Companies need people who understand industrial protocols and IoT device management, not generic IT security generalists. Think OT security engineers who can work with SCADA and PLC networks, and IoT specialists who handle asset discovery and firmware on connected devices. These are different skill sets from a typical SOC analyst.
An OT security engineer needs to understand how a production line actually runs before they can secure it. Segmentation on an industrial network isn't the same exercise as segmentation in a corporate data center. You're dealing with legacy equipment that can't just get patched on a Tuesday night, because patching it wrong might stop a machine mid-cycle.
IoT security specialists focus on a different problem: hundreds or thousands of small connected devices, cameras, sensors, access control systems, each with its own firmware, its own certificate lifecycle, its own blind spots. Nobody budgeted headcount for managing that inventory. Now they have to.
Then there's the compliance layer. Cyber risk managers who can translate NIS2 obligations into actual controls and evidence are becoming just as scarce as the technical specialists. They're the ones who sit between the CISO, operations, facilities and legal, and make sure the whole thing is documented well enough to survive an audit.
Roles like this show up more often now on our own information security analyst vacancies, where the OT and compliance angle has become a normal part of the brief instead of an edge case.