Skip to content
Regulated Industries · Cybersecurity

The Roles Nobody Can Fill

Seventeen completed cybersecurity searches — always the niche, senior end: cloud IAM, PKI and KMS engineering, threat modelling, penetration testing, security delivery management. The roles you hunt with a candle in Poland. First CVs in 48 hours.

Get Security CVs in 48h See the bench
17 completed searches — as of Q3 2026
8-role cloud-security team currently requested by PwC
48h to first CVs
as of Q3 2026
PwC
Live demand

What PwC Just Asked For

A current, real request on our desk — an eight-role cloud-security team, end to end:

Cloud IAM Security Engineer

AWS · GCP · Azure, IaC, 7+ yrs

Cloud KMS Engineer

Key management, cryptography, K8s

Cloud PKI Engineer

Cloud CA builds, certificate management

Cloud Information Security Officer

NIST · ISO 27001 · risk governance

Cloud Threat Modeller

STRIDE · PASTA · ATT&CK

Technical Delivery Manager

Cloud-security programme delivery

Vulnerability Assessment Tester

Offensive security, cloud pentest

ISRP Analyst

Incident & security-review operations

The common thread across the set: AWS, GCP and Azure security services, Kubernetes, Terraform, and real cryptographic tooling — the profile class that barely exists on the open market. Which is the point of keeping a bench.

The bench

Who Answers When We Call

A working bench of senior security specialists — anonymized here, delivered as blind CVs within 48 hours:

Offensive security

Pentest & Red Team

Senior specialists with published CVEs, red-team leadership at global enterprises, and experience running a 650-project-per-year testing programme.
OSCP · OSEP · CRTOCloud pentest — AWS, GCPRed-team operationsThreat emulation
Cloud security engineering

IAM · PKI · KMS Engineers

15+ year infrastructure-and-cloud profiles: IAM architecture, infrastructure as code, container security across the three major clouds.
AWS certified — SysOps to DevOps ProTerraform & AnsibleKubernetes securityCI/CD hardening
Governance

Cloud Information Security Officers

CISM and ISO 27001 Lead Auditor profiles with 50+ security reviews and risk assessments delivered across banking and health-adjacent sectors.
ISO 27001 · NIST 800Risk assessmentDevSecOpsGRC tooling
Delivery

Security Delivery Managers

14–20 year delivery leaders from global enterprise accounts — cybersecurity programmes, transitions, SLA governance across the DACH region and beyond.
ITIL · PRINCE2 · SAFeSecurity programme deliveryEnterprise transitions

Current bench rate band: 210–310 zł net/h, seniority-dependent — as of Q3 2026. We publish it because a rate band you can check beats a rate card you can't.

Proof · counted honestly

One Hard Search, In Numbers

A senior WAF engineer search, February 2024 — the full funnel, including the part most agencies leave out:

1 · Reach1,528 invited

the entire addressable market

2 · Response~300 replied

positive or negative — 20% of invited

3 · Screening22 interviews held

of 30 scheduled

4 · Shortlist6 sent to the client

fully vetted profiles

5 · The lesson1 client interview

the offer was the constraint, not the market

The market spoke clearly: senior WAF specialists in Warsaw sat above the role's rate cap, and the office requirement halved the pool. We put that on the table at the brief — market truth is part of the service. The recommendations that followed reshaped the role and the search.

Let's talk

Get Security CVs in 48h

Name the role — or the team. First anonymized profiles within 48 hours, and an honest read on whether your rate and remote policy will survive contact with this market.

Get Security CVs in 48h
Insights

More on Security & Compliance

All insights →

FAQ
Which cybersecurity roles do you staff?

The niche, senior end: cloud IAM, PKI and KMS engineering, penetration testing and red teaming, threat modelling, cloud information security officers, ISRP analysts, and security delivery managers. Seventeen completed searches to date — always the roles with the thinnest market.

How fast can you deliver security specialists?

First anonymized CVs within 48 hours from an active bench. Genuinely rare profiles — cloud PKI, senior red team — take longer to close, and we give you the realistic market read at the brief, not after three weeks.

Can you staff a full security team, not just single roles?

Yes — the current PwC request on our desk is exactly that: an eight-role cloud-security team from IAM engineering through threat modelling to delivery management, sourced as a coherent unit.

What if our budget is below the market for the role?

We tell you at the brief — with data. Our published funnel shows what happens when an offer sits below the market: 1,528 invitations become one client interview. The honest conversation about rate, remote policy and role scope is where every hard security search should start.

Talk to us

Two Ways to Start

Put a slot in a calendar, or send the brief and we will come back to you. Either way you are talking to a partner, not a queue.

Book a call

Thirty minutes, no deck. Whoever's calendar suits you — they take the call themselves.

Michał Stawski
Managing Partner
Book 30 min →
Bartłomiej Lewandowski
Managing Partner
Book 30 min →

Send a message

Roles, platform, headcount, timeline. A link to a brief is even better.

Goes straight to the partners' inbox. No newsletter, no sequence.