Threat modelling judgement grows as agents scan systems

As automated agents take over the routine scanning of UK systems, the human skill that grows in value is threat modelling judgement: deciding which risks matter, in what order, and why.
Author

Wajahat Abbasi

Job Title

Lead Developer

What does the state of defence and security hiring look like now?

The UK cyber workforce is substantial and still growing. There are approximately 143,000 individuals in the UK cyber security workforce, with growth moderately accelerating from 2% in 2022 to 5% in 2024 Cyber security skills in the UK labour market 2025 - GOV.UK. That tells us demand is real and rising, not flattening out.

Demand has not cooled the hiring challenge either. While the proportion of employers struggling to fill vacancies has declined overall, 70% of cyber firms reported at least one hard-to-fill vacancy AI Labour Market Survey 2025 (Gardiner & Theobald), GOV.UK / publishing.service.gov.uk. In defence and security, the gap is rarely about headcount alone. It is about judgement: who can read a system, picture how an attacker thinks, and decide what to protect first.

How are the roles and dynamics changing?

Automated agents now scan systems continuously. They surface misconfigurations, flag anomalies and run through checklists far faster than a person can. What they do not do well is weigh context. A flagged port on a test box and the same flag on a system handling sensitive data are not the same risk, and someone has to make that call.

So the centre of gravity shifts. Routine detection becomes a machine task, and the human role moves towards threat modelling: mapping assets, ranking attack paths and setting priorities an agent cannot infer on its own. With 70% of cyber firms reporting at least one hard-to-fill vacancy AI Labour Market Survey 2025 (Gardiner & Theobald), GOV.UK / publishing.service.gov.uk, the people who can do this thinking are the ones every team competes for.

How do you hire well in defence and security?

Start by hiring for judgement, not tool lists. Someone who can walk you through how they would model threats against one of your systems tells you more than a page of certifications. Ask them to prioritise a messy list of findings and explain the order. That reveals how they think under real conditions.

  • Test reasoning: give a realistic scenario and ask what they would protect first and why.
  • Value breadth of thinking over a long tool checklist, since agents already cover much of the routine scanning.
  • Look for people who can explain risk to non-technical stakeholders, because priorities need buy-in.
  • Move quickly and keep the process clear, as strong people in a workforce of around 143,000 Cyber security skills in the UK labour market 2025 - GOV.UK rarely stay on the market long.

Clear, fast and respectful processes win here. The best threat modellers are busy and in demand, so a slow or vague hiring journey loses them before you have made your case.

Where does our recruitment agent fit in?

We built Reed.ai to help defence and security employers find people with this kind of judgement, fast. Our recruitment agent manages recruitment end to end for 8% on a successful hire, with no monthly fee and no upfront cost. That fee reflects the value of finding the right person and running the whole process for you. Tell us the role, and we will get started today.

Sources

Wajahat Abbasi
Share