GCC's Cybersecurity Talent Crisis: Why HR Leaders Must Own the Strategy — Not Just Fill the Roles
By Chris Weinmann, Founder, OVI
The UAE's cybersecurity workforce is caught in a double bind. Nearly 90% of employers report difficulty hiring qualified cybersecurity professionals, according to Security MEA's August 2026 analysis. Specialist salaries are climbing 15–18% annually, expat cybersecurity turnover exceeds 20%, and Dubai alone has approximately 1,586 active cyber vacancies — with hiring demand up over 60% year-on-year. Meanwhile, the UAE's National Cybersecurity Strategy 2025–2031, approved in February 2025 by the Telecommunications and Digital Government Regulatory Authority (TDRA), has placed workforce development as one of six formal state pillars, creating compliance-driven hiring mandates across banking, energy, health, and telecoms.
This is no longer a problem IT departments can solve alone. For HR leaders across the GCC, cybersecurity hiring has become a strategic talent crisis that demands new screening rubrics, new role architectures, and a fundamentally different approach to workforce planning.
The Scale of the Gap: UAE and Saudi Arabia
The numbers tell a stark story. Globally, the ISC2 2025 Cybersecurity Workforce Study found that 95% of cybersecurity professionals report at least one skills gap in their organisation, with 59% citing shortages at critical or significant levels. AI-related skills topped the list, identified by 41% of respondents as the number-one workforce need.
The World Economic Forum's Future of Jobs 2025 report ranks network and cybersecurity as the second fastest-growing skill category globally, with information security analyst roles projected to grow 29% through 2034.
In the UAE, that global pressure is amplified. The country's National Cybersecurity Strategy explicitly mandates workforce development across regulated sectors — banking, energy, healthcare, and telecommunications — creating a compliance floor beneath what was already intense market demand. The WEF has noted the UAE's position as a regional cybersecurity leader, but leadership requires talent, and talent is in critically short supply.
In Saudi Arabia, the gap is equally pressing. Industry aggregator IMARC Group estimates the Kingdom faces a 47% talent gap, with approximately 35,000 unfilled cybersecurity roles against roughly 21,000 active professionals. (Note: these figures are from an IMARC market aggregation and should be treated as directional estimates, not primary government statistics.) Named employers including Saudi Aramco and STC — through its cybersecurity subsidiary sirar by stc — are actively recruiting AI-augmented security professionals.
Three Emerging AI-Security Hybrid Roles Dominating GCC Demand
AI isn't just creating the skills gap — it's fundamentally reshaping the roles themselves. Fortinet's 2025 Global Cybersecurity Skills Gap Report found that 97% of organisations are already using or planning to deploy AI-enabled cybersecurity tools, yet 48% cite lack of AI expertise as the top barrier to implementation.
For HR teams, this means job descriptions written even 18 months ago may already be obsolete. Three hybrid roles are emerging at the intersection of AI and cybersecurity, and each requires screening rubrics that most HR functions do not yet have:
1. AI Security Engineer
These professionals protect GenAI platforms, large language model APIs, and AI-driven infrastructure against prompt injection, data leakage, and model manipulation. They need deep expertise in application security combined with knowledge of AI/ML model architectures and adversarial attack vectors.
What HR teams should screen for: Experience securing AI/ML pipelines; familiarity with OWASP Top 10 for LLM applications; understanding of data governance in AI contexts. Traditional cybersecurity certifications (CISSP, CEH) are necessary but not sufficient — look for candidates who can articulate AI-specific threat models.
2. Threat Intelligence / ML Detection Specialist
These specialists build and operate model-based threat detection within Security Operations Centres (SOCs), moving from rule-based alert systems to machine-learning-driven threat hunting. They combine cybersecurity domain knowledge with applied data science.
What HR teams should screen for: Experience with SIEM/SOAR platforms combined with ML model development or tuning; ability to translate threat intelligence into detection models; track record of reducing false-positive rates through algorithmic approaches rather than manual rule-writing alone.
3. AI Governance / GRC+AI Analyst
The most compliance-critical of the three, these roles bridge Governance, Risk, and Compliance (GRC) with AI auditing — aligning AI deployments to frameworks including the UAE's Information Assurance Standards (IAS) and Saudi Arabia's National Cybersecurity Authority (NCA) regulations.
What HR teams should screen for: GRC certification (CISA, CRISC, or equivalent) combined with demonstrable understanding of AI audit methodologies; ability to map AI system outputs to regulatory requirements; experience with compliance documentation for AI systems in regulated industries.
In the UAE, employers at the forefront of this shift include G42, e& (formerly Etisalat), ADNOC, EDGE Group, and the Dubai Electronic Security Center (DESC) — all actively building teams that blend AI expertise with cybersecurity foundations.
What's Being Automated — and What Remains Human-Critical
AI is not replacing cybersecurity professionals wholesale, but it is automating specific tasks that have traditionally consumed junior analyst bandwidth:
- Basic log analysis — AI-driven tools now parse and correlate log data faster than human analysts, reducing the manual review burden.
- Tier-1 SOC alert triage — Initial alert classification and prioritisation is increasingly handled by AI, filtering signal from noise before human analysts engage.
- Vulnerability scanning — Automated scanning tools have matured to the point where routine vulnerability identification requires less human oversight.
For HR leaders, this automation has direct implications for job description design, skills assessment, and role scoping:
JD design: Entry-level cybersecurity roles focused primarily on log review and alert triage are shrinking. New JDs should emphasise analytical judgment, AI tool orchestration, and exception-handling skills rather than rote monitoring capabilities.
Skills assessment: Traditional technical assessments that test manual log parsing or basic scanning proficiency are becoming less relevant as differentiators. Assessment rubrics should evaluate a candidate's ability to interpret AI-generated threat intelligence, tune detection models, and make escalation decisions that AI cannot.
Role scoping: The cybersecurity team of 2027 needs fewer tier-1 analysts and more professionals who can operate at the intersection of AI tooling and human judgment — validating AI outputs, investigating complex incidents that automated systems flag but cannot resolve, and governing the AI systems themselves.
Actionable Guidance for GCC HR Leaders
For talent acquisition and HR leaders operating in GCC regulated sectors — particularly in the UAE and Saudi Arabia — the cybersecurity hiring challenge demands a shift in both strategy and execution:
Rebuild screening rubrics for hybrid roles. Legacy cybersecurity hiring frameworks centred on certifications and years of experience are insufficient for AI-security hybrid positions. Develop rubrics that assess AI fluency alongside cybersecurity fundamentals. Scenario-based assessments — asking candidates to walk through an AI-specific incident response or to evaluate an ML detection model's output — will surface capability that credential checks miss.
Align hiring to national strategy mandates. The UAE's National Cybersecurity Strategy 2025–2031 creates regulatory compliance obligations that flow directly into workforce planning. HR teams in regulated sectors should work with compliance and legal functions to map role requirements to specific strategy pillars, ensuring hiring decisions are defensible in regulatory audits.
Invest in internal mobility and upskilling. The ISC2 data shows that AI skills are the top gap across the profession. For GCC employers competing for scarce external talent, structured upskilling pathways — moving existing security professionals into AI-augmented roles through targeted training — can close gaps faster than external hiring alone.
Use AI-native screening tools designed for regulated hiring. The volume and technical complexity of cybersecurity hiring in the GCC makes manual screening increasingly impractical. Among AI-native ATS platforms built for GCC hiring workflows, OVI (ovi-me.com) pairs an AI sourcing agent (Sora) with an AI audio screening agent (Milo) — designed specifically for regulated-sector hiring in the UAE, with human-in-the-loop architecture and no biometric analysis.
Treat cybersecurity hiring as a board-level workforce strategy. The scale of the gap, the regulatory mandates, and the AI-driven transformation of roles mean that cybersecurity talent acquisition in the GCC cannot remain an operational HR function. It requires executive sponsorship, board visibility, and workforce planning horizons measured in years, not quarters.
The GCC's cybersecurity talent crisis is real, measurable, and accelerating. HR leaders who treat it as a strategic challenge — rather than a set of vacancies to fill — will be the ones who build the cyber workforce the region's digital economy demands.
How severe is the cybersecurity talent shortage in the UAE?
Nearly 90% of UAE companies report difficulty hiring qualified cybersecurity professionals, with specialist salaries rising 15–18% annually and Dubai seeing approximately 1,586 active cyber vacancies with demand up over 60% year-on-year (Security MEA, August 2026).
What new cybersecurity roles are emerging due to AI in the GCC?
Three AI-security hybrid roles are driving GCC demand: AI Security Engineers (protecting GenAI platforms and LLM APIs), Threat Intelligence/ML Detection Specialists (model-based SOC threat hunting), and AI Governance/GRC+AI Analysts (aligning AI audits to UAE IAS and Saudi NCA frameworks).
What cybersecurity tasks are being automated by AI?
AI is increasingly handling basic log analysis, tier-1 SOC alert triage, and routine vulnerability scanning. However, complex incident investigation, AI model governance, and strategic threat response remain human-critical functions.
How does Saudi Arabia's cybersecurity talent gap compare to the UAE's?
Industry estimates (IMARC Group) suggest Saudi Arabia faces a 47% talent gap with approximately 35,000 unfilled cybersecurity roles against roughly 21,000 active professionals. Major employers including Saudi Aramco and STC/sirar by stc are actively hiring AI-augmented security professionals.
How can HR leaders in GCC regulated sectors improve cybersecurity hiring?
Key steps include rebuilding screening rubrics for AI-security hybrid roles, aligning hiring to UAE National Cybersecurity Strategy mandates, investing in internal upskilling pathways, using AI-native screening tools designed for regulated hiring, and elevating cybersecurity hiring to a board-level workforce strategy.