[Disclaimer: also not a certified security professional, but I do follow the topic and practice it hands-on from time-to-time...]
However I think there are multiple (sometimes non-overlapping) types of cyber-security professionals / roles:
* the policy maker / enforcer -- which is what some companies want, and what the most well known people out there (including Schneier, Krebs, etc.) are blogging and speaking about; (to put it metaphorically they are the ones in charge of designing an IT "hygiene", and making sure everyone "washes their hands" properly;) :)
* the operations security -- which should make sure systems and networks are well locked down, patches properly installed, watches out for suspicious activity, and if he is capable enough tries to check the boundaries and limits the firms security; this is another role most companies want, what some courses train for, and what usual bloggers write about;
* "applied cryptography / security" developer (for the lack of a better name) -- which (if he knows better) should make sure proper well-known techniques and best practices are used throughout the developed applications, and when necessary (if not already covered by existing solutions) is capable enough to mix cryptographic primitives;
* "high budget zero-day" researcher (also for the lack of a better name) -- which is mostly employed by state level actors to discover zero-day vulnerabilities, and on the other side employed by large corporations (e.g. Google, Microsoft, etc.) to make sure their most valuable systems aren't vulnerable to those types of attacks; these are the guys that come up with Spectre and Meltdown and other very low-level hardware related vulnerabilities;
* (many others that escape me at this moment...)
Each of these roles require some different traits and focus areas, which most of the time aren't strictly related to IT or security; for example:
* the policy maker should be well versed in social sciences and human behavior, as in the end he has to work with people;
* the operations security person should be as capable (if not more) than any of its "normal" peers in all matters of network and systems administration;
* all of them must understand that in the end security is a spectrum (i.e. from air-gapped-system to no-authentication-internet-connected) and it has to take into account a balance between internal cost (development, operations, etc), end-user costs (e.g. how cumbersome is for the end-user to login), risks (e.g. is the data valuable enough to protect it with 2FA), time-to-market, etc.
So in the end I think the underlying problem is that most companies want "one cybersecurity guy", and most candidates see themselves as that "one guy", when in reality there is no real person that can actually fulfill all these roles. Just like nobody wants to hire "a developer", but a "web developer", or an "embedded developer", so should companies specify what kind of security professional they are looking for...