Two income channels for offensive-security talent closed in the same month. On the government side, CISA shed roughly 1,000 people in 2025, about 29 percent of its workforce, and its red team operations were dismantled. On the gig side, Huntr stopped accepting new open-source bug bounty submissions on June 30, 2026, closing the on-ramp thousands of independent researchers used to build a portfolio and earn side income. At the same time, demand for exactly this skillset is rising. If you need a security researcher, red teamer, or vulnerability researcher, the talent is on the market right now, and the startups that win it will be the ones with the fastest, most structured hiring process, not the biggest brand or budget.

## Two security-talent income channels just closed in the same month

What makes this moment unusual is that two independent supply channels contracted at once. Neither shock is speculative. Both are documented, and together they pushed experienced offensive-security people out of two income streams within weeks of each other.

### The government side: CISA lost ~1,000 people (and what "2,800" actually means)

CISA entered fiscal 2025 with about **3,400 employees**. During 2025 it lost roughly **1,000 people, about 29 percent of the workforce**, dropping to around 2,200, through a mix of buyouts, early retirements, layoffs, and DOGE-driven cuts. Its red team operations were dismantled in the process. The attrition is corroborated across [Cybersecurity Dive](https://www.cybersecuritydive.com/), [CyberScoop](https://cyberscoop.com/cisa-workforce-cuts-concerns-cybersecurity-panel-rsac-2025/), and Axios, which described the reduction as cutting the agency's total workforce by nearly a third.

You may have seen the number "2,800" attached to these cuts. It is worth getting right, because it is easy to misread. Per congressional testimony on June 3, 2026, **2,800 is a proposed staffing target**, below the authorized capacity of ~3,400. It is not the number of people cut. On top of the reductions already made, the administration's FY2027 budget proposal calls for cutting more than **$700 million** from CISA, per [Daily Security Review](https://dailysecurityreview.com/cyber-security/cisa-faces-700m-more-cuts-as-mullin-signals-restructure/). So the accurate framing is: about 1,000 already gone, roughly 29 percent of the workforce, with $700M-plus in additional cuts proposed. That is a real contraction. It does not need to be inflated to "2,800 laid off," and it should not be.

### The gig side: Huntr shut its OSS bug bounty and pivoted to AI red-teaming

Huntr was one of the most common on-ramps for junior and independent researchers to find real open-source vulnerabilities, get paid, and build a public track record. On June 8, 2026, it announced a transition to "Huntr 2.0," refocused on AI security challenges. The timeline is short and firm:

- **June 30, 2026:** stopped accepting new submissions for the OSS vulnerability program.
- **July 31, 2026:** all OSS submissions locked; reports not yet processed are abandoned.
- **August 30, 2026:** historical vulnerability data remains accessible until this date, with no guaranteed access after October 2026.

Huntr now positions itself as a challenge-based competition platform for testing the boundaries of AI systems, per the [Huntr 2.0 FAQ](https://blog.huntr.com/huntr-2-0-faq) and [huntr.com](https://huntr.com/). The traditional OSS bounty on-ramp is closing.

The human face of this is easy to find. As documented by [LoSec Research](https://losec.io/blog/the-final-days-of-huntr-oss), one researcher picked NLTK as a target on June 22, found three vulnerabilities the next day, submitted just before the cutoff, and had all three validated by July 4 for **$1,625 total**. Multiply that by the many researchers who used Huntr as a side channel, and you have a population of skilled people who just lost a source of income and portfolio-building work.

## Meanwhile, demand for the same skillset is rising

The supply-side story only matters because the demand side is moving the opposite direction. Offensive-security roles are a named 2026 hiring trend, and there are live requisitions open right now for exactly this profile.

### Live reqs, and why they move slowly

Two named examples show where the demand is concentrated:

- **ManTech** is hiring **CNO (Computer Network Operations) Vulnerability Researchers** in Herndon, VA and Fort Meade, MD, plus CNO developers working in C/C++, Python, assembly, and reverse engineering.
- **Apple** has an open **Vulnerability Researcher role in SEAR** (Security Engineering and Architecture), posted on jobs.apple.com.

These are strong employers with strong brands. They are also slow. Defense primes and big tech run long, multi-stage, often clearance-gated pipelines measured in weeks to months. That is the gap a startup exploits. You cannot out-brand ManTech or out-clearance a federal contractor, but you can respond in 48 hours while their req is still in step two.

### The broader market context

Beyond the named reqs, the market backdrop is consistent. There are roughly **470,000-plus** security job postings with about **12 percent** annual growth, against a persistent global talent gap often cited near **4.8 million** people. Offensive and pentest roles command the strongest pay in the field, frequently **$200,000-plus**, well above the general "security researcher" average of around $90,800. Treat these as directional market context rather than precise figures, but the direction is unambiguous: demand up, one part of supply constrained.

There is a defensive-side squeeze too. Microsoft ships **130-plus CVEs in a typical Patch Tuesday**, month after month, which keeps SOC and patch-triage headcount at MSPs stretched thin. That steady volume adds quietly and continuously to the pressure on security hiring.

## Why speed is your edge in a supply shock

Here is the counterintuitive part. In a talent supply shock, the binding constraint on *catching* newly available people is not budget and not brand. It is **process latency**, the time between a candidate raising their hand and you making a decision.

Think about who you are competing with. The defense primes and enterprises absorbing this talent run pipelines that take weeks. A researcher who is between income channels *this quarter* does not want to wait six weeks to hear back. The organization that sends a structured, respectful first response in 48 hours and reaches a decision in under two weeks wins that person, even against a bigger name paying more. Speed is the one dimension where a 20-person startup can beat a 20,000-person contractor outright.

The trap is that "fast" usually means "sloppy," and sloppy loses good candidates a different way, through inconsistent evaluation, gut-feel decisions, and dropped follow-ups. The goal is fast *and* structured. That combination is rare, which is exactly why it wins.

<div class="blog-inline-cta">
  <p><strong>Ready to move at window speed?</strong> Kit lets you define a security-hiring pipeline once, score candidates on a consistent scorecard, and decide in days, so a small team can catch fast-moving talent without going sloppy.</p>
  <p><a href="/users/sign_up">Start your free trial</a></p>
</div>

## How to hire offensive-security talent fast (without getting sloppy)

To hire offensive-security talent fast, do four things: codify the role as a reusable pipeline, evaluate with a structured scorecard so a small team can move quickly, respond within 48 hours and decide within two weeks, and tap your existing talent pool the moment the window opens. Each step removes a specific source of latency.

### Step 1: Codify the role as a reusable pipeline

Do not reinvent your hiring process for each candidate. Define the stages once, for example recruiter screen, then a practical or CTF-style exercise, then a structured technical interview, then a decision, and reuse that pipeline every time. This is the antidote to the improvised, weeks-long process that loses fast-moving people.

This is exactly what Kit's process templates do. You codify a role's stages as a versioned, reusable pipeline and publish a job posting against it in minutes. When the window opens, the process is already built. (For what to actually screen for in these interviews, pair this with our guide on [reading CTF performance as a hiring signal](/blog/hiring-security-engineers-ctf-performance-signal).)

### Step 2: Score candidates with a structured scorecard

A structured scorecard is how a two- or three-person team evaluates a red teamer or vulnerability researcher consistently, without a six-week gauntlet and without gut-feel bias. Everyone scores the same competencies on the same scale, so decisions are comparable and defensible.

Kit's review flow drives this: consistent stage-by-stage evaluation, pending-decision queues, and comparable reviews across interviewers. If you want the deeper method behind why this works, see [structured interview scorecards and predictive validity](/blog/structured-interview-scorecards-predictive-validity) and our take on [skills-based hiring with structured scorecards](/blog/skills-based-hiring-structured-scorecards).

### Step 3: Respond in 48 hours, decide in two weeks

Momentum is a feature the candidate can feel. A researcher deciding between offers notices which company keeps things moving. Aim for a first response within 48 hours and a final decision within two weeks. Prompt communication, fast advancement between stages, and clear next steps are what separate you from the contractor whose req is still in review.

Keeping candidates moving is a workflow problem, and it is one Kit is built to solve: application summaries, one-click advancement, and built-in messaging so nobody stalls in a queue while a competitor closes.

### Step 4: Tap your talent pool the moment the window opens

The fastest sourcing is the sourcing you already did. Prior applicants, sourced candidates, and people you passed on for timing reasons are a warm pool you can re-engage instantly instead of starting from zero. When the market moves, search that pool first. Kit's talent pool tools let you re-engage past candidates the day the window opens, not three weeks into a new search.

## Hiring displaced talent, honestly

This is a moment to be precise and human, not opportunistic. These are people losing income channels, not a fire sale. Handle a few things directly and a structured process will surface them early rather than late.

- **Clearances do not transfer to commercial work, and you do not need them.** Ex-government researchers bring deep, adversary-grounded skill. Commercial product security does not require their clearance, so do not treat its absence as a gap.
- **Some contractor roles carry restrictive covenants.** Non-competes and similar terms vary. Scope the role clearly and ask about constraints up front; a structured screen makes this a normal early question, not a late surprise.
- **Mission-fit is real.** Someone moving from mission-driven public-sector work to startup product velocity is making an adjustment. Name it in the interview. The pitch is meaningful, fast-moving work, not "cheap talent."

The through-line: a structured process gives you a clean, early place to raise each of these, which is better for you and more respectful to the candidate.

## Doing this in Kit

When the market hands you a talent window, the fastest structured process wins it. That is the whole thesis, and it is what Kit's Hiring vertical is built for. Define your offensive-security pipeline once as a reusable template, score every candidate on a consistent scorecard so a small team can evaluate without bias or delay, keep people moving with prompt communication and one-click advancement, and re-engage your talent pool the moment the window opens.

Kit will not place candidates, verify clearances, or make the hiring decision for you. What it removes is process latency, the single thing standing between you and the senior researcher who is between income channels this quarter. The CISA contraction and the Huntr shutdown created the supply. Rising offensive-security demand is the competition. Your speed is the edge.

Define the pipeline once, score candidates consistently, and decide in days. [Start your free trial](/users/sign_up) and be the fastest respectful process in a great researcher's inbox this quarter.