in 5.7% of these postings, OSCP in 5.7%, Security+ in 2.4%, CISM in 2.8% and CEH in 0.9% — that last one in 2 postings out of 212. An entire training industry is built on credentials that this segment of the market almost never asks for by name.
They ask you to code instead. Python appears in 53.3% of postings and Go in 30.7% — Python alone in about 9 times as many postings as CISSP. Security work at these companies is engineering work, and a resume built around certifications rather than shipped code is answering a question they did not ask.
Cloud is the platform, not a specialty. AWS is in 46.7%, GCP in 34%, Azure in 21.7%. Naming the specific cloud you have secured matters more than the generic phrase “cloud security,” because that is the term recruiters search on.
Named frameworks are rarer than you would expect. SOC 2 and ISO 27001 sit at 10.8% each, NIST at 8.5%, and MITRE ATT&CK leads them all at 10.8%. Compliance vocabulary is worth including when you have it, but it is not what most of these roles are screening for.
This finding has a hard boundary, and it matters more here than anywhere else on this page.
These are 51 technology companies hiring through modern applicant tracking systems. Government agencies, defense contractors, and the firms that serve them are not in this sample — and that is exactly where security certifications are frequently mandatory rather than optional. US Department of Defense roles have long carried explicit certification requirements for security positions, and banking, healthcare and consulting each have their own conventions.
So the honest reading is narrow: if you are targeting security roles at technology companies, your resume should lead with the systems you have secured and the code you have written, not the credentials after your name. If you are targeting the public sector or a regulated industry, this data says nothing about you.
| Term | Postings | Share | ±95% CI |
|---|---|---|---|
| CISSP | 12 | 5.7% | ±3.1 |
| OSCP | 12 | 5.7% | ±3.1 |
| CISM | 6 | 2.8% | ±2.2 |
| Security+ | 5 | 2.4% | ±2.1 |
| GIAC / SANS | 5 | 2.4% | ±2.1 |
| CEH | 2 | 0.9% | ±1.3 |
| Term | Postings | Share | ±95% CI |
|---|---|---|---|
| incident response | 80 | 37.7% | ±6.5 |
| threat modeling | 74 | 34.9% | ±6.4 |
| IAM / identity | 51 | 24.1% | ±5.8 |
| vulnerability management | 42 | 19.8% | ±5.4 |
| penetration testing | 41 | 19.3% | ±5.3 |
| detection engineering | 41 | 19.3% | ±5.3 |
| on-call | 40 | 18.9% | ±5.3 |
| cryptography | 29 | 13.7% | ±4.6 |
| secure code review | 26 | 12.3% | ±4.4 |
| red team | 24 | 11.3% | ±4.3 |
| zero trust | 22 | 10.4% | ±4.1 |
| Term | Postings | Share | ±95% CI |
|---|---|---|---|
| AWS | 99 | 46.7% | ±6.7 |
| GCP / Google Cloud | 72 | 34% | ±6.4 |
| Kubernetes | 49 | 23.1% | ±5.7 |
| Azure | 46 | 21.7% | ±5.5 |
| Terraform | 36 | 17% | ±5.1 |
| Linux | 25 | 11.8% | ±4.3 |
| Term | Postings | Share | ±95% CI |
|---|---|---|---|
| SIEM | 57 | 26.9% | ±6 |
| EDR / XDR | 41 | 19.3% | ±5.3 |
| SAST / DAST | 24 | 11.3% | ±4.3 |
| Splunk | 14 | 6.6% | ±3.3 |
| vulnerability scanning | 9 | 4.2% | ±2.7 |
| Burp Suite | 5 | 2.4% | ±2.1 |
| Term | Postings | Share | ±95% CI |
|---|---|---|---|
| SOC 2 | 23 | 10.8% | ±4.2 |
| MITRE ATT&CK | 23 | 10.8% | ±4.2 |
| ISO 27001 | 20 | 9.4% | ±3.9 |
| NIST | 18 | 8.5% | ±3.8 |
| FedRAMP | 13 | 6.1% | ±3.2 |
| GDPR | 10 | 4.7% | ±2.8 |
| PCI DSS | 7 | 3.3% | ±2.4 |
| HIPAA | 2 | 0.9% | ±1.3 |
| Term | Postings | Share | ±95% CI |
|---|---|---|---|
| Python | 113 | 53.3% | ±6.7 |
| Go | 65 | 30.7% | ±6.2 |
| Bash / shell | 12 | 5.7% | ±3.1 |
Source. The Greenhouse job board API, which companies expose so their listings can be embedded on their own sites. No scraping, no private data. Any figure here can be re-derived from that endpoint; the collector and analyzer are in the repository.
Selection. Titles naming a cybersecurity role — security engineer, application or product security, detection, incident response, red team, threat intelligence, appsec and related. Physical security roles are explicitly excluded: “Lead Physical Security Engineer” matches the same words and is a different profession.
Deduplication. The same role posted to several offices returns several near-identical records, so postings are deduped on company, normalized title and content length — the same rule used in the engineering and accounting studies.
Counting. Document frequency — the share of postings mentioning a term at least once, not how often it appears. Ambiguous words are matched case-sensitively with exclusions, because a bare match on “Go” also catches “go to market.”
Limits. 212 postings gives margins of error between ±5 and ±8 points, shown against every figure. Terms outside the 41-term list are uncounted, so absence here is not evidence of absence. And as above: technology companies only.
affirm · anaplan · anthropic · asana · bitgo · braze · brex · chime · cloudflare · coinbase · databricks · datadog · discord · elastic · faire · figma · flexport · gemini · gitlab · gusto · gympass · hellofresh · instacart · intercom · justworks · klaviyo · launchdarkly · lyft · mixpanel · mongodb · okta · oscar · peloton · pinterest · postman · reddit · ridgeline · ripple · robinhood · samsara · smartsheet · sofi · squarespace · stripe · tide · tripadvisor · twilio · vercel · verkada · zocdoc · zscaler
Paste your resume and a specific posting — the checker names the terms that posting uses and yours does not.
Check My Resume →Or read the cybersecurity keyword guide · the same study for engineers · for accountants · for marketing