The mid-level security hire fails more often than any other in CNI. The problem is almost never the talent market – it is the spec, the process, and the salary.
← Back to Insights
There’s a hire that nearly every CNI security team gets wrong at least once. It’s not the CISO appointment, which gets enough board attention and budget to usually land well. It’s not the graduate intake. It’s the mid-level security hire. The Security Engineer, the SOC Analyst with three to five years’ experience, the GRC professional who’s supposed to bridge the gap between your senior leadership and your operational delivery.
This is the role that sits open for four months, goes through three rounds of interviews with twelve candidates, and either ends in a compromise hire or starts again from scratch in January.
We see it constantly. And the problem is almost never the talent market.
Pull up the last mid-level security job spec your team posted. Count the requirements. Not the nice-to-haves. The stated requirements.
If it’s over fifteen, you’ve written a wish list, not a job description. If it asks for CISSP and three years’ experience in the same paragraph, you’ve contradicted yourself. CISSP requires five years. If it lists both “hands-on technical security engineering” and “stakeholder management at board level,” you’re describing two different people.
We see specs for mid-level roles that read like they were assembled by committee – because they were. The hiring manager wrote the technical requirements. HR added the competency framework language. The CISO appended the strategic bits they wish the role included. The result is a document that describes nobody, and filters out everybody.
The candidates who could do the actual job read the spec and self-select out. The candidates who apply regardless tend to be the ones who’ve learned to ignore requirements they don’t meet, which tells you something about how carefully they’ll read your policies once they’re in the door.
Mid-level security professionals with genuine CNI experience are not waiting around. When a good candidate enters the market, or even signals they might be open, multiple conversations start immediately. Not in a month. That week.
We regularly see this sequence: a client asks to see candidates, we send three strong profiles, two weeks pass before first-round interviews are scheduled, another week for feedback, another two weeks for second rounds, a week for the offer. Seven weeks, start to finish. By week three, the best candidate has already accepted somewhere else.
The organisations that consistently land mid-level hires have two things in common. Their process from first interview to offer takes under three weeks. And someone with hiring authority is in the first interview – not a screening call with HR, not a cultural fit chat, not a competency-based phone screen. A real conversation with the person they’d actually work for.
Speed isn’t about cutting corners. It’s about respecting the candidate’s time and recognising that you’re competing for it.
This is the harder one to hear. Sometimes the mid-level hire keeps going wrong because the role itself is wrong.
A team of eight with a CISO at the top and six junior analysts at the bottom doesn’t need a mid-level hire. It needs a restructure. Dropping someone into the gap between a strategic leader and an operational team without giving them authority, budget, or a clear remit is a setup for failure. They’ll spend a year trying to work out what they’re actually supposed to be doing, and then they’ll leave.
We’ve also seen the pattern where a mid-level hire is really a disguised senior hire. The salary band says £65k–£75k but the responsibilities say £90k. The organisation knows what it needs but won’t pay for it, so it writes a mid-level spec and hopes someone overqualified and undervalued will show up. Occasionally someone does. They don’t stay long.
Being honest about what the role actually requires, and paying accordingly, eliminates most of the misfires we see. The roles that fill cleanly are the ones where there’s a genuine match between the seniority of the work, the seniority of the title, and the seniority of the salary.
There’s no clever hack here. The organisations that get this right do three things.
They write specs with ten requirements or fewer, all genuine, all things the person will actually do in the first six months. They run a process that gets from first interview to offer in three weeks or less. And they pay the going rate for the level of work they need done, even if that means regrading the role upward and having an awkward conversation with finance.
None of that is exciting. But the alternative is spending four months and a significant amount of internal resource on a process that either produces nobody or produces the wrong person.
Your mid-level hires should be your easiest hires. If they’re your hardest, the spec, the process, or the salary is the problem. Usually all three.
Trusted by security leaders at



"I can't recommend Gyles and the team at Foundations enough. We struggled to find a suitable candidate for 5 months, Foundations found 3 perfect candidates in 24 hours."
Manager of EMEA & APAC Network Engineering, Equinix