Dated report · Q3 2026
The Ghost Job Index
How much of cybersecurity hiring looks real? We ran our ghost-job language heuristics over 3,000 recent postings pulled straight from the applicant tracking systems of 252 security companies. This report scores posting language patterns in aggregate - it is never a verdict on any specific employer.
Data frozen as of 2026-08-10. These figures do not change, so they can be cited. Free to cite with attribution to infosecjobboard.com.
Postings analyzed
3,000
from Greenhouse, Lever, Ashby boards
Show warning signals
49.3%
at least one strong ghost-job signal
High ghost-job risk
5.1%
154 postings scored red
Clearly legitimate
50.7%
specific, disclosed, concrete
Key findings
- 49.3% of analyzed postings show at least one strong ghost-job signal (scored amber or red); 5.1% hit several at once.
- 11% contain evergreen "always hiring" pipeline language - the strongest single ghost-job tell.
- 48% mention no pay anywhere in the posting text.
- Postings that publish a structured salary range are about 2.2x less likely to score high ghost-job risk (2.6% vs 5.7%).
Verdict distribution
Each posting gets a red / amber / green read from the same scoring our free detector uses.
How often each signal appears
Share of the 3,000 analyzed postings whose text triggered each signal.
Spells out clear responsibilities
The posting says what you would actually do.
Names specific tools and tech
A concrete stack (SIEM, cloud, EDR, languages) points to a real, defined role.
Mentions a pay range
Salary language detected in the posting text.
Names the team or reporting line
Concrete team or manager context is rare in filler posts.
No pay range anywhere in the text
A soft ghost-job signal on its own; heavier alongside other flags.
Evergreen "always hiring" language
Talent-pipeline phrasing that often means no specific opening.
Third-party / agency phrasing
"Our client" style reposts are more likely speculative or duplicated.
Stacked years-of-experience wishlist
Four or more separate experience requirements in one post.
Buzzwords in place of specifics
Three or more filler cliches ("rockstar", "fast-paced") instead of duties.
Salary transparency vs ghost-job risk
Among the 580 postings with a structured salary range, 2.6% scored high ghost-job risk and 70.3% read clearly legitimate. Among the 2,420 without one, 5.7% scored red and only 46% read clearly legitimate.
Salary-disclosing postings are about 2.2x less likely to look like ghost jobs.
Honest caveat: pay disclosure is itself one of the scored signals, so part of this gap is by construction. The direction still holds across the independent signals (evergreen and agency language also cluster in undisclosed postings).
Test any posting yourself
Run the same check on a job you are eyeing
Paste any posting into our free ghost-job detector for an instant red / amber / green read with every signal explained.
Methodology (and its limits)
- Sample: the 3,000 most recently posted active postings with full description text, ingested directly from the Greenhouse, Lever, Ashby applicant tracking systems of the 252 cybersecurity companies we track.
- Listing-only ATS sources (Workday, Comeet, Jobvite) expose no description text through their public APIs, so their postings cannot be language-analyzed and are excluded. Postings under the detector’s 40-word floor are skipped (0 in this sample).
- Each description was stripped to plain text and scored by the same open heuristics behind our ghost-job detector: evergreen pipeline language, pay disclosure, buzzword density, agency phrasing, experience wishlists, and the positive marks of a real role (concrete duties, named tools, a reporting line).
- This is heuristic language analysis, not employer verdicts. A vague posting from a great company is still just a vague posting, and no employer is named or implied anywhere in this report.
- Because the sample is drawn from companies that publish full descriptions on modern ATS platforms, it likely understates ghost-signal rates on the wider job-board ecosystem, where reposted, agency and pipeline listings are far more common.
Figures frozen 2026-08-10. Free to cite with attribution to infosecjobboard.com.
Frequently asked questions
- What share of cybersecurity job postings look like ghost jobs?
- In our Q3 2026 analysis of 3,000 recent postings from the applicant tracking systems of 252 cybersecurity companies, 5.1% scored as high ghost-job risk and another 44.1% showed mixed signals. 50.7% read as clearly legitimate. These are language-pattern scores on the postings themselves, not verdicts on any employer.
- How common is "always hiring" pipeline language in cybersecurity postings?
- 11% of the 3,000 postings we analyzed contained evergreen talent-pipeline phrasing such as "talent community" or "future opportunities" - the single strongest ghost-job signal in the literature.
- How many cybersecurity job postings publish a salary range?
- 48% of analyzed postings contained no pay information anywhere in the text. Absence of pay is a soft ghost-job signal on its own, but it compounds with vague or evergreen language.
- Are salary-disclosing job postings less likely to be ghost jobs?
- Yes, in our data: postings with a structured salary range scored high ghost-job risk 2.6% of the time versus 5.7% for postings without one - about 2.2x less likely. Note that pay disclosure is itself one of the scored signals, so part of this gap is by construction.
Skip the ghosts entirely
Every listing on our board is ingested from the employer's own applicant tracking system and links straight to their application - no pipeline traps, no recruiter middleman.