Who gets hired, and why
Security
Java backend
Test
Cloud and DevOps
C/C++ systems
Go backend
GenAI
Frontend
Software Engineer, Security. These are software engineers who specialise in security, building login systems, cloud and network protections, and the checks that keep code safe. In a security product company the role is not about guarding the company's own systems. It is about building security into the product that customers buy. The work splits four ways.
Cloud security and DevSecOpsThis is the largest part. Engineers secure cloud platforms and the pipelines that ship code, with Terraform and cloud-security tools such as Prisma Cloud.
Identity and accessEngineers build login, single sign-on and permissions on standards such as OAuth, SAML, OpenID Connect, SCIM and LDAP.
Application securityEngineers find and fix weaknesses in software, which is the core of scanning products.
Network securityEngineers work with TCP/IP, firewalls and the inspection of network traffic.
Most of these postings also require real programming in Python, Java or Go, and many require database skills, because security software engineers here write product code.
Java backend engineers. Behind most security products sits a large backend shared by many customers. Java engineers build it, whether it is an identity and certificate service, a vulnerability-management platform or privacy and compliance software. They are the most common opening in cybersecurity, in roughly the same proportion as across product companies, and the stack is Java and Spring Boot with Kafka, on AWS and Kubernetes.
Test engineers. A security product that fails lets an attacker in, so testing carries extra weight here, and testers are hired more often than at most product companies. Most of them test the products as software, automated in Java and Python with Playwright and Selenium. Some test network appliances and traffic handling on real equipment. Many postings also require security testing, meaning checks that the product itself resists attack.
Cloud and DevOps engineers. Many security products now run as cloud services that sit in the path of their customers' traffic, so they must never go down. That raises the demand for cloud and DevOps engineers above the level at most product companies. The postings require Python and Go as often as AWS, Kubernetes and Terraform, and many add security responsibilities.
C/C++ systems engineers on Linux. A firewall has to inspect every packet without slowing the network down. Writing that code is the work of C/C++ systems engineers, who are concentrated in network security. They build the packet-inspection path of firewalls and cloud gateways, VPN and proxy engines, and agents that run deep inside the operating system of laptops and servers. The postings require TCP/IP, NAT, DNS, HTTP, IPSec, DPDK and the Linux kernel.
Go backend engineers. Much of the newer security software is written in Go, including cloud gateway services, scanners that check how cloud accounts are configured, back ends for managing devices and certificate services. That makes Go engineers a distinctive group here, far more common than at a typical product company.
GenAI engineers. GenAI engineers build AI assistants inside security consoles, AI that sorts and prioritises alerts, and agents that investigate a threat, in Python on the major clouds. Their share of hiring is close to that at other product companies, and it is rising, as described below.
Frontend engineers. Analysts and administrators spend their day in security consoles, reading alerts and managing policies. Frontend engineers build those consoles, mostly in React, and they are hired in about the same proportion as elsewhere.
Rare here. Data engineering, .NET, mobile, SAP and ServiceNow each appear, but none is central to what cybersecurity companies build.
Where in the Industry Vertical the work is
Cybersecurity has fifteen Market Segments, and the hiring is concentrated in a few of them.
Market Segment 4.5Network security, firewalls and SASE hires the most. It is also the most systems-heavy, with C/C++ engineers for the code that inspects traffic in firewalls and gateways, cloud engineers for security delivered from the cloud, and testing at scale.
Market Segment 4.2Identity and access management (IAM) is the clear second. It is the most Java-heavy, with identity and access (IAM) engineers beside the Java engineers, and mobile engineers for authenticator apps.
Market Segment 4.11Vulnerability management and penetration testing comes next. Java engineers and security software engineers build vulnerability scanners there, and the work is centred on Pune.
Five Market Segments hire at a modest level. They are 4.4 Endpoint security and device management, 4.1 Email security and anti-phishing, 4.14 Governance, risk and compliance (GRC), 4.7 Application and API security and 4.3 KYC, identity verification and fraud prevention.
The rest hire little under their own companies' names. They are 4.8 Data security and privacy, 4.9 SIEM and security operations (SOC), 4.10 Managed security services (MDR and MSSP), 4.12 Threat intelligence and attack surface management, 4.13 AI security and 4.6 Cloud and SaaS security. The largest cloud-security companies, Zscaler, Palo Alto Networks and Netskope, are counted where they live, in Market Segment 4.5.
Some companies listed in cybersecurity have their main home elsewhere. Among them are Cisco, Juniper and Aruba (Industry Vertical 1, Networking and telecom), Ivanti (Market Segment 16.1, in Industry Vertical 16), JFrog (Market Segment 6.1, in Industry Vertical 6, Devtools companies) and LexisNexis Risk Solutions (Market Segment 18.3, in Industry Vertical 18, Lending and credit). Their hiring is described where they live, not here.
Bengaluru has most of the work. Pune is a strong second, mainly through vulnerability management, and Hyderabad is third.