Market DataHiring PulseSalaries

Cybersecurity Hiring Pulse - September 2026: 1,031 Open Roles, a Third of Postings Disclose Pay, Cloudflare Climbs to Second

IJB

InfoSec Job Board

September 7, 2026 · 6 min read

This is the September 2026 Cybersecurity Hiring Pulse - a monthly snapshot measured from live postings we track hourly across 252 security companies, not from surveys. As of 2026-09-07: 1,031 open security roles on the board, essentially flat against 1,029 a month ago, with 79 posted in the last seven days(88 in August). Coverage was stable this month - six small additions on August 7 (Zafran Security, Armadin, Cloaked, Geordie AI, RunSybil, Terra Security) took the registry from 246 to 252 companies, none large enough to move the totals - so the headline is a market holding its size while it re-sorts underneath. Two of our own measurement fixes landed since August, and this edition names both where they matter. Every number is frozen at publication and free to quote with attribution.

Who is hiring hardest

The security companies that posted the most new roles in the past 30 days (counted from real ATS posting dates - not reposts, and excluding sources that do not publish genuine dates):

  • Zscaler - 198 new roles
  • Cloudflare - 138 new roles
  • Okta - 108 new roles
  • SentinelOne - 86 new roles
  • Rubrik - 82 new roles

Zscaler holds the top seat for the third month running and posted more than in August (179). Cloudflare climbed from fourth to second, Okta and SentinelOne each posted fewer than last month, and Rubrik enters the top five for the first time, displacing Netskope (58 this month, 87 in August). The live version of this ranking, refreshed hourly, is at top cybersecurity employers →.

Where the demand is

  • Security Engineering - 180 open roles
  • Detection Engineering - 157
  • Threat Intelligence - 110
  • AppSec - 110
  • GRC - 86
  • Cloud Security - 79
  • AI Security - 69
  • Identity & Access - 64

A methodology note before anyone reads a trend into that list: on 2026-08-05 our title classifier gained the keywords "security analyst", "security architect", "identity governance", "identity management" and "agentic security". Roles with those titles were previously unclassified and invisible to this cut. The specialization numbers are therefore not month-over-month comparable across that date, which is why we print them without deltas. In particular, Detection Engineering at 157 against 110 in August is mostly reclassified "security analyst" titles now landing where they belong, not a hiring surge. Identity & Access is inflated the same way. Read this month's list as the new baseline.

What the list does support: Security Engineering remains the largest category by a wide margin, AppSec and Threat Intelligence are tied for third, and AI Security holds its place as a first-class demand category ahead of offensive work (48) and privacy (27).

Where the jobs are

  • United States - 479 (308 in August)
  • Israel - 94 (80)
  • India - 69 (37)
  • United Kingdom - 56 (57)
  • Canada - 36 (25)

These use the same single-country method as earlier editions (each role counted once, under its primary country) so the August figures sit alongside for reference - but the jumps are not hiring. The total barely moved, so what changed is how many roles resolve to a country at all: on 2026-08-19 we taught the location parser about 250 cities, and on 2026-09-02 every stored posting was re-processed, so roles that used to sit in a no-country bucket ("Pune", "Boston, MA", "Tel Aviv") now count under their country. The United States gaining 171 roles on a flat board is that parser catching up, and India's near-doubling is the same effect. The one clean reading: the United Kingdom, which the parser already handled well, is flat at 56. Pay data for 21 countries lives on our salary leaderboards →.

The skills the market is asking for

From the job descriptions themselves: Python (315 roles), AWS (304), Incident Response (242), Go (222), GCP (213), and Azure (208). Python and AWS swapped places again, by eleven roles - last month AWS led by twelve. That is a wobble inside the noise of a 300-role count, not a crown changing hands; the honest reading is that the top two are tied and have been since spring. Incident Response climbed from fourth to third (231 to 242), and Machine Learning now sits seventh at 181 mentions, which is the AI-adjacent shift showing up in requirements, not just in job titles. Browse roles by skill at /skills →.

What pays (and who says so)

34% of security postings on the board publish a salary. Last month's edition said 14%, and the difference is not employers becoming more transparent - it is us fixing a defect. On 2026-09-02 we found that pay-range widgets on Greenhouse-hosted postings were stored HTML-escaped, so our extractor never saw the numbers inside them. We fixed the reader and re-processed every posting, and roughly 1,300 stated salary bands that had been silently dropped for two months are now counted: Okta went from 0 disclosed roles to 277, Zscaler to 262. So the disclosure rate is not comparable to earlier editions; the true rate was always closer to a third. A few of this month's roles that publish a band:

  • Obsidian Security - Chief Information Security Officer: $300,000 - $380,000 (Palo Alto, CA)
  • GitLab - Staff Security Researcher: $168,000 - $238,000 (remote; US, Canada, UK, Israel)
  • Tanium - Staff Identity and Access Management Engineer: $180,000 - $230,000 (hybrid, US)
  • Okta - Staff Identity Governance and Access Engineer: $161,000 - $221,000 (Bellevue, Chicago or Washington, DC)
  • Twilio - Staff Security Engineer: $155,520 - $194,400 (remote US)

Two of the five are fully remote and one is hybrid - a more mixed picture than August's four-of-five, and the Okta band is exactly the kind of posting the old extractor was dropping. Check your own number against the market band for your role and country with Am I Underpaid? →

Remote, and the honest entry-level number

31% of the security roles we track are remote, up two points from August's 29% - the full breakdown by specialization, country, and region is in our remote cybersecurity jobs guide →. And the number most boards will not show you: of 1,031 live security roles, only 19 are explicitly entry-level or internships (12 entry-level, 7 internships), up from 13 last month but still under 2% of the board. The way in remains the adjacent doorway, not the job title - the full strategy is in how to get into cybersecurity →.

The takeaway

September's picture is a market holding steady in size - 1,031 roles, the same five or six vendors doing most of the posting, Security Engineering still the largest seat - while our own instruments got sharper. The two corrections in this edition both point the same way: the market was always more transparent about pay, and more analyst-heavy, than earlier snapshots could see. If you are hiring or searching, the edge is the same: work from live data, and know what the instrument measures.

A new Pulse ships every month - the August edition is here, and the deeper quarterly analysis lives in the State of Cybersecurity Hiring report →. All figures are free to quote with attribution to InfoSec Job Board.

The latest cybersecurity roles on the board

See who is hiring most

Get weekly alerts for Get weekly alerts for new cybersecurity jobs:
Share:LinkedInXWhatsApp

Related guides

Stay ahead of the curve. Get new infosec jobs in your inbox.