The defensive population is smaller than the offensive one, better paid in its day job, and dramatically easier to reach — because it congregates in a handful of named, addressable channels rather than a diffuse bounty crowd.
192,900 US information security analysts, median pay $129,180/year ($62.11/hour) as of May 2025, projected +21% growth to 2035 with about 14,100 openings a year (BLS). That occupation code aggregates SOC analysts, detection engineers and most threat-intel roles; BLS does not break them out, so every sub-specialism population figure below is an inference, not a statistic.
The arbitrage
| Role | Figure | Source |
|---|---|---|
| Information security analyst | $129,180 median, $62.11/hr | BLS |
| Threat intelligence analyst | $100,058 avg; $48.10/hr; 25th pct $77,500, 90th $137,000 | ZipRecruiter |
| Malware reverse engineer | Median total pay $181,051, range $141k–236k [WEAK — 7 reports, most recent Feb 2024] | Glassdoor |
| Detection engineer | Listings $143k–182k [WEAK] | ZipRecruiter |
A threat intelligence analyst's effective hourly rate is $48.10. Mercor is currently posting $85–95/hour for "Cyber Security Experts" evaluating how AI models handle threat detection and incident response, for an undisclosed "cutting-edge AI research lab" (Mercor).
That is roughly a 1.8x premium over day-job hourly, before accounting for the fact that it is remote, flexible and additive to a salary rather than a replacement for it. It is the single most important supply-side number on this page.
The posted requirements tell you who is being recruited: 5+ years as "SOC analyst, incident responder, detection engineer, threat hunter, or red team operator," hands-on real incident involvement, SIEM expertise across Splunk, Sentinel, QRadar and Elastic, EDR/XDR across CrowdStrike, Defender and Carbon Black, log and network traffic analysis, and MITRE ATT&CK mapping. Paid weekly through Stripe or Wise, independent contractor. A second, now-closed Mercor listing — "Cybersecurity SWE — AI Safety" at $60–90/hour, 15–25 hrs/week — involved "crafting expert-level prompts across specialized cybersecurity topics" and annotating model responses (Mercor).
For contrast, the aggregated market for offensive AI-training work is cheaper: OpenTrain lists AI red-team roles at $40–62/hour with a QA lead up to $100/hour, and no defensive-specific listings at all (OpenTrain). Defensive expertise appears to command a 1.5–2x premium over offensive in the AI-training labour market [UNVERIFIED — comparison across two sources with different sample sizes]. That inverts the usual assumption and it matters for Sizing the cyber pot: the cheaper half of security to hire is the half everyone assumes is expensive.
There is a floor to respect. Loginsoft sells "Security Data for AI Training" with "expert labeling and ground-truth validation," from a 201–500 person firm headquartered in Chantilly, Virginia with its development centre in Hyderabad, billing $25–49/hour [WEAK — third-party directory] (Loginsoft; Enosis profile). Any pitch that assumes expert security labelling must be expensive has to answer for that number.
Why the demand is real and not closing
Frontier models are far worse at defensive security than offensive, and two hyperscalers have independently said so with numbers.
CrowdStrike and Meta's CyberSOCEval puts frontier-model accuracy at 23–34% on malware analysis and 43–53% on threat intelligence reasoning, against random baselines of 0.63% and 1.7%, and states plainly that "current LLMs are far from saturating our evaluations" (arXiv 2509.20166). Microsoft's ExCyTIn-Bench tops out at 56.2% for GPT-5 at high reasoning (Microsoft); its CTI-REALM tops out at 0.637 for Claude Opus 4.6 and 0.282 on cloud multi-step attack tasks (arXiv 2603.13517). Against that, OpenAI reports offensive CTF performance moving from 27% to 76% in three months (OpenAI).
The sharpest single number is DFIR-Metric: GPT-4.1 scores 92.75% on forensics certification questions and 28% on practical CTF-style challenges (arXiv 2505.19973). The models have read the books and cannot do the job, and the only thing that closes that gap is a practitioner doing the job under recording.
More usefully for pricing: reasoning does not help here. CyberSOCEval found test-time reasoning models "do not achieve the boost they do in areas like coding and math." CTI-REALM independently found medium reasoning effort outperformed both high and low, and dedicated reasoning models underperformed general-purpose ones. Two vendor-scale benchmarks agreeing that inference-time compute does not fix defensive security is the strongest available argument that the bottleneck is training data, not model scale. See Defensive security.
The channels that are actually sized
tl;dr sec — 90,000+ subscribers, an audience described as spanning security engineers to CSOs at Google, Microsoft, AWS, Netflix, Dropbox and Slack (tldrsec.com). It is the largest single distribution channel into security practitioners that exists.
Detection Engineering Weekly — 5,200+ subscribers at roughly ten months, with its author, Zack Allen, estimating a 100,000+ addressable population of "infosec people interested in threat detection" and targeting 10% of it (detectionengineering.net). The 5,200 figure is from a growth retrospective and is dated; the current number is not published. It is nonetheless the most precisely targeted channel to the highest-value sub-specialism in the domain.
Clint Gibler, who created tl;dr sec, joined OpenAI in June 2026 to lead its cyber team (tl;dr sec #332; Benzinga, 11 Jun 2026).
Read it both ways. As a signal: a frontier lab valued the person with the deepest relationship to the defensive practitioner community highly enough to hire him to run cyber — which is a lab telling you where the scarce resource is. As a complication: the largest distribution channel into your supply is now operated by an employee of your largest prospective customer. Whether it remains available for third-party sponsorship is unresolved and should be established directly before any plan depends on it.
Contributor registers are the highest-precision qualification signal in the domain, because every contributor has by construction authored a working detection rule and had it merged through a QA pipeline. SigmaHQ/sigma holds 3,000+ rules at 10.9k stars and 2.7k forks, licensed under Detection Rule License 1.1, which grants rights "to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies" — unusually permissive for a security corpus (SigmaHQ; SPDX). elastic/detection-rules sits at 2.7k stars and 693 forks under the less permissive Elastic License v2 (GitHub). sublime-security/sublime-rules is the equivalent register for email and phishing detection.
Conferences and certification registers. BSides lists 36 upcoming 2026 events across six continents, an archive of 8,893 past talks from 235 chapters, and a stated footprint of "200+ events across 70 countries" (allbsides.com) — per-event attendance is not published, and the value is that BSides speakers are self-selected practitioners who prepared original technical material. SANS DFIR Summit, Objective by the Sea and DEF CON Blue Team Village are the specialist gatherings; none publishes attendance. GIAC has issued 290,000+ certifications across 60+ types (GIAC) — certifications issued is not people certified, and per-certification holder counts are not published, so GCIA, GCIH, GCFA, GREM, GCTI and GCDA cannot be sized individually.
The ISC2 2025 Workforce Study (16,029 respondents) reports 59% citing critical or significant skills needs, up from 44% in 2024, with AI/ML the top gap at 41% (ISC2). A workforce that names AI as its own biggest skills gap is a workforce that will take AI-adjacent paid work partly for the exposure.
Discord and Slack community sizes are entirely unestablished. No figures for the Detection Engineering, MacAdmins or DFIR communities — they publish none, and the counts are obtainable only by joining each server. SigmaHQ and Elastic contributor counts are unestablished — GitHub's contributor API was not reachable in this research, so the two highest-precision recruitment registers in the vertical could not be sized. Both are trivially resolvable with the right access and neither should be estimated in the meantime.
Subreddit sizes (r/cybersecurity 700K+, r/netsec 600K+, r/blueteamsec 40K+) come from a single SEO aggregator and are [WEAK] (RedditBlast). Note the shape they imply: general security subreddits are 10–70x larger than defensive-specialist ones, which is the recruitment problem in miniature.
The realistic reach
Combining what can be established: ~90,000 via tl;dr sec subject to the OpenAI question, 5,000+ via Detection Engineering Weekly, low thousands of demonstrated rule authors across the GitHub registers, and a US employed base of 192,900. The population capable of producing senior-grade defensive artefacts is plausibly in the low tens of thousands globally [UNVERIFIED — synthesis] — small enough to reach through a handful of named channels, large enough to staff a data business.
That is a better-shaped supply problem than the offensive side described in Offensive supply, where the equivalent population is low thousands and already contested. What both sides share is the question of how you pay them, which is Paying the crowd.