Cyber Security Recruitment Sydney: Stop Hiring the Job Title

Somewhere in Australia, a cybercrime report is filed every six minutes. Your approval chain meets fortnightly.

That gap is the whole problem. If cyber security recruitment in Sydney feels impossible at the moment, the market is rarely the reason. The pool is not empty. It is fragmented into specialisms that do not answer to a single job title, and a generic brief cannot see any of them. The fix is unglamorous and it works: name the specific failure you are hiring to prevent, write the brief around that failure, and shorten your decision window to days rather than months. Do that and roles that sat open for a quarter start closing.

The numbers behind the six minute figure come from the Australian Signals Directorate. In its Annual Cyber Threat Report 2024-25, released in October 2025, the ASD recorded more than 84,700 cybercrime reports to ReportCyber across FY2024-25, which averages one report every six minutes. Reports were actually down 3 per cent on the prior year. What went up was the damage.

Figures cited below are as published by the Australian Signals Directorate, the Australian Bureau of Statistics and the Australian Computer Society on the dates named, current as of July 2026.

What is the loss data actually telling you to hire for?

The ASD Annual Cyber Threat Report 2024-25 puts the average self-reported cost of cybercrime per business report at $80,850, up 50 per cent year on year. Split by size, the pattern gets more interesting:

  • Small business: $56,600 per report, up 14 per cent
  • Medium business: $97,200 per report, up 55 per cent
  • Large business: $202,700 per report, up 219 per cent

Read that last line again. Reports fell. Costs at the large end more than tripled. That is not a story about volume, it is a story about blast radius. The same class of intrusion is simply doing far more damage once it lands, because it lands inside environments with more identities, more integrations and more data to hold hostage. The ASD also found that 11 per cent of incidents it responded to involved ransomware, consistent with the year before.

Blast radius is governed by three things: how fast you notice, how tightly identity is controlled, and how quickly you can restore. Those are three different capabilities, held by three different types of engineer, who read three different job ads. Advertising for a “Cyber Security Engineer” and hoping is how you end up interviewing forty people and hiring none of them.

The composite brief that empties its own pipeline

The following is a composite drawn from a pattern we see repeatedly across Sydney technology teams. It is illustrative rather than a single named engagement.

A Series B scaleup, roughly 140 staff, decides it needs security leadership. The board has asked a question after a customer’s supplier was breached, and the answer that came back was uncomfortable. So a role goes out: Head of Security. Broad remit, competitive package, reporting to the CTO.

Twelve weeks later there is nothing. Plenty of conversations, two offers, both declined. The internal verdict forms quickly and comfortably: there is a shortage, nobody good is available, we will try again next quarter.

Then someone finally asks the founder what the board actually said. It was one sentence. If we were hit with ransomware on a Friday, could we have customers back online by Monday?

That is not a Head of Security question. Nobody solves that by hiring a leader who will spend their first two quarters writing a strategy and building a function. That question is answered by an engineer who owns detection and response tooling, and a platform engineer who tests backup restoration on a schedule and can prove the restore time. Two hires, both with deep and findable candidate pools in Sydney, both fillable in weeks. The generic brief was not competing against a shortage. It was competing against every other company in the country running the same vague search, while the two roles that would have actually answered the board’s question were never advertised.

Which cyber roles should you actually be advertising?

Scope to the failure mode and the market reappears. In practice, most Sydney hiring problems resolve into one of four briefs.

Detection and response. This is the “how fast do we notice” hire. Someone who lives in your logging and SIEM tooling, tunes alerts so people stop ignoring them, and runs the playbook when something fires. Hire this when your honest answer to “how would we find out” is “a customer would tell us”.

Identity and access. The unglamorous one that moves risk most. Privileged access, service accounts, joiner and leaver processes, multifactor coverage that is actually enforced rather than merely available. Given how much of the cost escalation at the large end tracks with sprawling access, this is frequently the highest value hire on the list and the one most often deferred.

Cloud and security platform engineering. Closest in shape to the platform engineering roles you may already be hiring, and adjacent to the software engineering recruitment you run today. Infrastructure as code, secrets management, build pipeline integrity, and the restoration testing that turns a backup policy into a provable recovery time. The candidate pool here overlaps heavily with general infrastructure engineering, which means it is far larger than the security specific pool most briefs target.

Governance, risk and assurance. The hire you make when the pressure is contractual rather than technical: enterprise customers sending security questionnaires, certification work, supplier assessments. Different people entirely. Do not bundle this into a technical brief and expect either half to be done well.

Any one of these can be written, priced and filled. All four bundled into a single title cannot, because the person who is excellent at three of them does not exist in the volume your timeline assumes. If you are unsure which of the four you need, our roles we cover page is a reasonable place to sanity check the shape of the brief.

Why your decision window matters more than your salary band

The Australian labour market is not what is stopping you. ABS Labour Force, Australia, June 2026 put the seasonally adjusted unemployment rate at 4.4 per cent, with participation at 67.0 per cent and underemployment at 6.5 per cent. Tight, but not seized.

The relevant constraint is behavioural. Strong cyber candidates in Sydney are almost always employed, rarely applying, and typically holding two or three conversations at once when they do move. In that setting, a four stage process with a fortnightly approval committee is not thoroughness. It is a slow forfeit.

Three changes do most of the work:

  1. Band the role and get the money signed off before the first advertisement goes out. Discovering your ceiling at offer stage costs you the candidate and the eight weeks.
  2. Run two stages, not four. One technical conversation grounded in your actual environment, one with the people the hire will work beside daily.
  3. Commit to a decision inside ten working days from first conversation, and tell candidates that up front. It is a genuine differentiator, and it costs nothing.

This is not going to ease. ACS Australia’s Digital Pulse, released October 2024, forecasts that Australia will need 1.3 million technology workers by 2030, against a workforce that passed one million in 2024, and specifically flags cyber security demand as set to double by 2030. The teams that build a habit of fast, narrow, well scoped hiring now will simply be better at it when the competition intensifies.

Do this one thing this week

Take whichever cyber role you currently have open. In one sentence, write down the specific incident you are hiring to prevent, and the evidence you would accept that it can no longer happen.

If you can write that sentence, you have a brief, and probably a narrower and more fillable one than the job title you started with. If you cannot write it, the role is not ready to advertise, and no amount of market activity will fix that.

Big Wave Digital has been recruiting specialist technology talent in Sydney since 2010, across IT recruitment, engineering, data and security. If you would like a second opinion on how a cyber role is scoped before it goes to market, start a conversation with us.

Frequently asked questions

Is there really a cyber security skills shortage in Australia?

Demand is genuinely outpacing supply. ACS Australia’s Digital Pulse, October 2024, forecasts 1.3 million technology workers needed by 2030 and identifies cyber security demand as set to double over that period. That said, most stalled searches we see are not caused by absolute scarcity. They are caused by briefs so broad that no realistic candidate matches them.

Should you hire a Head of Security or a specialist engineer first?

It depends on whether your pressure is strategic or operational. If the board wants a security function, a risk framework and a multi-year plan, hire the leader. If the pressure is a specific exposure, such as detection speed or recovery time, hire the specialist who removes that exposure. Hiring a leader to solve an operational problem usually adds six months before anything changes.

How long should a cyber security hire take in Sydney?

Plan for roughly four to eight weeks from a well scoped brief to an accepted offer. Expect that to stretch considerably if approvals sit with a monthly committee, if the salary band is unconfirmed when you advertise, or if the brief covers more than one specialism.

Do candidates need certifications for cyber security roles in Australia?

Certifications help with shortlisting and are often mandatory for government and regulated work, particularly where security clearance is involved. For most commercial roles they are a signal rather than a requirement. Demonstrated incident experience in an environment resembling yours is the stronger predictor.

Sources

Share this blog