Most security roles that sit open for months were unfillable the day they were written. The specification asked for three jobs, the seniority was set a level too high, and nobody caught either before it went live.
It is the most fixable of the four reasons security roles sit open, and the one entirely within your control before a single application arrives.
This is the fixable part. A security job posting that describes one real job attracts a shortlist in weeks. One that describes an ideal attracts nobody, and the delay gets blamed on the talent market.
Write the first six months into the security job posting
Start with a narrower question than the one most specifications answer. What will this person actually spend their time on between month one and month six?
If the answer is triaging alerts and improving detection rules, that is the job. Cloud architecture, compliance reporting and vendor assessment might all be things the team eventually needs, and none of them belong in this posting unless they are genuinely part of the first six months.
The test is simple. Read the requirements back and ask whether one person could plausibly have built depth in all of them. If the honest answer is that they would have had to do three different roles to get there, the posting is describing a career rather than a hire.
Separate what is required from what is useful
A security job posting accumulates requirements the way a shared document accumulates comments. Someone adds a certification, someone adds a cloud platform, someone adds a compliance framework, and each addition is individually reasonable.
The cost is invisible and large. Every requirement narrows the pool, and strong candidates self-select out of postings where they miss two or three items, while weaker ones apply regardless. A long requirements list filters for confidence more than competence.
Two lists solve it. Required means the person cannot do the work without it. Useful means it would shorten the ramp. Most security postings have one or two genuine requirements and a long tail of useful, and separating them changes who applies.
Set the seniority to the work
Security work feels important, so titles drift upward. A role that involves running monitoring well gets specified as senior because the consequences of doing it badly are serious.
That costs twice. The people who would have been excellent at it are screened out on years of experience, and the people who match the title get bored inside a year and leave. A correctly pitched intermediate role fills faster and retains better than a senior role that is intermediate work with a bigger number attached.
What the bands actually look like is set out in our breakdown of cyber security salary in Canada, and the gap between advertised and accepted is wider in security than in most disciplines.
Ontario postings now carry compensation, and that changes the draft
Since 1 January 2026, Ontario employers with 25 or more employees must include expected compensation or a range on publicly advertised job postings, and a posted range cannot span more than fifty thousand dollars. The obligation falls away above two hundred thousand.
The practical effect on a security posting is that the range is now a public statement compared directly against everyone else advertising the same work. Posting low to preserve negotiating room is a more expensive strategy than it was, because a candidate deciding whether to apply sees your number next to theirs.
The same rules require disclosure of whether artificial intelligence is used to screen applications, and prohibit Canadian experience requirements. Our guide to Ontario job posting requirements covers the detail, and we publish a compliant job posting template if you would rather start from something that already meets the rules.
Say what the screening will involve
Security candidates who are good at the work are usually employed and cautious about processes that waste their time. Stating the shape of the process in the posting is a filter that works in your favour, and what that process should actually test is covered in our piece on cyber security interview questions.
Two conversations and a technical panel, over ten days, tells a strong candidate that you are organised. Silence tells them nothing, and the ones with options assume the worst. If a clearance requirement is going to add months, say that too, because finding out at offer stage loses the candidate and the goodwill.
The posting is itself a hiring decision
Every choice in a security job posting narrows or widens the field before a single application arrives. The requirements list sets the pool, the seniority sets the retention, the range sets the comparison, and the process description sets whether people with options bother.
Getting those right is most of the difference between a role that fills in six weeks and one still open at Christmas. It is also why we spend the first conversation of a search on the specification rather than on candidates, which is the approach behind our cyber security recruitment work and the reason we push back on postings before we start sourcing.