Rachel spent eight years teaching high school history before she ever touched a firewall. She didn’t start out chasing a cybersecurity career. She started out taking a free evening class on network basics because a friend said the job market for it looked good. Eighteen months later she was working as a security operations center analyst at a regional bank, triaging alerts that a computer science graduate three cubicles over had spent four years in school preparing for. Her path wasn’t the exception it once would have been. It’s becoming the norm, and the industry is starting to notice.
Stories like this one are popping up across the security world right now, and they point to something bigger than a few inspiring career pivots. The cybersecurity industry has a staffing problem so large that it can no longer afford to keep hiring the same way it always has, and a growing number of the people stepping into the gap are women who came in sideways, through bootcamps, certifications, and unrelated careers rather than a four-year computer science degree.
A Shortage Too Big to Fill the Old Way
The numbers behind this shift are hard to ignore. The 2025 ISC2 Cybersecurity Workforce Study puts the global talent gap at roughly 4.8 million unfilled positions, with total demand for security professionals now sitting above 10 million worldwide. The United States alone accounts for more than 500,000 of those open roles. To put it plainly, the workforce would need to grow by close to 90 percent just to meet the demand that already exists today, before accounting for whatever new threats show up next year.
What’s notable is how that gap is starting to be described. For years, the standard explanation was a lack of qualified candidates. The 2025 study found something different happening for the first time: budget pressure and hiring freezes have overtaken a lack of talent as the leading reason security seats stay empty. In other words, plenty of capable people exist. Organizations are still figuring out how to find them, train them, and justify paying for them.
Where Women Actually Stand in the Field
Women remain a small share of that workforce. ISC2 puts the global figure at around 22 to 26 percent of security teams, with wide variation by country, from roughly 15 percent in Germany to closer to 27 percent in Italy, and the United States sitting around 19 to 20 percent. That is real progress compared to a decade ago, when women in cybersecurity were closer to a rounding error, but it still leaves the field far from balanced.
The barriers aren’t mysterious once you ask the people living with them. In ISC2’s research, 45 percent of women cited work life balance and caregiving demands as the main thing holding them back from staying in the field or moving into leadership, compared to just 29 percent of men who saw it as a serious issue. Almost as telling, 42 percent of men said they didn’t notice or didn’t believe there were any significant barriers for women at all. That perception gap, more than any single policy failure, is often what keeps a workplace from changing.
Why the Front Door Was Built Too Narrow
Part of the problem sits in how cybersecurity jobs have traditionally been advertised and filled. Fortinet’s most recent Global Cybersecurity Skills Gap Report found that 71 percent of organizations still require a four year degree for security roles, even though 89 percent of the same IT decision makers say they actually prefer candidates who hold relevant certifications. That’s a strange mismatch. Employers say certifications matter more in practice, yet the degree requirement stays bolted to the job posting anyway, filtering out capable candidates before a hiring manager ever sees a resume.
Rob Rashotte, vice president of the Fortinet Training Institute, has been blunt about what that gap costs the industry. His argument, echoed across recent congressional testimony and industry panels, is that hiring organizations need to actively recognize alternative routes into the field rather than treating the traditional degree as a proxy for competence. A four year computer science program teaches useful things, but so does a background in law, teaching, nursing, the military, or small business operations, especially the parts involving risk assessment, attention to detail, and staying calm when something is actively on fire.
The Paths Actually Working
What’s changed in the last two or three years is how many credible on ramps now exist outside the university system. Certifications like CompTIA Security+, Certified Ethical Hacker, and eventually CISSP give career changers a way to prove baseline knowledge without four years and a mountain of student debt. Bootcamps have matured well past their reputation as quick cash grabs, with the better ones reporting job placement rates near 75 percent within six months of graduation. Nearly 40 percent of adult learners entering these programs now come through nontraditional admissions paths that accept demonstrated problem solving skills or relevant work history in place of a technical transcript.
Organizations built specifically around this shift are doing some of the heaviest lifting. Women in CyberSecurity, usually shortened to WiCyS, runs mentorship programs and scholarships aimed at exactly the kind of candidate who wouldn’t otherwise picture themselves in a security operations center. Springboard and similar programs extend the same kind of support to veterans and other underrepresented groups. None of this is charity. It’s a direct response to a labor shortage that traditional recruiting pipelines have failed to solve on their own.
Why This Matters Beyond Headcount
There’s a temptation to treat this purely as a staffing fix, a way to plug open seats faster. That undersells what’s actually at stake. Security teams built entirely from one kind of background tend to share the same blind spots, and attackers are very good at finding blind spots. Someone who spent years reading people as a teacher or negotiating as a lawyer often brings a different instinct for social engineering and human risk than someone who came up purely through systems administration, and modern attacks increasingly target people rather than code.
It also lines up with a broader industry realization that technology alone was never going to solve this problem. Analysts have been pushing companies to invest in the human side of cyber resilience for a while now, arguing that bolstering defenses means more than buying better tools, it means building teams that actually reflect the range of ways people think and behave. A more varied workforce, recruited through more varied doors, is one concrete way to get there.
The staffing crunch isn’t confined to any one corner of the industry either. When eight major telecom carriers recently set aside their usual rivalry to form a joint alliance for sharing real time threat intelligence, part of the underlying pressure was the same one driving the push for non-traditional hiring: no single team, and no single company, has enough people to watch everything on its own anymore. More eyes, recruited from more places, is quickly becoming a competitive necessity rather than a nice to have.
What This Looks Like Going Forward
None of this means the degree requirement disappears overnight, or that every certification mill deserves trust. Some hiring managers will keep defaulting to familiar credentials because it feels safer, even when the data says otherwise. But the direction of travel is clear enough. Employers who keep filtering out qualified candidates over a missing diploma are choosing to compete for talent with one hand tied behind their back, in a field where the talent pool is already stretched thin.
For anyone reading this and wondering whether a career switch into security is realistic without a technical background, the honest answer is that the door is open wider than it has been in years. It usually starts small, with something as basic as learning how phishing attempts work or picking up the habits covered in a solid beginner’s guide to cybersecurity basics, before moving toward a certification and eventually a junior analyst role. Rachel didn’t plan on leaving the classroom for a security operations center. The industry needed her more than either of them expected, and it still needs a lot more people like her.

