You Don’t Need 100% of the Job Requirements to Apply

I’ve reviewed thousands of resumes throughout my career. I’ve sat on both sides of the hiring table. And one pattern shows up repeatedly: qualified candidates eliminate themselves from consideration before anyone else gets the chance to evaluate them.
They read a job description, count the requirements they don’t meet, and close the browser tab.
The position requires five years of experience and they have three. The posting lists Splunk and they’ve only used QRadar. Python is mentioned and they know PowerShell. They assume they’re wasting everyone’s time by applying.
But here’s what most candidates misunderstand: job descriptions aren’t checklists. They’re wish lists. And employers know the difference between what they post and what they actually need to move forward with a hire.
Prefer to read the full breakdown? Keep scrolling. Prefer to watch? Full video above.
Why Job Descriptions Aren’t Checklists
Job descriptions rarely emerge from a single person sitting down and carefully defining the minimum qualifications for a role. Instead, they result from committee decisions, HR templates, and the accumulated preferences of multiple stakeholders.
A hiring manager mentions they’d love someone who knows Terraform. HR adds it to the posting as a requirement. The outgoing employee used ServiceNow, so that gets listed. A senior leader once mentioned Python would be useful for automation. Add it to the list.
What started as a conversation about core needs becomes a document listing everything the team currently uses, everything they wish they had, and everything that might possibly be useful. Nothing gets removed because removing items feels like lowering standards.
The result is a job description that describes a perfect candidate who probably doesn’t exist—and certainly isn’t required for someone to succeed in the role.
Many hiring managers will tell you privately that they’d be thrilled to find someone who meets 70% of what’s listed. They wrote the posting hoping to attract strong candidates, not to define an absolute threshold below which nobody should bother applying.
What Employers Actually Need Versus What They Post
There’s a persistent gap between what organizations post and who they actually hire. And that gap creates opportunity for candidates who understand how to evaluate their own qualifications honestly.
The cybersecurity unemployment rate has hovered near zero for years. Many security positions remain unfilled for months. Employers eventually face a choice: continue waiting for the perfect candidate or hire someone strong who can grow into the role.
Most choose the latter.
This isn’t settling. It’s recognizing that someone with solid fundamentals and the ability to learn quickly often delivers more value than someone who checked every box but lacks depth or adaptability.
When a hiring manager interviews candidates who lack specific tools or certifications but demonstrate strong analytical thinking and genuine interest in the work, they’re usually willing to provide training on the missing pieces. The hard part is finding candidates with the right foundation and mindset. The specific tools can be learned.
Finding the Core Job Function
Learning to read job descriptions strategically starts with identifying what the position actually requires you to do every day.
Look past the bullet points listing technologies and certifications. Find the sentences that describe activities and responsibilities. Those reveal the core function.
A security analyst position might list fifteen technologies, but the actual work involves investigating alerts, analyzing logs, identifying threats, documenting findings, and communicating with stakeholders. That’s the job. Whether you do it in Splunk or Sentinel, using CrowdStrike or Carbon Black, matters less than whether you can perform those fundamental activities.
When you identify the core function, ask yourself: Can I do this work with reasonable onboarding?
If the job requires analyzing network traffic to identify threats and you understand TCP/IP, common protocols, and what normal versus suspicious traffic looks like, you can probably learn whatever analysis tool they use. You have the foundation.
If the job requires those same activities but you’ve never worked with networks and don’t understand how traffic flows, that’s a different situation. The tool isn’t your problem. The missing foundation is.
Focus your evaluation on whether you can perform the core activities, not whether you’ve used the exact technologies mentioned.
Trainable Gaps Versus Knowledge Gaps
Not all gaps carry equal weight. Understanding the difference between trainable gaps and knowledge gaps helps you assess whether you’re reasonably qualified.
Trainable gaps involve specific implementations, tools, or processes. You understand the concept but lack experience with that particular version. You know vulnerability management but haven’t used Tenable. You understand infrastructure as code but haven’t written Terraform. You’ve done incident response but not using that organization’s specific playbooks.
These gaps close quickly because you’re not learning something new. You’re applying existing knowledge in a slightly different context.
Knowledge gaps are different. They involve missing the conceptual foundation the job requires. If a position requires investigating endpoint security alerts and you don’t understand how operating systems work, how processes execute, or what normal system behavior looks like, you’re missing foundational knowledge.
You can’t fix that with a few weeks of tool training.
Be honest about which type of gap you’re facing. If you’re looking at trainable gaps, you’re probably more qualified than you think. If you’re facing knowledge gaps in core competencies, you should think carefully about whether this position matches your current capability level.
Reading Between the Lines: Decoding Job Description Language
Job descriptions contain signals about what’s truly required versus what would simply be nice to have. Learning to spot these signals helps you evaluate whether your gaps matter.
Pay attention to qualifying language. “Preferred” means optional. “Desired” means they’d like it but don’t expect it. “Nice to have” explicitly tells you it’s not required. “Or equivalent experience” signals flexibility.
When requirements include this language, the employer is telling you directly that they’ll consider candidates without those qualifications.
Notice the placement and emphasis of requirements too. Items listed first usually matter more. Requirements mentioned in both the summary and the detailed qualifications probably carry more weight than items appearing once at the bottom of a long list.
Look at how experience requirements are framed. “Five years of experience in security operations or equivalent combination of education and experience” is very different from “Must have five years of experience.” One shows flexibility. The other does not.
The absence of flexible language doesn’t necessarily mean a requirement is absolute, but its presence definitely signals room for interpretation.
When You’re Qualified Enough to Apply
So how do you decide whether to apply when you don’t meet everything listed?
Start with the core competencies. If you can perform the fundamental activities the job requires, you’re probably in reasonable territory. Meeting 60-70% of listed requirements means nothing if you’re missing the three things central to the job function.
Weight your assessment toward what matters most. If a security engineering role emphasizes automation and you have strong scripting skills but lack experience with two of the five listed security tools, you’re likely a viable candidate. If the same role emphasizes those security tools and you have weak scripting skills, the calculation changes.
Consider your ability to close gaps quickly. If you can credibly commit to learning what you’re missing and explain how you’d do it, that strengthens your position. Employers appreciate candidates who recognize their gaps and have plans to address them.
Think about the role level. Entry-level positions expect training needs. Senior roles expect you to contribute immediately. The same gap carries different weight depending on the position level.
If you meet the core requirements, understand the fundamental concepts, and can close your trainable gaps within a reasonable onboarding period, you’re qualified enough to apply. You’re not wasting anyone’s time. You’re giving them the opportunity to evaluate whether your particular combination of skills meets their needs.
How to Address Your Gaps in Your Application
When you decide to apply despite missing some requirements, address it strategically.
Don’t ignore obvious gaps and hope nobody notices. That approach fails when your resume gets screened. Instead, acknowledge transferable skills and demonstrate learning ability.
If the job requires Python and you know PowerShell, mention your scripting experience and note that you’re currently learning Python. If you can point to a project or coursework, even better. You’re showing that you recognize the requirement and are already working to meet it.
When you lack experience with a specific tool but understand the category, emphasize the conceptual knowledge. “While I haven’t used Splunk specifically, I have extensive experience with log analysis and SIEM platforms including QRadar, and I understand the fundamental processes of query development, alert creation, and investigation workflows.”
You’re demonstrating that the gap is tool-specific, not conceptual. That’s what matters to most hiring managers.
Focus your application on what you bring rather than apologizing for what you lack. Lead with your strengths. Address gaps honestly but briefly. Show you understand the role and can perform the work.
When You Actually Aren’t Qualified
Understanding when you’re qualified enough to apply requires also understanding when you’re not.
If you’re missing the core competencies—the fundamental knowledge required to perform the job’s primary activities—you’re probably not ready. A security architect role requiring extensive experience designing enterprise security programs isn’t appropriate if you’ve been working help desk for two years. The gap is too large.
If you’re facing multiple knowledge gaps rather than trainable gaps, reconsider. Missing the specific tool is fine. Missing the conceptual foundation for several core requirements suggests the role is beyond your current level.
If the position emphasizes seniority, independent work, or leadership and you lack that experience, recognize that some requirements actually do matter. Years of experience isn’t always meaningful, but when a job clearly expects someone who can operate autonomously in complex situations, your three years of guided work in a structured environment probably doesn’t match what they need.
There’s no shame in recognizing when a position doesn’t match your current capabilities. That’s judgment, not defeat. Apply for roles where you can succeed, not just roles that sound interesting.
Making Better Application Decisions
Job descriptions describe ideal candidates, not minimum qualifications. When you understand that distinction, you can make better decisions about where to apply.
Identify the core job function. Assess your trainable gaps versus knowledge gaps. Look for signals about flexibility. Focus on whether you can perform the fundamental work with reasonable onboarding.
If you meet 60-70% of requirements and those include the core competencies, you’re probably qualified enough to apply. Let the employer decide whether your particular mix of skills meets their needs. Don’t make that decision for them.
The candidates who get hired aren’t always the ones who meet every listed requirement. They’re often the ones who demonstrate strong fundamentals, learning ability, and the judgment to recognize when they’re a reasonable match for a role.
You might be eliminating yourself from positions where you could succeed. Stop treating job descriptions as checklists. Start evaluating whether you can actually do the work.
One practical step: Find a job description you’ve been hesitant to apply for. Identify the three to five core activities it requires. Honestly assess whether you can perform those functions with reasonable training. If yes, write the application.
Tagged:
Enjoyed this article?
Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.
A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.
No spam. Unsubscribe anytime.
Prefer to Listen?
Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.
Listen on Spotify
