The cybersecurity job market keeps moving, whatever the headlines say. This is the July 2026 Hiring Pulse - a monthly snapshot measured from live postings we track hourly across 200+ security companies, not from surveys. As of mid-July: 901 open security roles on the board, 84 of them posted in the last seven days. Every number below comes from our own data, frozen at publication.
Who is hiring hardest
The security companies that posted the most new roles in the past 30 days (counted from real ATS posting dates - not reposts, and excluding sources that do not publish genuine dates):
- Zscaler - 184 new roles
- Okta - 149 new roles
- Cloudflare - 112 new roles
- SentinelOne - 110 new roles
- Netskope - 77 new roles
The live version of this ranking, refreshed hourly, is at top cybersecurity employers →.
Where the demand is
- Security Engineering - 162 open roles
- Threat Intelligence - 117
- AppSec - 102
- Detection Engineering - 100
- Cloud Security - 73
The composition shift we have been tracking all year is visible in one list: engineering-heavy roles dominate, and GRC (73 open roles this month) keeps growing on the back of regulation - DORA, NIS2, and the wave of data-protection laws arriving across Asia, Africa, and Latin America.
Where the jobs are
- United States - 295
- Israel - 54
- United Kingdom - 46
- India - 31
- Canada - 25
The long tail matters more than this top five suggests: hiring is compounding fastest in markets most boards ignore - India, the Gulf, Southeast Asia, and Africa. Pay data for 21 countries lives on our salary leaderboards →.
The skills the market is asking for
From the job descriptions themselves: Python (286 roles), AWS (272), GCP (206), Go (201), and Incident Response (198). Two of the top four are programming languages and two are clouds - the market keeps telling on itself: security engineering is software engineering with a defender's job description. Browse roles by skill at /skills →.
What pays (and who says so)
Only 14% of security postings publish a salary. A few of this month's roles that did:
- Vercel - Security Software Engineer, Open Source Frameworks: $208,000 - $312,000
- Illumio - Sr. Software Engineer, Container Security: $170K - $196K
- Twilio - Senior Security Engineer, Incident Response: $141,520 - $176,900 (remote)
- Ping Identity - Senior Software Engineer, Platform Security: $110,218 - $137,773 (remote)
Check your own number against the market band for your role and country with Am I Underpaid? →
Remote, and the honest entry-level number
29% of the security roles we track are remote - detection, GRC, cloud, and AppSec all hire remote at scale, and remote seats pay to the employer's market, not yours (live remote list →). And the number most boards will not show you: of 901 live security roles, only 17 are explicitly entry-level. The way in is the adjacent doorway, not the job title - the full strategy is in how to get into cybersecurity →.
The takeaway
Security hiring is not shrinking - it is re-sorting: toward cloud and engineering, toward governance seats created by regulation, and toward markets where compliance law just arrived. If you are hiring or searching, the edge is the same: work from live data, not last year's narrative.
A new Pulse ships every month, and the deeper quarterly analysis lives in the State of Cybersecurity Hiring report →. All figures are free to quote with attribution to InfoSec Job Board.
The latest cybersecurity roles on the board
Related guides
GRC Analyst Salary in 2026: US Bands, 21 Countries & What Moves the Number
What GRC analysts actually earn in 2026 - US pay by level, benchmark ranges across 21 countries including Indi…
9 min read
How to Transition into GRC in 2026: From Project Management, Audit, IT, or DevOps
A career-changer's guide to breaking into GRC in 2026 - what transfers from project management, audit, IT supp…
10 min read
GRC Interview Questions in 2026: What Hiring Managers Actually Ask
The GRC analyst interview, decoded - the framework, risk, and scenario questions that actually come up (SOC 2 …
9 min read