The Security Hire That Keeps Going Wrong

The mid-level security hire fails more often than any other in CNI. The problem is almost never the talent market – it is the spec, the process, and the salary.

Hiring Strategy
Skills & Talent Gaps
July 24, 2026
4
minutes
← Back to Insights

There’s a hire that nearly every CNI security team gets wrong at least once. It’s not the CISO appointment, which gets enough board attention and budget to usually land well. It’s not the graduate intake. It’s the mid-level security hire. The Security Engineer, the SOC Analyst with three to five years’ experience, the GRC professional who’s supposed to bridge the gap between your senior leadership and your operational delivery.

This is the role that sits open for four months, goes through three rounds of interviews with twelve candidates, and either ends in a compromise hire or starts again from scratch in January.

We see it constantly. And the problem is almost never the talent market.

The spec is doing too much

Pull up the last mid-level security job spec your team posted. Count the requirements. Not the nice-to-haves. The stated requirements.

If it’s over fifteen, you’ve written a wish list, not a job description. If it asks for CISSP and three years’ experience in the same paragraph, you’ve contradicted yourself. CISSP requires five years. If it lists both “hands-on technical security engineering” and “stakeholder management at board level,” you’re describing two different people.

We see specs for mid-level roles that read like they were assembled by committee – because they were. The hiring manager wrote the technical requirements. HR added the competency framework language. The CISO appended the strategic bits they wish the role included. The result is a document that describes nobody, and filters out everybody.

The candidates who could do the actual job read the spec and self-select out. The candidates who apply regardless tend to be the ones who’ve learned to ignore requirements they don’t meet, which tells you something about how carefully they’ll read your policies once they’re in the door.

The process is too slow

Mid-level security professionals with genuine CNI experience are not waiting around. When a good candidate enters the market, or even signals they might be open, multiple conversations start immediately. Not in a month. That week.

We regularly see this sequence: a client asks to see candidates, we send three strong profiles, two weeks pass before first-round interviews are scheduled, another week for feedback, another two weeks for second rounds, a week for the offer. Seven weeks, start to finish. By week three, the best candidate has already accepted somewhere else.

The organisations that consistently land mid-level hires have two things in common. Their process from first interview to offer takes under three weeks. And someone with hiring authority is in the first interview – not a screening call with HR, not a cultural fit chat, not a competency-based phone screen. A real conversation with the person they’d actually work for.

Speed isn’t about cutting corners. It’s about respecting the candidate’s time and recognising that you’re competing for it.

You’re hiring for the wrong problem

This is the harder one to hear. Sometimes the mid-level hire keeps going wrong because the role itself is wrong.

A team of eight with a CISO at the top and six junior analysts at the bottom doesn’t need a mid-level hire. It needs a restructure. Dropping someone into the gap between a strategic leader and an operational team without giving them authority, budget, or a clear remit is a setup for failure. They’ll spend a year trying to work out what they’re actually supposed to be doing, and then they’ll leave.

We’ve also seen the pattern where a mid-level hire is really a disguised senior hire. The salary band says £65k–£75k but the responsibilities say £90k. The organisation knows what it needs but won’t pay for it, so it writes a mid-level spec and hopes someone overqualified and undervalued will show up. Occasionally someone does. They don’t stay long.

Being honest about what the role actually requires, and paying accordingly, eliminates most of the misfires we see. The roles that fill cleanly are the ones where there’s a genuine match between the seniority of the work, the seniority of the title, and the seniority of the salary.

The fix is boring

There’s no clever hack here. The organisations that get this right do three things.

They write specs with ten requirements or fewer, all genuine, all things the person will actually do in the first six months. They run a process that gets from first interview to offer in three weeks or less. And they pay the going rate for the level of work they need done, even if that means regrading the role upward and having an awkward conversation with finance.

None of that is exciting. But the alternative is spending four months and a significant amount of internal resource on a process that either produces nobody or produces the wrong person.

Your mid-level hires should be your easiest hires. If they’re your hardest, the spec, the process, or the salary is the problem. Usually all three.

LC
Laurence Connor
Operations Director, Foundations Search
Share this article

Trusted by security leaders at

Datacor logoNomios logoBritish Airways logoForvis Mazars logoEquinix logoJamf logo

Talk To Our Founder

Book a Call

Gyles Whitnall

"I can't recommend Gyles and the team at Foundations enough. We struggled to find a suitable candidate for 5 months, Foundations found 3 perfect candidates in 24 hours."

Manager of EMEA & APAC Network Engineering, Equinix