> CyberSecurity, the domain that doesn't recruit yet has a shortage.
Yes, they are 100% lying about this. Any time you see an article about skills shortage, it's complete bullshit. It is cheap for them to create the illusion of a skills shortage via articles and blog spam. What they really want is people to spend their own money on training vs. them training their own talent. Then, once you've spent your money on training, you'll still run similar gauntlets in interviews that developers like to complain about.
This is why some of the certs are kind of useless at getting a job despite industry advice to get them. Some places will see something like OSCP and then still give you a time-limited CTF to do before they'll even talk to you about an entry-level position. Other larger companies will praise you for your certs, saying certs + programming skills is what they look for with new people, then just ghost you.
The interviewing process in pentesting is just as bad, if not worse, than development.
Plus, despite most pentesting gigs being more difficult day-to-day than regular web development jobs, they pay much, MUCH less, sometimes as much as $40k less (80k vs. 120k in a large metro area).
All of this is kind of countered by the fact that you can really do bug bounties on your own now, so you may not really need a traditional job. IMHO, you're better off being a developer first before going down that route.