EmployersHiringJob Descriptions

How to Write a Cybersecurity Job Description (Template + Examples, 2026)

IJB

InfoSec Job Board

August 12, 2026 · 10 min read

TL;DR: a cybersecurity job description has one job: convince a qualified, busy security professional that this role is real, scoped, and worth an application. The JDs that fail all fail the same way - vague mission, a wishlist of ten must-haves, no salary band, and buzzword filler that reads like a ghost job. This guide gives you a copy-paste template, role-specific guidance for engineer, analyst, and GRC reqs, the case for publishing a salary band, and the mistakes that quietly kill your applicant quality.

Want the printable version? The free hiring kit includes this JD template plus the interview scorecard and screening checklist that pair with it.

Free cybersecurity hiring kit

Interview scorecard, screening checklist, JD template, and offer checklist. Built for hiring managers.

The template (copy, paste, fill in)

Six sections, in this order. Everything else - culture manifestos, twelve-paragraph company histories - moves below these or gets cut.

[Job title] at [Company] - [location / remote policy]

Mission line (1-2 sentences): what this person will own and why it matters. "You will own detection coverage for our AWS estate - building, tuning, and measuring the rules that catch real attacks against 400 production accounts."

What you'll do (5-7 bullets): concrete activities in the first year, written as verbs. Name the actual stack (the SIEM, the cloud, the languages). If on-call exists, say so here, with the rotation.

Must-haves (5 maximum): the genuinely non-negotiable skills. Each one you add cuts your applicant pool - spend them carefully.

Nice-to-haves (3-5 bullets): everything you would be pleased by but would not reject over. Certifications usually belong here, not in must-haves.

Salary band + benefits: a real range you would actually pay, plus the headline benefits. If the band depends on location or level, show the structure.

Interview process (3-5 steps, with timeline): "Recruiter screen (30 min) - hiring manager (45 min) - technical exercise (take-home, 2 hours max) - team panel - offer. Two to three weeks end to end."

Why this order: candidates scan mission, scope, and pay before anything else. The interview-process section is rarer than it should be - listing it signals an organized team and measurably reduces drop-off from senior candidates who have been burned by seven-round loops.

Role-specific guidance

Security engineer

Engineers screen JDs for the stack and the build-versus-operate ratio. Name the technologies precisely - "Terraform on AWS, detections in Python, Splunk" beats "modern cloud environment" every time - and say honestly whether the job is building tooling or operating someone else's. The most common engineer JD failure is disguising an operations seat as an engineering one; the mismatch surfaces in the first interview and costs you the candidate. If coding is required, state the language and how much of the week it fills.

Security analyst / SOC

Analysts filter on three things JDs habitually hide: the shift model (24/7 rotation? nights? say it in the first screen of text, not in an aside), the tier and escalation path (Tier 1 triage and Tier 2 investigation are different jobs), and the growth story (does this seat feed detection engineering or threat hunting?). A JD that states "Tier 2, no nights, detection-engineering track after 18 months" will out-recruit a vague one at the same salary.

GRC analyst

GRC candidates want the framework scope (SOC 2? ISO 27001? PCI? all three?), the audit cadence, and whether the role builds a program or maintains one - a first-GRC-hire seat and a seat on a twelve-person team are different careers. Certifications carry more genuine weight in GRC than in engineering, so CISA or CRISC can defensibly sit in must-haves here - but still cap the list at five. Writing quality is the core skill; say that you will ask for a writing sample and strong candidates will self-select in.

Publish the salary band (the data says so)

The strongest single upgrade to any security JD is a real salary band. The pattern is widely observed across the industry: postings that disclose pay draw more applications from qualified candidates, waste fewer cycles on mismatched expectations, and cut the negotiation surprise at offer stage. Momentum is also one-directional - pay transparency laws keep expanding, and candidates increasingly read a missing band as a low one.

Our own data adds a trust angle. In our Ghost Job Index - a scan of 3,000 recent security-relevant postings for ghost-job warning signs - salary-disclosing posts were far less likely to score as likely ghost jobs (2.6% red versus 5.7% for non-disclosing posts, roughly a 2.2x gap). One honest caveat the report itself makes: disclosure is one of the scored signals, so part of that gap is by construction. The practical takeaway stands either way: candidates use the missing band as a ghost-job tell, and a posting without one starts the conversation with a trust deficit it did nothing to earn.

Not sure what band to publish? The cybersecurity salary report aggregates live disclosed postings by role, seniority, and country, and the salary-by-state pages cover the US cuts.

Common mistakes (and what they cost you)

  • The ten-years-of-everything wishlist. Stacked experience requirements - a decade of cloud, plus forensics, plus appsec, plus compliance - describe three different professionals and repel all of them. Strong candidates read an unrealistic wishlist as a team that does not know what it needs. Five must-haves, maximum, and every one defensible.
  • Cert soup. Listing six certifications as requirements filters out excellent practitioners and selects for checkbox collectors. Pick the one credential that genuinely maps to the work, put the rest in nice-to-haves, or state the honest equivalent: "certification or demonstrable equivalent experience."
  • Ghost-job vagueness. No team named, no manager, no concrete responsibilities, evergreen "always hiring" language, urgency with no substance - these are the exact signals candidates (and our detector) use to flag postings that may not be real openings. Run your draft through the free ghost job detector before publishing; if your own posting scores red, qualified candidates are skipping it for the same reasons.
  • Boilerplate above the fold. Three paragraphs of company history before the first concrete detail loses the mobile reader. Mission line first; the company story earns two sentences, later.
  • Entry-level roles requiring five years of experience. It signals a mislabeled req and feeds the exact cynicism that makes security hiring harder. If you need five years, the role is mid-level - title and pay it accordingly.

Where to publish it

A strong JD underperforms on the wrong channel. The short version: generalist boards (LinkedIn, Indeed) for reach and passive candidates, a specialist cybersecurity board for concentrated intent, and both for hard-to-fill roles - the full reasoning is in LinkedIn vs a niche cybersecurity job board and the wider where-to-post scorecard. Posting here puts the JD in front of security professionals only, with direct applies into your ATS and Google Jobs structured data emitted automatically - a flat $299 for 30 days.

JD written?

Put it in front of security professionals today

Post to a security-only audience from 250+ security companies - direct applies, Google Jobs eligible, live in minutes.

Flat $299 for a 30-day listing

Related guides

Stay ahead of the curve. Get new infosec jobs in your inbox.