CTI Academy
Log in Create account

The CTI & EASM Job Market in 2026: What 1,000 Job Postings Actually Show

By CTI Academy Team

We analyzed 1,000 cybersecurity job postings for CTI and EASM roles to see what employers actually ask for, how it changes by seniority, and what it pays.

Most "how to break into cybersecurity" advice is written from a hunch. We wanted numbers instead, so we scanned 1,000 live job postings across 20 country and role searches, then went deep on a detailed sample of 214 Cyber Threat Intelligence (CTI) postings and 54 External Attack Surface Management (EASM) postings to see exactly what employers ask for, how that changes as you get more senior, and what it actually pays. This post is that research, plus what it means if you're deciding where to start.

Why We Analyzed 1,000 Job Postings

CTI Academy already teaches Cyber Threat Intelligence, OSINT, HUMINT, and Attack Surface Management as separate learning paths. Before we scoped what each one covers, we wanted to check our assumptions against what the market is actually hiring for right now, in 2026, rather than what a certification syllabus said five years ago.

So the curriculum behind our Cyber Threat Intelligence and Attack Surface Management paths was reviewed against this same data. This post is the research itself, published in full rather than kept as an internal scoping document.

The Cybersecurity Talent Gap Isn't Closing

The hiring backdrop matters before the skill data does. The 2025 ISC2 Cybersecurity Workforce Study (16,029 professionals surveyed globally) found that 59% of organizations now report a "critical or significant" skills shortage, up sharply from 44% the year before, and 95% reported at least one skill gap on their team. AI topped the list of most critical gaps at 41%, ahead of cloud security and risk assessment.

The 2025 ISACA State of Cybersecurity report puts a number on how long that gap stays open: 58% of organizations report being understaffed, and nearly 40% of non-entry-level roles take six months or longer to fill.

Key Takeaway

Neither report breaks its numbers out specifically for threat intelligence roles, so treat this as the general backdrop CTI and EASM hiring sits inside, not a CTI-specific statistic.

What CTI Employers Actually Ask For

Across the 214 detailed CTI postings, ten skills came up far more often than everything else. Reporting and briefing appeared in 95% of listings, ahead of every technical skill on the list, and threat actor, TTP, and campaign analysis followed at 90%.

Bar chart showing the share of 214 CTI job postings requiring each skill: reporting and briefing 95%, threat actor and campaign analysis 90%, detection engineering 52%, IOC and infrastructure analysis 50%, MITRE ATT&CK 49%, SOC and incident response integration 49%, OSINT 41%, intelligence lifecycle 41%, network and DNS analysis 41%, data analysis and SQL 40%

Two things stand out. First, the two most-requested skills are both about communication and judgement, not tooling: an employer wants an analyst who can tell them what happened and why it matters, before they care what platform you used to find it. Second, MITRE ATT&CK sits at 49%, not 90% or higher, despite being the framework most CTI courses lead with. It's expected, not universal.

Detection engineering (52%) and SOC/incident response integration (49%) are the two skills most likely to surprise someone coming from a pure research background: over half of CTI postings expect you to connect what you found to something a defensive team can actually act on, not hand off a report and move on.

What EASM Employers Actually Ask For

External Attack Surface Management reads as a much narrower, more consistent job description. Three skills appeared in literally every one of the 54 detailed postings we sampled: exposure metrics and reporting, remediation workflow, and vulnerability validation or prioritization.

Bar chart showing the share of 54 EASM job postings requiring each skill: exposure metrics and reporting 100%, remediation workflow 100%, vulnerability validation and prioritization 100%, asset discovery 74%, DNS and TLS fundamentals 74%, EASM tooling 74%, external attack surface 74%, recon and enumeration 74%, shadow IT and asset attribution 74%

Read that as a job description in plain English: find the assets, prove which findings are real and which ones are noise, and get someone to actually fix it. A cluster of six more skills (asset discovery, DNS/TLS fundamentals, EASM tooling, external attack surface concepts, recon/enumeration, and shadow IT attribution) each appeared in about three of every four postings, which is the technical-discovery half of the job. Discovery and remediation are treated as one job here, not two, which is worth knowing before you assume "I can find subdomains" is the whole role. See our full ASM guide for how the discovery half actually works, or start the Attack Surface Management learning path to build both halves.

How the Skillset Changes as You Advance

The same skill can mean something very different depending on the seniority level attached to the posting. We mapped four CTI skills against the "Entry" and "Advanced" tiers in our sample, and the shift is close to a full reversal.

Dumbbell chart showing entry versus advanced skill demand: OSINT drops from 63% to 26%, scripting and Python rises from 22% to 63%, detection engineering rises from 15% to 67%, network and DNS analysis rises from 15% to 53%

OSINT is what gets you in the door: 63% of entry-level postings ask for it, and that falls to 26% at the advanced tier, not because it stops mattering but because it stops being the thing that differentiates you. Scripting and Python (22% → 63%), detection engineering (15% → 67%), and network/PCAP/DNS analysis (15% → 53%) all move the opposite direction. The practical reading: research skills get you hired, automation and defensive-integration skills get you promoted.

What These Roles Actually Pay

Compensation data disagrees with itself more than most people expect, so we're giving you the range rather than a single number. Glassdoor puts the average CTI Analyst salary at roughly $159,683/yr (25th–75th percentile: $125,987–$204,910), rising to about $216,200/yr average for a Senior CTI Analyst. Payscale's figure for a Threat Intelligence Analyst is notably lower, averaging around $75,000/yr base with a $51k–$140k range. The U.S. Bureau of Labor Statistics' broader "Information Security Analyst" category (which is not CTI-specific) sits in between at a $129,180/yr median as of May 2025.

EASM/Attack Surface roles run a wide band too: aggregator data (ZipRecruiter) shows roughly $66,000–$142,000 for entry-to-mid roles and $99,000–$225,000 at senior level, though these are job-posting-derived figures rather than a formal salary survey, so treat them as directional.

Why the spread? Different sources mix seniority levels differently, and "threat intelligence" job titles vary wildly in scope between companies. For a full breakdown by experience level and region, see our dedicated Threat Intelligence Analyst Salary Guide.

Is This Job Market Actually Growing?

By the BLS's numbers, yes: information security analyst employment is projected to grow 21% from 2025 to 2035, with roughly 14,100 average annual openings, both well above the average for all occupations.

EASM specifically looks like the faster-growing sub-market. Market-sizing estimates vary a lot by research firm, but cluster around $1.0–1.5 billion in 2025, with growth projections in the 26–31% CAGR range depending on whose model you use. Gartner's Continuous Threat Exposure Management (CTEM) framework is a big part of why: Gartner has projected that by 2026, organizations that prioritize security investment through a CTEM program will be three times less likely to suffer a breach, and separately found 60% of organizations already pursuing or considering one. Treat the exact multiplier as a forward-looking industry projection rather than a settled fact, since it's most often relayed through vendor commentary rather than Gartner's own published report directly.

The AI Wrinkle: Why Entry-Level Is Getting Harder

This is the least settled part of the data, and worth flagging as industry commentary rather than hard research: several sources report that roughly 64% of 2026 cybersecurity job listings now ask for some AI/ML skill, and ISC2 separately names AI/ML and cloud security as the two most in-demand skill areas for 2026.

The consistent theme across industry writeups (not an academic study) is that AI is absorbing a growing share of Tier-1 SOC triage, which raises the floor for what a junior analyst is expected to already know, rather than lowering it. A pattern worth naming plainly: a meaningful share of organizations report making zero entry-level security hires in 2026, in the same breath as naming talent shortage as their top challenge. That is a real hiring paradox, and it's one more reason the CTI skill data above matters: if reporting, ATT&CK, and OSINT are the actual entry bar rather than a checklist of tools, that's a more useful thing to optimize for than "learn every SIEM."

Certifications: What's Actually Recognized

On the CTI side, two certifications come up consistently: GIAC's GCTI (tied to the SANS FOR578 course, covering strategic through tactical intelligence, intrusion and malware analysis, and indicator pivoting) is the most established, with EC-Council's CTIA (Certified Threat Intelligence Analyst) positioned as a more hands-on, more accessible alternative built around the intelligence lifecycle and scripting labs.

On the EASM side, there currently isn't a dedicated EASM certification from GIAC, CompTIA, EC-Council, or ISC2. That's not an oversight in our research, it's a real gap: EASM is growing faster than certification bodies have caught up to, which means hands-on tooling experience currently substitutes for a credential in a way it doesn't yet for CTI.

Our Methodology

We scanned 1,000 visible job-card listings across 20 country and role searches to get a sense of title and market diversity, then built a detailed, weighted skill analysis from a sample of postings whose descriptions were specific enough to code reliably: 214 for CTI, 54 for EASM. A skill was only marked present when the posting's description, requirements, or responsibilities gave explicit evidence for it, never inferred from the job title alone. Duplicate postings (the same description reposted across locations or job boards) were counted once toward the skill percentages, so the same listing can't inflate a number by appearing on three job boards. "Entry" was read as junior/associate-level titles, "Advanced" as senior/lead/principal/staff or postings with clear, deep technical ownership.

We're intentionally not claiming more precision than the data supports: this is a scan for coverage and priority signal, not a claim that we parsed 1,000 full job descriptions and can tell you the exact percentage of the entire market that wants a given skill.

What This Means If You're Starting Out

If you're deciding where to begin: reporting, source evaluation, and OSINT get you into a CTI seat; asset discovery and vulnerability triage get you into an EASM one. Neither path expects you to already know a specific vendor's SIEM or scanner. Both expect you to already be comfortable with the fundamentals covered in Cybersecurity Foundations before you specialize.

From there: Cyber Threat Intelligence and Open Source Intelligence (OSINT) build the research and analytic-tradecraft side this data says gets you hired; Human Source Collection for CTI covers the human-reporting skills that show up alongside OSINT in real CTI work; and Attack Surface Management builds the discovery-to-remediation skillset EASM postings actually ask for.

Further Reading

Continue with the Cyber Threat Intelligence Learning Path

Start Learning Path

Related Articles

Read more at CTI Academy Blog