Where have all the cyber engineers gone? Exploring the Cybersecurity Engineer Role in Cybersecurity Workforce Frameworks
This paper explores the role of a cybersecurity engineer within existing cybersecurity workforce frameworks. It specifically compares how the NIST NICE Framework, the European Cybersecurity Skills Framework (ECSF), and the UK Cyber Security Council (UKCSC) pathways align with and diverge from the cybersecurity engineer job title. The research employs a machine learning methodology to analyze job advertisements from LinkedIn against these frameworks to identify commonalities in required Tasks, Knowledge, and Skills (TKS). The central finding suggests that while the engineer title is highly in demand, its functions are distributed across multiple work roles in these frameworks, with US-based frameworks focusing more on technical abilities and breach prevention, while UK/EU frameworks emphasize operational roles and risk assessment. Ultimately, the paper seeks to make recommendations for creating a distinct and standardized cybersecurity engineer career field to address workforce planning gaps.