Finding Cybersecurity Specialists: Recruiting Guide for DACH

(ex: Photo by

Aditya Naidu

on

Finding Cybersecurity Specialists: Recruiting Guide for DACH

6

Morten Laufer

Founder

The cybersecurity market in 2026 is divided in two: standard roles face a selection problem, while specialised NIS2 and OT profiles face a pure access problem. This guide shows you how to optimise job profiles and fill vacancies with Nova Search in 5 days.

Topics on this page
The topic briefly and compactly
  • In 2025, 25,839 IT security positions were advertised in Germany - with an average vacancy duration of 7.7 months for IT roles.

  • A rigid CISSP mandatory filter systematically excludes capable practical profiles and artificially exacerbates the shortage of skilled workers.

  • NIS2 and DORA are generating massive peaks in demand: interim experts bridge the vacancy period until a permanent appointment is made.

  • Specialised security recruiters like Nova Search deliver custom-fit profiles within 5 working days following a two-stage screening process.

AI This article was created with the help of AI.

The 2026 market: where the shortage is real - and where it isn't

The diagnosis of a skills shortage falls short in the security sector. The German economy lacks around 109,000 IT specialists, and German companies advertised a total of 25,839 positions specifically for IT security in 2025, up from 24,373 the year before. In parallel, Bitkom expects spending on IT security to increase by 9.9 per cent to 12.2 billion euros in 2026. However, the market is fundamentally split: there are segments with a pure selection problem and domains with a serious access problem.

Standard roles such as Junior SOC Analysts often receive dozens of applications for open vacancies. In contrast, for specialised roles in NIS2 and DORA compliance, cloud security or OT security according to IEC 62443, there is virtually no active candidate market. On average, IT positions in Germany remain vacant for 7.7 months. Anyone who addresses both market segments with the same standard job advertisement loses valuable months.

Role Family

Market Situation

Typical Vacancy Duration

Search Strategy

SOC Tier 1 & 2

High volume of applicants, highly fluctuating quality

3 to 5 months

Structured technical pre-screening for filtering

Incident Response & Forensics

High demand, limited senior capacities

6 to 8 months

Active direct sourcing within the professional network

Pentest & Red Team (OSCP, CREST)

Stable community of specialists, price-sensitive

5 to 7 months

Tech stack and project focus in initial contact

Cloud & DevSecOps (Zero Trust)

Acute shortage of interface competence

7 to 9 months

Active sourcing via architecture focus areas

IAM & PAM (SailPoint, Okta, Keycloak)

Very tight specialist market in DACH

6 to 8 months

Targeted sourcing of experienced system engineers

GRC & NIS2 / DORA

Extreme excess demand due to regulation

7 to 10 months

Direct sourcing and parallel interim bridging

OT Security / Critical Infrastructure (IEC 62443)

Almost zero passive willingness to change jobs

8 to 12 months

Headhunting in industrial and automation environments

CISO & Security Leadership

Strategic key position with high responsibility

6 to 9 months

Executive search with a focus on cultural fit

Regulatory requirements such as NIS2 create predictable demand peaks, because medium-sized companies in particular lack the specialised staff to implement the new requirements. DORA also requires continuous monitoring and structured processes, thereby increasing staffing requirements. If an organisation needs to submit new compliance evidence in the first quarter, recruiting must start in the third quarter of the previous year. With an average time-to-hire of 7.7 months for IT positions, strategic security hiring is a calendar issue and not an operational emergency.

The requirement profile that decides the search

The most expensive mistake in the entire hiring process happens before the first candidate is contacted: in the requirement profile. Job advertisements often require rigid certificates such as the CISSP as a mandatory requirement. Since a CISSP requires at least five years of proven professional experience in multiple security domains, this filter excludes numerous highly competent engineers and analysts from the outset. A well-founded comparison between CISSP vs. CISM makes it clear that while certificates serve as proof of qualification, rigid requirements artificially shrink the already narrow pool of candidates.

What is crucial is a strict separation between genuine must-have criteria and desirable nice-to-have criteria. Anyone looking for a field-tested GRC Manager or an ISO 27001 Officer primarily needs experience in auditing, risk management and stakeholder communication. Instead of filtering CVs by formal abbreviations, hiring managers should integrate concrete testing methods into the interview process.

Instead of this requirement

Test this in the interview

Mandatory CISSP or CISM certificate

Practical case study: How do you structure a risk analysis for a new cloud infrastructure?

10+ years of experience in all security domains

Deep dive focus: Concrete incident handling experience and escalation paths in ransomware incidents

Perfect knowledge of every ISO 27001 control

Comprehension test: How do you translate technical security policies for business departments and management?

Complete mastery of all IAM tools

Architectural understanding: How have you designed role models and privileged access management in hybrid environments?

Certified OT Security Lead according to IEC 62443

Practical scenario: How do you segregate IT and OT networks without risking production downtime?

For example, if you want to fill an experienced CISO role, a strategic understanding of governance carries more weight than mastering individual SIEM tools. The requirement profile must reflect what the person is expected to achieve operationally in the first 90 days, rather than formulating a theoretical wish list.

The three ways to hire: internal, platform, specialist

For hiring critical security roles, companies in the DACH region have three main paths open to them, which differ greatly in terms of effort, lead time and probability of success:

  • Internal HR and career portal: Low direct costs, but binds significant internal resources. Effective for standard profiles, this approach quickly reaches its limits for bottleneck profiles such as DevSecOps or OT security due to the lack of a specialised industry network.

  • Generic job platforms: Generate visibility for entry-level roles, but often lead to high screening effort without professional fit for senior security positions.

  • Specialised recruitment consultancy: Relies on active direct sourcing, an established professional network and technical pre-qualification. This path minimises the internal screening effort and leads to predictable results even in hidden candidate markets.

To meet regulatory deadlines and cushion the months-long process of filling IT positions, a hybrid approach is often recommended. Through the Freelancer & Contract Placement model, specialised interim CISOs or external NIS2 project leads can fill critical gaps within a few days, while permanent recruitment for the core team is driven forward in parallel.

Process: how to get to a shortlist in five working days

To solve the access problem in the cybersecurity market, the Hamburg-based recruitment consultancy Nova Search relies on a highly structured recruitment process without CV noise. Under the professional leadership of Strahinja Karanovic, who has already successfully filled over 25 security-critical key positions, the team has access to a network of over 1,500 pre-qualified security profiles. The range of services in the area of Cybersecurity Recruiting covers all relevant domains: from SOC, IAM/PAM (Keycloak, Okta, SailPoint) through cloud security, AppSec and DevSecOps to GRC (ISO 27001, NIS2, DORA), offensive security and IEC 62443 OT security.

The recruitment process for permanent positions follows four clearly defined steps:

  1. 60-minute briefing: Precise recording of the tech stack, regulatory requirements, team culture and salary structure.

  2. Two-stage security screening: Detailed technical deep-dive combined with a structured culture interview to ensure technical and personal fit.

  3. First qualified shortlist in 5 working days: Provision of up to three vetted profiles including a commitment to feedback within 48 hours.

  4. Contract signing with a 90-day guarantee: If a placement ends within the first three months, a replacement will be provided free of charge.

The fact that this targeted direct search approach works is proven, among other things, by the placement of the Team Lead Cybersecurity & Network for avodaq AG in Hamburg. After previous internal and external attempts had been unsuccessful, the challenging leadership role was filled within eight weeks. The client's conclusion: No CV noise, but a real understanding of the profile.

Are you facing an unfilled security vacancy or are regulatory deadlines pressing due to NIS2 and DORA? Start your briefing now and receive your qualified shortlist within 5 working days.

Sources

FAQ

Why does it often take longer than 7.7 months to fill cybersecurity roles?

For highly specialised profiles such as cloud security, GRC or OT security in accordance with IEC 62443, there is an extreme access problem. Many companies artificially prolong vacancies with rigid certification requirements instead of assessing practical skills and experience.

How many vacant IT security positions are there in Germany?

In 2025, German companies advertised 25,839 jobs in IT security, up from 24,373 the previous year. At the same time, the general shortage of IT specialists stands at around 109,000 vacancies. Security budgets are set to rise to 12.2 billion euros in 2026, which is putting massive pressure on recruitment.

Which roles are particularly difficult to fill due to NIS2 and DORA?

The regulations are driving demand for GRC experts, CISO profiles and cybersecurity management specialists.

Are certifications such as CISSP a must in the requirement profile?

No. A rigid certificate filter often excludes capable candidates who have years of project experience. Specific technical interview questions and scenario tests are far more effective for targeting the right security specialists.

How quickly does Nova Search deliver the first cybersecurity profiles?

Nova Search delivers the first qualified shortlist within 5 working days thanks to access to over 1,500 pre-qualified profiles. Each profile undergoes a rigorous two-stage screening process consisting of an in-depth technical check and a culture interview.

Cta Image

Book your free consultation