In the year 2000, the dot-com bubble popped, erasing around 5 trillion dollars in market value from the stock market. Often considered as one of the most devastating events in modern economics, the burst of the dot-com bubble bankrupted hundreds of companies, caused millions to lose their jobs, and decimated a huge chunk of retirement savings among ordinary people. Naturally, many experts in both finance and tech concluded that this signaled the end of tech giants and the internet era as they knew it.
Three years later in 2003, Apple introduced the iTunes Store, recording over 1 million online song downloads in the first two weeks of its release. In hindsight, what was considered at the time to be the end of the internet turned out to be a minor speed bump in a never-ending race of technological developments that continues even in today's era. As if fate intended it, in a year that saw one of the greatest technological comebacks in human history, I was born into this world as well. Today, I am pursuing a career in cybersecurity, a field that I consider to be one of the most underappreciated aspects of modern day technology that built the foundation of the internet as we know it.
Although regarded as one of the most boring career choices in tech, cybersecurity is without a doubt the backbone of the digital world, and one that is becoming increasingly relevant at that. According to the Federal Bureau of Investigation (2025), 859,532 cybercrimes were reported in 2024 in the United States alone, causing an estimated 16.6 billion dollars in losses, yielding a 33% increase from the previous year. More recently, in May of 2026, an extortion group attacked Canvas, resulting in a security breach that impacted an estimated 8,000 universities worldwide – compromising students and professors' user data including names, email addresses, student ID numbers, and private messages between them (Kaleem & Wong, 2026). Naturally, positions in cybersecurity have become increasingly sought-after across many industries as they fight to protect users from these incidents that are growing more common.
Roles within cybersecurity
Cybersecurity can be broken down into a spectrum of roles, ranging from security engineers who design the systems that users depend on to penetration testers who take on the role of hypothetical hackers to see how well those systems were designed. While WorkBC (2025) states that being an information systems specialist mainly entails ensuring that the information stored in systems is protected, the Canadian Cybersecurity Network (CCN) notes that roles are categorised and ranked by popularity in the order of: Operate & Maintain (OM), Oversight & Governance (OV), Securely Provision (SP), Collect & Operate (CO), and Protect & Defend (PR). After analysing 2,448 postings from March 2025 to February 2026, CCN classified these roles according to the National Initiative for Cybersecurity Education (NICE) Workforce Framework, and ranked each category based on its demand in the job market of Canada (McMichael, 2026).
Roles in OM are responsible for handling alerts, monitoring networks, and responding to incidents when they happen. Accounting for 34% of hiring demand in the entirety of Canada, OM positions are the most accessible entry points to those who want to join the industry. OV roles develop policies, ensure regulatory compliance, and lead cybersecurity programmes within organisations. Because of the legal and administrative aspects of OV, roles in this category can be both technical and non-technical, mostly focused on strategy and leadership rather than hands-on work. Accordingly, titles in this category also tend to be further up in the corporate hierarchy, including titles such as chief information security officer (CISO), security manager, compliance specialist, etc. Engineers who work in SP take on the task of designing and building security infrastructures. Because of the level of expertise required for these tasks, not only are roles in this category less accessible, they tend to receive higher pay than the aforementioned groups. This higher pay reflects the amount of work that they have to do, but more importantly the responsibility of building a secure architecture that users can rely on. Professionals in SP work closely with those in CO, who simulate attacks to reveal and thus reinforce spots of vulnerability within the system. As the most offensive and intelligence-focused group of the 5, analysts in CO focus on finding weaknesses before real attackers do, gathering intelligence about threats and probing systems to strengthen them. In this category, most common titles include penetration tester or ethical hacker. Lastly but arguably most importantly, PR specialists are the first respondents to real cyberattacks, hunting for threats and conducting forensic investigations of active incidents in real time. These specialists investigate the source of the attack and ways to mitigate risks of data exposure as they happen (McMichael, 2026).
Salary in Canada
Like most tech industries, cybersecurity positions and their salaries scale with experience. In cybersecurity, this can be seen even in entry-level jobs, as employers generally place more weight on certifications that require experience such as the CISSP or AWS security over formal university education. In the first 2 years of their career, available titles typically include SOC (security operations centre) analyst, cybersecurity analyst, IT support, etc. These roles mostly fall under the OM category, tasked with basic vulnerability scans and monitoring systems for threats (International Information System Security Certification Consortium, 2025). The salary for these entry-level positions can range from around $55,000 to $75,000 per year, which is relatively competitive compared to entry-level positions in other industries (The Canadian College, 2026).
Once they hit the 3–5 year mark, analysts are generally considered to have enough experience to move on from junior roles to heavier mid-level positions – often in more specialised roles such as CO and PR, though many remain in OM or transition into SP. Their new set of tasks would most likely include penetration testing, forensic analysis, and incident response planning (Course Report, 2024). Professionals with these responsibilities usually earn around $65,000 to $90,000 per year (McMichael, 2026).
After around 8–10 years of experience, cybersecurity workers can be expected to be eligible for senior and executive levels, unlocking titles such as senior security architect, CISO, director of information security, etc. Now in SP and OV roles, they will generally be responsible for overseeing entire teams of cybersecurity practitioners, setting security strategies for corporate organisations, and reporting to boards or executive leadership (TechTarget, 2025). Senior professionals at this stage can expect to earn around $80,000 and above, executive-level positions going beyond $200,000 depending on the size of the company (The Canadian College, 2026).
Job Trends
In Canada, Ontario hosts the biggest demand for cybersecurity professionals by far, holding an absolutely massive 57% share of the entire demand market – Toronto accounting for roughly 32% of the national total on its own. Alberta came second at 12.2%, followed by British Columbia closely at 11.9%. While Ontario offers the widest variety and the highest concentration of cybersecurity roles, British Columbia has the lead on salary, with a median of $105,000 compared to Ontario's $102,272 (McMichael, 2026).
However, with an ever-increasing demand for cybersecurity professionals, especially with the developments of AI cybersecurity threats that enable anybody to become an advanced hacker, it seems more than likely that demand will keep rising over the next few years. A study published by ISC2 in 2024 reported that the cybersecurity workforce had a global gap of approximately 4.8 million positions, which was a 19.1% increase from the year prior. This gap represents the number of cybersecurity professionals that are needed across the world and the number of those currently available (ISC2, 2024). While the future remains unpredictable as nature intended, the cybersecurity sector shows no signs of slowing down in the foreseeable future.
References
Course Report. (2024). Cyber Security Career Roadmap: From Junior to Senior Roles. https://www.coursereport.com/blog/cyber-security-career-roadmap-from-junior-to-senior-roles
Federal Bureau of Investigation, Internet Crime Complaint Center. (2025). 2024 Internet Crime Report. https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
ISC2. (2024, October 31). 2024 ISC2 cybersecurity workforce study. https://www.isc2.org/Insights/2024/10/ISC2-2024-Cybersecurity-Workforce-Study
ISC2. (2025, December 4). 2025 ISC2 cybersecurity workforce study. https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study
Labour Market Information Office, Ministry of Post-Secondary Education and Future Skills, Government of British Columbia. (2025). B.C.'s labour market outlook. WorkBC. https://www.workbc.ca/research-labour-market/bc-labour-market-outlook
McMichael, S. (2026, March 9). The State of Cybersecurity Jobs in Canada. Canadian Cybersecurity Network. https://canadiancybersecuritynetwork.com/cybervoices/the-state-of-cybersecurity-jobs-in-canada
Tozzi, Chris. (2025, July 1). Cybersecurity career path: A strategic guide for professionals. TechTarget. https://www.techtarget.com/searchsecurity/tip/Cybersecurity-career-path-5-step-guide-to-success
The Canadian College. (2026). Cybersecurity Career in Canada: Salary & Demand 2026. https://thecanadiancollege.ca/cybersecurity-career-in-canada-salary-demand-2026/
The Silent Battle Fought in Cybersecurity © 2026 by Duhyun Kim is licensed under CC BY-NC 4.0