
Finding Cybersecurity Specialists: Guide for DACH 2026
6

Morten Laufer
Founder
The security skills shortage is not widespread: SOC Tier 1 has a selection problem, while NIS2-GRC and OT-security according to IEC 62443 have practically no open market. The most expensive mistake happens in the requirement profile — a mandatory CISSP filter requires five years of practical experience and halves the pool. Nova Search is a founder-led tech recruitment consultancy with cybersecurity as its core niche and over 1,500 pre-qualified security profiles.
In 2025, 25,839 IT security positions were advertised in Germany - with an average vacancy duration of 7.7 months for IT roles.
A rigid mandatory CISSP filter systematically excludes capable, hands-on profiles and artificially worsens the skills shortage.
NIS2 and DORA are generating massive peaks in demand: interim experts bridge the gap until permanent roles are filled.
Nova Search fills security roles from SOC to CISO from over 1,500 pre-qualified profiles — shortlist in 5 working days.
AI This article was created with the assistance of AI.
The 2026 market: where the real shortages lie - and where they don't
The diagnosis of a skilled-labour shortage in the security sector is too simplistic. In the German economy, around 109,000 IT specialists are lacking, and specifically for IT security, German companies advertised a total of 25,839 positions in 2025, up from 24,373 the previous year. In parallel, Bitkom expects spending on IT security to increase by 9.9 per cent to 12.2 billion euros in 2026. However, the market is fundamentally divided: there are segments with a pure selection problem and domains with a severe access problem.
Standard roles such as junior SOC analysts often receive dozens of applications for open vacancies. On the other hand, for specialised roles in NIS2 and DORA compliance, cloud security or OT security in accordance with IEC 62443, there is virtually no active candidate market. On average, IT positions in Germany remain vacant for 7.7 months. Anyone addressing both market segments with the same standard job advertisement is losing valuable months.
Role Family | Market Situation | Typical Vacancy Duration | Search Strategy |
|---|---|---|---|
SOC Tier 1 & 2 | High volume of applicants, highly fluctuating quality | 3 to 5 months | Structured technical pre-screening for filtering |
Incident Response & Forensics | High demand, limited senior capacity | 6 to 8 months | Active direct outreach in professional network |
Pentest & Red Team (OSCP, CREST) | Stable specialist community, price-sensitive | 5 to 7 months | Tech stack and project focus in initial contact |
Cloud & DevSecOps (Zero Trust) | Acute shortage of interface skills | 7 to 9 months | Active sourcing via architectural focus areas |
IAM & PAM (SailPoint, Okta, Keycloak) | Very tight specialist market in DACH | 6 to 8 months | Targeted outreach to experienced system engineers |
GRC & NIS2 / DORA | Extreme excess demand due to regulation | 7 to 10 months | Direct outreach and parallel interim bridging |
OT-Security / KRITIS (IEC 62443) | Virtually zero passive willingness to change jobs | 8 to 12 months | Headhunting in industrial and automation environments |
CISO & Security Leadership | Strategic key position with high responsibility | 6 to 9 months | Executive search with a focus on cultural fit |
Regulatory requirements such as NIS2 generate predictable demand peaks, as small and medium-sized enterprises in particular lack the specialised staff to implement the new requirements. DORA also demands continuous monitoring and structured processes, thereby increasing staffing requirements. If an organisation needs to submit new compliance evidence in the first quarter, recruiting must start as early as the third quarter of the previous year. With an average vacancy duration of 7.7 months for IT positions, strategic security hiring is a calendar issue and not an operational emergency.
The requirement profile that decides the search
The most expensive mistake in the entire hiring process happens before the first candidate is even contacted: in the requirement profile. Frequently, job postings demand rigid certifications such as the CISSP as a mandatory requirement. Since a CISSP requires at least five years of proven professional experience in several security domains, this filter excludes numerous highly competent engineers and analysts from the outset. A well-founded comparison between CISSP vs. CISM makes it clear that while certificates serve as proof of qualification, rigid requirements artificially shrink the already narrow candidate pool.
Crucial is a strict separation between genuine must-have criteria and desirable nice-to-have criteria. Anyone looking for a field-tested GRC manager or an ISO 27001 manager primarily needs experience in auditing, risk management and stakeholder communication. Instead of filtering CVs by formal acronyms, hiring managers should integrate concrete testing methods into the interview process.
Instead of this requirement | Test this in the interview |
|---|---|
Mandatory CISSP or CISM certification | Practical case study: How do you structure a risk analysis for a new cloud infrastructure? |
10+ years of experience across all security domains | Deep dive focus: Concrete incident handling experience and escalation paths in ransomware incidents |
Perfect knowledge of every ISO 27001 control | Comprehension check: How do you translate technical security policies for departments and management? |
Complete mastery of all IAM tools | Architectural understanding: How have you designed role models and privileged access management in hybrid environments? |
Certified OT security lead according to IEC 62443 | Practical scenario: How do you segregate IT and OT networks without risking production downtime? |
For example, if you are looking to fill an experienced CISO role, a strategic understanding of governance carries more weight than the mastery of individual SIEM tools. The requirement profile must reflect what the person is expected to achieve operationally in the first 90 days, rather than formulating a theoretical wish list.
The three paths to hiring: internal, platform, specialist
To fill critical security roles, companies in the DACH region have three main paths open to them, which differ greatly in terms of effort, lead time and probability of success:
Internal HR and career portal: Low direct costs, but binds significant internal resources. Effective for standard profiles, this approach quickly reaches its limits for bottleneck profiles such as DevSecOps or OT security due to the lack of a specialised industry network.
Generic job platforms: Generate visibility for entry-level roles, but for senior security positions often lead to high screening efforts without a precise technical fit.
Specialised recruitment consultancy: Relies on active direct search, an established professional network and technical pre-qualification. This path minimises the internal vetting effort and leads to predictable results even in hidden candidate markets.
In order to meet regulatory deadlines and cushion the months-long vacancy duration of IT positions, a hybrid approach is often recommended. Through the Freelance & Contract placements model, specialised interim CISOs or external NIS2 project leads can bridge critical gaps within a few days, while permanent recruitment for the core team is driven forward in parallel.
Process: how to get a shortlist in five business days
To solve the access problem in the cybersecurity market, the Hamburg-based recruitment consultancy Nova Search relies on a highly structured hiring process without the resume noise. Under the technical leadership of Strahinja Karanovic, who has already successfully filled over 25 key security-related positions, the team draws on a network of over 1,500 pre-qualified security profiles. The service offering in cybersecurity recruiting covers all relevant domains: from SOC, IAM/PAM (Keycloak, Okta, SailPoint) to cloud security, AppSec and DevSecOps, as well as GRC (ISO 27001, NIS2, DORA), offensive security and IEC 62443 OT security.
The recruitment process for permanent positions follows four clearly defined steps:
60-minute briefing: Precise capture of the tech stack, regulatory requirements, team culture and salary framework.
Two-stage security screening: Detailed technical deep dive combined with a structured culture-fit interview to ensure professional and interpersonal alignment.
First qualified shortlist in 5 business days: Provision of up to three vetted profiles, including a binding feedback commitment within 48 hours.
Contract sign-off with a 90-day guarantee: Should a placement end within the first three months, a replacement search is carried out free of charge.
That this targeted direct-search approach works is proven, among other things, by the placement of the Team Lead Cybersecurity & Network for avodaq AG in Hamburg. After previous internal and external attempts had failed, the demanding leadership role was filled within eight weeks. The client's conclusion: No resume noise, but a genuine understanding of the profile.
Are you facing an unfilled security vacancy or are regulatory deadlines pressing due to NIS2 and DORA? Start your briefing now and receive your qualified shortlist within 5 business days.
Further reading
Sources
FAQ
Why does it often take longer than 7.7 months to fill cybersecurity roles?
For highly specialised profiles such as cloud security, GRC or OT security in accordance with IEC 62443, there is an extreme access problem. Many companies artificially prolong vacancies with rigid certification requirements instead of assessing practical skills and experience.
How many vacant IT security positions are there in Germany?
In 2025, German companies advertised 25,839 jobs in IT security, up from 24,373 the previous year. At the same time, the general shortage of IT specialists stands at around 109,000 vacancies. Security budgets are set to rise to 12.2 billion euros in 2026, which is putting massive pressure on recruitment.
Which roles are particularly difficult to fill due to NIS2 and DORA?
The regulations are driving demand for GRC experts, CISO profiles and cybersecurity management specialists.
Are certifications such as CISSP a must in the requirement profile?
No. A rigid certificate filter often excludes capable candidates who have years of project experience. Specific technical interview questions and scenario tests are far more effective for targeting the right security specialists.
How quickly does Nova Search deliver the first cybersecurity profiles?
Nova Search delivers the first qualified shortlist within 5 working days thanks to access to over 1,500 pre-qualified profiles. Each profile undergoes a rigorous two-stage screening process consisting of an in-depth technical check and a culture interview.

