If there's one trend keeping me busy this winter (while you lot enjoy your Aussie summer), it's the fierce competition for cybersecurity talent down under. My usual patch is sustainability and agritech, but lately I've had more than a few Australian companies tapping me up about security roles, particularly those weird hybrid positions where sustainability meets compliance.
Recruitment patterns in Australia don't typically cross my desk. When three separate clients mention the same market dynamics within a fortnight, I pay attention.
Several sectors that wouldn't traditionally compete for the same talent pool are now fighting over the same candidates. The drivers are worth understanding.
Compliance deadlines creating bottlenecks
The biggest driver is regulatory compliance. The revised Critical Infrastructure Act amendments that kicked in fully this year have caught plenty of organisations with their trousers down.
I spoke with a hiring manager at a Sydney water utility last month who'd been trying to fill a senior security governance role for nearly 16 weeks. "We're competing with banks now," she told me. "That wasn't happening before."
The ASD Essential Eight compliance requirements compound the problem. While not technically mandatory for all sectors, they've become the de facto standard that boards are demanding. And finding people who understand both the technical controls and can translate them to business stakeholders? Gold dust.
One bank CISO I placed candidates with back in my financial services days put it bluntly: "We've got budget. We've got tools. What we haven't got is enough qualified people who understand both our industry and cybersecurity frameworks."
Beyond Tick Boxes: Diversity Recruitment Strategies That Actually Transform UK Workplaces
Master the Virtual Hot Seat: 7 Video Interview Techniques Recruiters Don't Tell You
How to Master 'Tell Me About Yourself' Interview Question: UK Expert Insights
The sectors at the centre of the storm
Financial services: The usual suspects with unusual tactics
The big four banks have always paid well for cyber talent. That hasn't changed. What has changed is their willingness to consider candidates without financial services backgrounds.
I've seen hiring managers at Commonwealth and ANZ specifically requesting candidates from critical infrastructure sectors, water, energy, healthcare, because they want people familiar with operational technology security and physical/digital convergence. Banks didn't worry about this five years ago.
Salary packages in Sydney for mid-senior cyber governance roles are pushing past A$220K. Melbourne isn't far behind. But money isn't winning this war anymore.
Some banks have started offering four-day work weeks for cyber roles, something utterly unimaginable pre-pandemic. Others are accepting fully remote candidates based in regional areas like Ballarat or Armidale. I even heard of one major bank setting up a satellite security operations team in Hobart because they found a cluster of talent there.
Critical infrastructure: Late to the party but spending big
The water, power, and transport operators face a double whammy. They need to comply with tougher regulations, but they've historically under-invested in cybersecurity talent. Many still have IT security tucked under a general IT manager rather than a dedicated function.
The talent gap is about experience, not just headcount. How do you secure systems designed in the 1990s that were never meant to be internet-connected but now absolutely are? How do you monitor industrial control systems that use protocols security scanning tools weren't built to understand?
Roles I've seen advertised include:
- OT Security Specialists with SCADA experience
- Compliance Officers specialising in Essential Eight implementation
- Security Awareness Managers (fascinating that user education is finally getting budget)
- Supply Chain Security Analysts (this role barely existed two years ago)
What's striking is how these employers are trying to stand out. One Queensland electricity distributor has started offering six weeks of annual leave as standard for all cyber roles. Another is providing housing assistance for those willing to relocate to regional headquarters.
Defence and intelligence contractors: The silent vacuum
These organisations have always needed security talent. What's changed is the scale. The AUKUS agreement continues to reshape Australia's defence technology landscape, creating demand for security specialists with clearances.
Defence contractors rarely advertise their most sensitive roles publicly. Candidates don't know these jobs exist unless they're already in adjacent networks. That pulls talent from other sectors without those sectors realising who they're competing against.
I've heard through industry contacts that several defence technology firms based near Adelaide are offering salaries 30% above market rates for cyber specialists with machine learning experience. They don't appear in any salary surveys because the roles are never publicly benchmarked.
The weird regional differences nobody talks about
Most recruitment articles treat Australia as one market. It isn't. The Sydney/Melbourne difference is stark enough, but there are fascinating regional patterns emerging.
Brisbane has quietly become a security operations hub, with several global managed security service providers setting up there. Lower cost of living, lifestyle benefits, and Queensland government tech incentives have created a mini-cluster of security employers there.
Perth is experiencing acute shortages in industrial cybersecurity specialists due to the mining and resources sector finally taking OT security seriously after several high-profile incidents.
Canberra remains its own strange bubble, with government agencies and contractors creating an ecosystem that barely connects to the commercial security market in other cities.
The most interesting development? Regional centres like Newcastle, Wollongong and Geelong actively positioning themselves as cybersecurity hubs with university partnerships and local government incentives.
Skills that are actually in demand (not just the buzzwords)
Most job ads mention "cloud security" and "Zero Trust" because recruiters think they have to. The actual shortage is more specific:
-
Implementation experience with the ASD Essential Eight - Not just understanding the framework, but having actually implemented it across an organisation. The gap between theoretical knowledge and practical implementation experience is vast.
-
OT/IT convergence specialists - People who understand both traditional IT networks and operational technology environments are unicorns in this market.
-
Security automation engineers - Australia's talent market can't scale to meet demand through hiring alone. Organisations that can automate security processes have an edge.
-
Supply chain security assessment - With so many Australian organisations dependent on international technology providers, this has become critical.
-
Regulatory translators - People who can interpret compliance requirements and turn them into practical security programmes. Not technically difficult, but requires a rare blend of technical understanding and business communication.
Penetration testers are not in short supply, despite what you might read elsewhere. Despite what you might read elsewhere, the market for junior and mid-level pentesters is actually reasonably balanced. It's the governance, risk and compliance specialists who are commanding the premium.
Why local candidates are winning
Australian firms aren't importing overseas talent at the scale you'd expect given the shortage. Several factors make local candidates more attractive:
-
Security clearance requirements for many roles, especially in critical infrastructure
-
Understanding of the Australian regulatory context
-
Existing networks within the relatively small Australian security community
-
The ability to start immediately rather than waiting for visa processes
International candidates still have opportunities, especially from the UK, New Zealand and Canada, but they're typically looking at a 3-6 month timeline from application to start date. In a market moving this quickly, that's often too slow.
What this means for recruiters and hiring managers
If you're trying to fill cybersecurity roles in Australia right now, standard approaches won't cut it. Some practical advice from what I've observed:
-
Speed is everything - Decision-making processes designed for normal hiring cycles will fail. I've seen candidates receive three offers in the time it takes some organisations to schedule a second interview.
-
Consider adjacent skills - The best security hires I've seen weren't always from security backgrounds. Former software developers, systems administrators and even business analysts with the right aptitude can fill some roles effectively.
-
Benefits beyond salary - With everyone offering high salaries, the differentiators are flexibility, purpose, and development opportunities. One firm offering a sabbatical after three years of service is having remarkable success with mid-career professionals.
-
Invest in development - Growing your own talent is no longer a nice-to-have. It's essential. Several organisations are having success with intensive cyber academies that convert existing staff into security specialists.
Stop asking for certifications that don't exist in combination. I recently saw a job ad requiring candidates to have CISSP, CISM, CCSP and AWS security certification. That unicorn doesn't exist, and if they did, they wouldn't need your job.
The opportunity cost nobody calculates
The bigger problem isn't the roles taking months to fill. It's the security work not happening because organisations can't find people. The projects delayed, the controls not implemented, the monitoring not happening.
Security debt accumulates just like technical debt. And unlike other resource constraints, you might not know you've failed until it's too late.
For recruiters, understanding this bigger picture helps frame the urgency to clients. It's about organisational resilience.
For Australian organisations struggling with this market, there are specialist security recruiters worth connecting with. The OHub's specialist security recruitment service has had success matching hard-to-fill roles with pre-vetted candidates, particularly for those cross-disciplinary positions.
What happens next?
The Essential Eight compliance wave will subside as organisations catch up. The structural shortage will likely persist through 2028, based on university enrolment patterns and the ongoing digitisation of critical infrastructure.
Smart organisations are already thinking beyond the immediate crunch. They're building security talent pipelines through university partnerships, apprenticeship programmes, and internal development pathways.
Some are exploring creative approaches like security job-sharing between smaller organisations that can't justify full-time roles individually. Others are using security-as-a-service models to access expertise they can't hire directly.
But for the next 18-24 months? Expect continued intense competition, salary inflation, and innovation in recruitment approaches. The organisations that adapt fastest to this new reality will build the most effective security teams.