GCS Talent Briefing
Careers & Hiring

The Advert Demands a Degree. The Hiring Manager Does Not.

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
17 September 2026 · 7 min read
GCS Talent Briefing cover: The Advert Demands A Degree, The Hiring Manager Does Not. Dark brand panel with the headline in white and red, a standfirst noting that DSIT analysed 32,370 UK core cyber job postings while ISC2 asked 929 hiring managers what they would actually accept, and four stat chips: 81% of core cyber adverts require a degree, 90% of managers accept prior IT work alone, 89% accept an entry certification alone, and 84% set a skills assessment.

Some 81% of UK core cyber job postings set a bachelor's degree as the minimum entry requirement. Asked directly what they would accept, 90% of cyber hiring managers say they would consider an early-career candidate whose only relevant credential is previous IT work. Both findings are sound. The distance between them is where most cyber careers stall, and it is the most addressable problem in the market.

Two documents, one hire

A job advert and a hiring decision are written by different people, at different moments, for different purposes. Candidates read the first and assume it describes the second. It does not.

The Department for Science, Innovation and Technology analysed 32,370 core cyber job postings across the UK during 2024, in research published on 19 September 2025. Some 81% specified a bachelor's degree or equivalent as the minimum, with a further 7% asking for a master's or a doctorate. Across the wider cyber workforce the figure rose to 83%. Experience requirements narrowed in the same direction. Some 63% of core postings asked for two to six years, while demand for candidates with under a year of experience fell from 25% in 2022 to 17% in 2024.

Read that alone and the UK market looks shut to anyone without a conventional route in.

Now read the second document. ISC2 surveyed 929 cyber security hiring managers across six countries, the UK among them, for its 2025 Cybersecurity Hiring Trends report. Asked what they would accept in an early-career hire, 90% said they would consider a candidate whose only relevant background was previous IT work. Some 89% would consider a candidate holding nothing but an entry-level certification. And 81% would consider one whose sole credential was a degree in IT, cyber security or computer science. The academic qualification that four adverts in five demand finished last of the three.

The two findings do not contradict each other, and it matters that a candidate understands why.

81%
of core cyber adverts require a degree
90%
of managers accept prior IT work alone
89%
accept an entry certification alone
84%
set a skills assessment

The advert is a rationing device

An advert is written to reduce volume. It is a filter, and often a defensive one: it must survive internal sign-off, sit consistently beside every other advert the organisation has published, and give a recruiter a defensible reason to reject nine applications in ten. Degree lines and year counts do that work efficiently. They are not a description of the person the manager intends to hire.

The manager's answer is the description. It is given privately, in a survey, with nothing to justify, and it says something quite different about what the job needs.

One qualification is worth stating plainly, because flattening it would mislead. The ISC2 figures concern early-career and junior hiring specifically. The DSIT posting data covers core cyber roles across all levels. The gap between advert and intent is therefore sharpest at exactly the point where candidates conclude the door is closed, and thinnest at senior level, where the advert and the decision converge because both are describing scarcity.

Portrait infographic on a near-black background with red accents, titled: What the advert asks for, and what the manager accepts. The upper panel, sourced to DSIT analysis of 32,370 UK core cyber job postings in 2024, shows 81% requiring a bachelor's degree, 63% requiring two to six years of experience, and 17% open to candidates with under one year. The lower panel, sourced to an ISC2 survey of 929 hiring managers on early-career hiring, shows 90% accepting prior IT work alone, 89% accepting an entry-level certification alone, and 81% accepting a degree alone. A closing panel reads: the advert is a rationing device, the manager's answer describes the hire.

Same market, two documents. The advert is written to reject applications. The manager's answer describes the person they intend to hire.

The machine that reads the advert

Between the two documents sits a third party, and it has grown quickly.

Barclay Simpson's 2026 cyber security salary and recruitment survey found 63% of employers now using AI in CV screening and shortlisting, 59% in interview support, 48% in writing and targeting adverts, and 41% in candidate sourcing. Some 44% of those same employers regard AI as a threat to the integrity of their own recruitment process.

The consequence for a candidate is structural rather than moral. The automated screen is calibrated to the advert, because the advert is the only specification it has been given. The human is calibrated to something else. An application therefore faces two assessors with different criteria, in sequence, and most candidates prepare for neither: they prepare a document that reads well to a sympathetic human who never sees it in that form.

Surviving the first assessor is a vocabulary exercise. If the posting names ISO/IEC 27001, vulnerability assessment or incident response, those exact terms need to appear where the candidate has genuinely done the work. That is not gaming a system. It is answering the question that was actually asked, in the words it was asked in.

What the manager is calibrated to

Winning the second assessor is a different exercise entirely.

Some 84% of hiring managers use skills-based assessments or tests when evaluating entry and junior applicants. Three of the five most valued competencies they name are not technical at all: teamwork, problem solving and analytical thinking. Some 56% report that an entry-level hire takes four to nine months to reach the point of handling tasks independently.

That last figure is the commercial engine of the whole process. The manager is not buying credentials. The manager is buying a reduction in the months between the offer and the first week the hire is useful without supervision. Every element of the assessment is a proxy for that. A candidate who can demonstrably shorten four to nine months is worth materially more than one who can only assert that they would.

The demand pattern in the postings points the same way, and it corrects a common misreading of the market. Beyond the generic category, the named skills most requested in core cyber postings were vulnerability work at 20%, auditing at 19%, ISO/IEC 27001 at 16%, risk management at 16% and incident response at 15%. Three of those five are governance and assurance rather than offensive or engineering work. Governance, risk and compliance is not the consolation route into the industry. It is a substantial share of the paid demand, and it is where a candidate without a computer science degree most often has a defensible claim already.

One further finding deserves attention, because it is rarely mentioned and it is cheap to fix: 54% of hiring managers have rejected a candidate on the basis of their social media activity.

The Evidence Ladder

Careers in this market are built by moving claims up four rungs. Each rung is harder to fabricate than the one below it, and each is worth more.

Stated. What the candidate asserts on a CV or profile. Costless to produce, therefore discounted heavily by anyone experienced. This is the rung that survives the automated screen and nothing beyond it.

Shown. What the candidate can put in front of someone inside ten minutes: a written incident analysis, a policy set they drafted, a control mapping, a repository, a lab build with the reasoning recorded. The commercial value is not the artefact. It is that the reader stops having to take anything on trust.

Tested. What the candidate can do while being watched, which is what 84% of hiring managers are already arranging. Preparation here is not revision. It is having performed the task before, unassisted, on something real enough to have gone wrong.

Vouched. What a credible third party will confirm without being prompted. This is the slowest rung to build and the only one that keeps working after the candidate stops maintaining it.

Most candidates invest almost everything in the first rung, where returns are lowest, and treat the other three as things that happen to them. Reversing that allocation is the single highest-return move available to a practitioner at any level.

Portrait infographic titled The Evidence Ladder, presenting four rungs on dark panels with a red accent bar, brightening as they climb. From the bottom: Stated, what your CV asserts, costless to produce so it is discounted heavily. Shown, what you can put in front of someone in ten minutes, such as a write-up, a control mapping or a lab build with the reasoning kept. Tested, what you can do while being watched, noting that 84% of managers already set a skills assessment. Vouched, what a credible third party confirms unprompted, described as the slowest to build and the only rung that keeps working when you stop. A closing panel reads: most invest almost everything in rung one, where returns are lowest.

The Evidence Ladder. Each rung is harder to fabricate than the one below it, and each is worth more. Most practitioners never leave the first.

Three questions worth answering honestly

  1. If a skills assessment were set tomorrow for the role I want, what would it test, and have I done that specific thing outside an examination?
  2. Which of my claims can I evidence in ten minutes, and which require the other person to believe me?
  3. Who outside my current employer would confirm my strongest claim without being asked to soften it?

The strategic takeaway

The UK cyber market is not short of people who hold qualifications. Some 88% of employers describe finding skilled talent as challenging, and 56% name insufficient technical or regulatory knowledge as the obstacle. That is a statement about demonstrable capability, not about paper. The shortage sits at rungs three and four of the ladder, which is precisely where supply is thinnest and where a deliberate candidate can move fastest.

The advert will keep asking for the degree. Answer it in its own language, then win the part that actually decides.

A note on confidence

The DSIT figures are drawn from analysis of job postings and employer surveys and describe what was advertised, not what was hired. The ISC2 figures are self-reported hiring manager intent, which tends to run more open than behaviour. The Barclay Simpson figures are employer self-reporting from a recruitment firm's own survey. We have set them beside each other because the divergence between advertised requirement and stated intent is consistent across all three, not because any single figure should be treated as precise.

If a hiring manager set you an assessment next week, would you be revising for it or repeating something you have already done?

Garzon Cyber Solutions is a young firm, and the recruitment work is handled personally by the founder rather than passed to a delivery team. Our engagements are contingency only: nothing is payable until a candidate accepts and starts. No CV goes to a hiring organisation without your explicit permission for that specific role. If you want your next move handled by someone who will tell you when a role is wrong for you, register your interest.

Register Your Interest →
Subscribe to GCS Insights
Sources
Department for Science, Innovation and Technology, Cyber security skills in the UK labour market 2025, published 19 September 2025. ISC2, 2025 Cybersecurity Hiring Trends, 929 hiring managers across six countries, published June 2025. Barclay Simpson, 2026 Salary Survey and Recruitment Trends Guide: Cyber Security. Department for Science, Innovation and Technology, Cyber security sectoral analysis 2026, published 12 May 2026.
Talent Cyber Careers Hiring GRC Skills