Wimbush & Associates now is Discovered Search - Powered by Discovered.ai

Cybersecurity Recruiter Fee Math: Contingency vs Fractional

How much a cybersecurity recruiter is worth depends on how often you hire. If you run a managed service provider (MSP), do the fee math before you sign anything. At 20% contingency, a $120,000 security engineer costs $24,000 per hire. Fractional recruiting, where a recruiter works your roles part-time for a flat monthly fee, runs $1,500 a month on a six-month commitment. That’s $9,000, and it covers that seat plus every other role you’re filling in the same window. This guide walks through what a recruiter does beyond a job post and how to choose between the models.

Cybersecurity Recruiter: The Fee Math

Cybersecurity hiring timelines routinely run longer than other tech roles, which makes the cost of a slow search easy to underestimate. CyberSeek reports cybersecurity jobs take 21% longer to fill than other tech jobs in its CyberSeek 2025 infographic.

A cybersecurity recruiter only makes financial sense when the pricing model matches how often you hire. If you mostly hire one security-leaning role now and then, a percentage fee can be tolerable. At two or more technical roles a year, it becomes the most expensive way to buy recruiting help.

A $120,000 security engineer at 20% contingency is a $24,000 fee for one hire. If that same firm charges 30%, you’re even higher. “Free until you hire” isn’t free; it hides the line item until the day you’re out of time.

Now compare a flat monthly model to a percentage fee model. With fractional, $1,500/month on a six-month commitment totals $9,000 and covers every open seat in that window. If you need month-to-month, $2,500/month is still $15,000 over six months. Typical fill for a quality hire is 4 to 12 weeks either way, so the real difference is predictable spend and who does the sourcing and first screens.

At two technical hires a year, a single $24,000 contingency fee already costs more than six months of fractional.

A flat fee recruiting model takes the per-hire sticker shock out when you’re filling multiple technical seats in the same window.

What You Still Need Done

A job post doesn’t recruit. It catalogs your need and waits for applicants who already feel like moving. In security, that usually gets you a pile of cert-forward resumes and very few people who’ve lived in ticket queues and on-call rotations. If you’re hiring for an MSP, you also need someone who can handle context-switching across clients without creating audit findings and missed escalations.

The real work is outbound. Employed candidates have to be found, contacted, and screened the same week, before they lose interest. An MSP security engineer might list four certs and still be unable to explain how they’d scope a client firewall change without breaking a site-to-site VPN. Catching that on a first call is where an MSP recruiter earns their keep and HR generalists struggle. As Fletcher Wimbush puts it, “HR people are not recruiters. Making a compliance-focused HR person do recruiting is like making an accountant do sales.”

Someone also has to keep scheduling and feedback moving, coordinating interviews around client meetings and stopping hiring managers from dragging feedback out for days. This usually extends beyond security engineers to cloud and network engineers with security duties. You’ll also see L2 and L3 help desk people moving into security and vCISO-adjacent ops leaders. A 4 to 12 week fill needs a clear owner for sourcing, screening, and scheduling. It also needs one person who approves the offer.

Which Roles Justify Help

A service manager hires a “security engineer” off a clean resume, then discovers in week two they’ve never owned a change window in a live client environment. Now every firewall tweak turns into a senior engineer escalation.

Not every help desk and NOC seat justifies a recruiter. The case is strongest when the role is scarce and the job is easy to misread from a resume. It gets stronger when a bad hire creates CMMC or SOC 2 client risk or drags senior engineers into endless firewall and VPN rework. Handle every security-adjacent role the same way and you’ll either overpay for search or underinvest on the hires that swing your delivery.

Start by separating promotable roles from must-arrive-ready roles. Moving an L2 or L3 help desk tech into a junior security track can work when you’ve got a real mentor, stable coverage, and time for ramp. But hiring your first dedicated security engineer or the person who’ll be the escalation point when a client asks, “Are we exposed?” isn’t the same bet. When you’re buying certainty, you’re paying for sourcing and evaluation discipline.

External recruiting support usually makes sense for roles like these:

  • Security engineer (or first security-focused hire): You can’t afford evaluation shortcuts here. A miss leads to weak scoping, slow incident response, and higher client churn risk.

  • Cloud or network engineer with security ownership: Hybrid roles attract fuzzy candidates. You need someone who does the core engineering work and thinks in risk and controls.

  • vCISO-adjacent ops leader: You’re hiring judgment and client-facing credibility. Those candidates are often employed and won’t apply.

Before you buy help, ask one question. Can your service manager and senior engineers assess integrity first, then attitude, then cognitive ability, then personality, without defaulting to certifications as the proxy? If the answer is no, you’re already paying for recruiting, just in owner time and slow cycles.

Client-facing leadership and judgment separate a vCISO-adjacent hire who can lead QBR conversations from one who can only talk tools. There are proven ways to screen for those soft skills and leadership traits in candidates.

Choosing a Cybersecurity Recruiter Model

The right model gives you a predictable monthly recruiting line item, and your team gets its evenings back. The catch is choosing a model that matches your hiring frequency rather than your optimism.

Choose the model that matches how often you hire and how much owner time you can spare. The wrong match costs more and recreates the failure you’re escaping. Follow-up slows, screens get shallow, and a hiring manager ends up doing recruiter work between client escalations.

Contingency works when you hire once every few years and you’ll tolerate a percentage fee to avoid a monthly commitment. But paying only on placement doesn’t make it low-risk. The fee pays the recruiter to close, not to source patiently and calibrate with you.

Use this table as your first-pass decision filter:

Model How You Pay What It Covers When It Makes Sense
Contingency 20% to 30% of first-year salary per hire Candidate submission and coordination through placement You hire infrequently and want pay-per-hire, even if it’s the highest unit cost
Retained search Upfront or milestone fees Dedicated search effort and deeper role calibration You need a hard-to-find, high-stakes hire and want the firm fully committed
Fractional recruiting $1,500/month on a six-month commitment, or $2,500 month-to-month Recruiting capacity across every open seat, with predictable spend You hire two or more technical roles a year and want hiring help without per-hire sticker shock

Fractional works best when you need repeatable outbound sourcing and screening across several roles at once. The full fractional recruiting vs contingency breakdown covers when each one wins.

What to Ask Before You Commit

You do one great interview on Monday, then nobody follows up until Friday because client work took over. By the time you reply, the candidate is gone and you’re back to square one.

Most bad recruiter relationships don’t fail on effort or intent. They fail because nobody agreed on a 48-hour follow-up standard and a single owner for the process. Without plain-language answers to these questions, you’re buying another inbox.

Start by getting specific about who does the unglamorous work. Candidates who don’t hear back within 48 hours won’t wait around while you’re in QBRs and on-call rotations.

Ask these before you sign anything:

  • Who owns outbound sourcing, not just inbound applicants? Ask how many employed candidates they’ll contact weekly for your role.

  • What’s the response-time standard? Agree on a simple SLA for candidate follow-up and interview scheduling.

  • How will you screen for ticket-queue triage and firewall changes vs cert collecting? Have them walk through a first-call screen for a security engineer supporting multiple client environments.

  • What will you see every week? Require a short pipeline update: outreach sent, replies, screens completed, interviews set.

  • Who drives calibration? Confirm they’ll test your must-haves so you don’t interview five almost-fits and call it a market problem.

Frequently asked questions

How Long Does It Typically Take to Fill a Security Role?

A typical fill for a quality hire is 4 to 12 weeks, and cybersecurity often runs longer than other tech roles. You’ll move faster when someone owns outbound sourcing and you return interview feedback quickly.

When Does Contingency Recruiting Make Sense?

Contingency makes sense when you hire once every few years and you can tolerate a 20% to 30% fee to avoid a monthly commitment. If you hire two or more technical roles a year, that per-hire math usually becomes your most expensive option.

How Do You Avoid Hiring Someone Who’s Just Collecting Certifications?

Don’t treat certifications as your shortcut. Ask for concrete, recent examples of messy real-world work, like scoping a change without breaking production. Then verify those examples in references.

How Much of My Team’s Time Will Recruiting Still Take?

Even with help, you still need a hiring manager who can do tight calibration, run a focused technical interview, and give same-day feedback. If you can’t commit to that, you’ll blame the recruiter for a process you didn’t run.

What If We Want to Promote from L2 or L3 Instead of Hiring?

That can work when you have a real mentor, stable coverage, and time for ramp. If the role is your first security-focused seat or a client-facing escalation point, you’re usually better off buying certainty and promoting later.

If fractional looks right on paper and you want to test it against your own hiring plan, schedule a 30-minute call with Discovered and we’ll run the numbers with you.

Content

Picture of Fletcher Wimbush
Fletcher Wimbush

CEO, Talent Assessment Innovator & Hiring Strategist