{"id":9538,"date":"2026-09-21T08:25:00","date_gmt":"2026-09-21T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9538"},"modified":"2026-09-21T08:25:00","modified_gmt":"2026-09-21T08:25:00","slug":"5-ways-ai-is-reshaping-the-cybersecurity-job-market","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9538","title":{"rendered":"5 ways AI is reshaping the cybersecurity job market"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Mario Platt spent part of last year eliminating a team. As CISO for online password management service LastPass, he shut down the company\u2019s dedicated vulnerability management function in late 2025, folding its responsibilities directly into IT and product security. AI and business intelligence tools now handle the triage and analysis that once required a standing group of specialists.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s a concrete example of a trend that\u2019s largely lived in the abstract: security work reorganizing itself around what AI can now do faster than people can. The pressure to rethink cybersecurity roles for this new era is profound: 87% of organizations cite AI-related vulnerabilities as their fastest-growing risk category, according to the <a href=\"https:\/\/www.weforum.org\/publications\/global-cybersecurity-outlook-2026\/in-full\/executive-summary-6efae97d74\/\">World Economic Forum\u2019s 2026 Global Cybersecurity Outlook<\/a>. Companies are already responding. The <a href=\"https:\/\/www.sans.org\/mlp\/2026-evolving-cybersecurity-workforce-ai-compliance-talent\">2026 SANS\/GIAC Cybersecurity Workforce Research Report<\/a> found that 74% of organizations say AI is already affecting the size of their security teams and the shape of the roles within them.<\/p>\n<p class=\"wp-block-paragraph\">Ask security leaders and staffing experts whether AI is creating new jobs, killing old ones, or just changing what the people already there do, and they\u2019ll tell you it\u2019s a bit of each. Here are five ways that\u2019s playing out across companies.<\/p>\n<h2 class=\"wp-block-heading\">1. Security leadership is consolidating, not multiplying<\/h2>\n<p class=\"wp-block-paragraph\">Some cyber roles were eliminated alongside consolidation at LastPass. Platt is also partway through a similar shakeup in his governance, risk, and compliance (GRC) function, automating the routine compliance work so the group can take on a higher-level risk advisory role, with staff evolving into full <a href=\"https:\/\/www.csoonline.com\/article\/574279\/the-biso-bringing-security-to-business-and-business-to-security.html\">business information security officers<\/a> aligned to specific business units.<\/p>\n<p class=\"wp-block-paragraph\">Elsewhere, entire functions are consolidating under one executive rather than splitting up among new ones. Burke Autrey, president of technology consulting and executive services firm Fortium Partners, says his firm\u2019s standard advice to clients wrestling with AI governance comes down to one simple rule: Don\u2019t invent another C-level title. One client recently consolidated infrastructure, information security, and AI\/ML under an existing senior technology leader and promoted that person rather than recruiting a separate CISO and AI leader.<\/p>\n<p class=\"wp-block-paragraph\">Martha Heller, founder and CEO of executive search firm Heller, sees the same pattern in her practice. Clients increasingly want a single leader to run both infrastructure and cyber \u2014 particularly candidates who cut their teeth on a cloud migration. \u201cAnybody who\u2019s led a really successful cloud migration will know a thing or two about cyber,\u201d she says.<\/p>\n<p class=\"wp-block-paragraph\">Most companies are still in an earlier, messier phase: piling AI governance duties onto existing security and privacy leaders without adding staff to match, says John Alford, CSO at Quant, where he leads security, compliance, and AI governance for the company\u2019s agentic AI platform.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCompanies will eventually formalize these responsibilities,\u201d Alford says. \u201cThe current model puts too much risk into too few roles.\u201d<\/p>\n<h2 class=\"wp-block-heading\">2. The security analyst\u2019s job is changing from finding answers to evaluating them<\/h2>\n<p class=\"wp-block-paragraph\">At Nexus Black, the AI accelerator unit within enterprise software company IFS, head of cybersecurity Robin Fewster built an automation that scans security sources daily, checks affected packages against the company\u2019s source code, and flags exposure. That kind of capability, he says, is becoming the baseline expectation rather than a specialty. And the line between security analyst and security engineer, Fewster says, is blurring.<\/p>\n<p class=\"wp-block-paragraph\">Detection tools already handle the who, what, when, and where of an incident quite well, says Randy Gross, CISO at CompTIA; the SOC analyst\u2019s real value now is in answering the why. \u201c\u2018Why\u2019 unlocks business impact, appropriate response, and long-term mitigations,\u201d Gross says, \u201cand, as a bonus, it\u2019s also moving some senior InfoSec functions left.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That doesn\u2019t necessarily equate to fewer jobs, though. Automating a process or enriching telemetry won\u2019t eliminate the person who did it, says Gross; it clears space to deal with GRC debt, incident response planning, and the rest of the backlog every security team has.<\/p>\n<p class=\"wp-block-paragraph\">Today\u2019s analysts spend less time working the queue and more time designing, tuning, and validating the systems that work the queue, says Autrey of Fortium Partners.<\/p>\n<p class=\"wp-block-paragraph\">That evolution is producing new titles that didn\u2019t exist 18 months ago, says Heller, including one companies are now asking for by name: agent security engineer.<\/p>\n<h2 class=\"wp-block-heading\">3. Judgment, not technical knowledge, is the scarcest skill<\/h2>\n<p class=\"wp-block-paragraph\">Judgment is \u201cthe hardest trait to hire for,\u201d says Quant\u2019s Alford. AI can produce a technically polished answer that ignores business impact or architecture, he says, and reduced cyber staffing leaves fewer experienced people around to catch it.<\/p>\n<p class=\"wp-block-paragraph\">Gross of CompTIA frames what\u2019s happening in cyber hiring as a value shift: judgment, he says, is now in high demand.<\/p>\n<p class=\"wp-block-paragraph\">But it may also be in short supply, according to Autrey. Verifying an automated conclusion \u201ctakes more seniority than producing the finding ever did,\u201d he says, \u201cand that is the seat almost nobody has staffed.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That shortage is most acute for identity engineers and identity and access management (IAM) architects who understand machine and agent identity, a specialty nearly every client asks for and almost none can find, Autrey says.<\/p>\n<p class=\"wp-block-paragraph\">The mechanical work of parsing logs, correlating alerts, and first-pass triage has mostly moved to the model, says Rob T. Lee, chief AI officer and chief of research at SANS Institute. \u201cWhat is left is judgment: knowing when the output is wrong, what to ask next, when to stop and escalate.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The problems compound when AI starts checking AI. Alford calls it the \u201cAI loop\u201d: one system drafts a policy or control, a second evaluates it, and a third produces the risk rating an executive actually sees \u2014 each layer potentially reinforcing the assumptions of the one before it.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe final report can look sophisticated even when the original assumption was wrong,\u201d Alford says. Automation, he warns, \u201ccan fail confidently and at machine speed.\u201d Breaking that loop still requires an experienced person to check the output against the actual architecture and business impact.<\/p>\n<h2 class=\"wp-block-heading\">4. AI fluency has become a baseline hiring filter<\/h2>\n<p class=\"wp-block-paragraph\">The share of cybersecurity job postings requiring AI skills doubled year over year across G7 countries, from 14.2% to 28.5%, according to an <a href=\"https:\/\/blogs.cisco.com\/our-corporate-purpose\/ai-workforce-consortium-building-a-cybersecurity-workforce-ready-for-whats-next\">August 2026 analysis<\/a> of recruitment data from Cornerstone and Indeed by the Cisco-founded AI Workforce Consortium.<\/p>\n<p class=\"wp-block-paragraph\">But it\u2019s no longer enough for a cybersecurity professional to be technically strong. Candidates are also being screened for how they relate to the tools they use.<\/p>\n<p class=\"wp-block-paragraph\">\u201cNo company can afford to hire a new AI skeptic,\u201d says LastPass\u2019 Platt, adding that outright AI evangelism isn\u2019t the goal either, because many of these capabilities haven\u2019t been around long enough to prove themselves. \u201cAssessing AI enthusiasm is key.\u201d<\/p>\n<p class=\"wp-block-paragraph\">However, the appetite for AI-fluent hires runs ahead of what most organizations actually need right now, Fortium Partners\u2019 Autrey cautions. Many clients ask his firm for AI security talent when what they most need is asset inventory, identity hygiene, data classification, and least-privilege capabilities.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAI did not invent a new control set,\u201d he says. \u201cIt exposed the companies that never finished implementing and automating the old one.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Even when organizations try to validate AI competence, the tools they use may be lagging, too. Certifications are now the leading way organizations validate skills, ahead of degrees, says Lee of SANS Institute. \u201cA certification is a timestamp,\u201d he cautions. \u201cIt tells you when someone last proved it, not whether it is still true.\u201d<\/p>\n<h2 class=\"wp-block-heading\">5. A shrinking pipeline is becoming a security risk<\/h2>\n<p class=\"wp-block-paragraph\">The same intelligent automation that\u2019s driving cybersecurity role consolidation and boosting the importance of judgment is also closing off the paths cybersecurity pros traditionally took to develop their very human skills. Senior-titled cybersecurity postings grew 65% in the six months ending March 2026, while junior-titled postings grew just 5.9%, according to the <a href=\"https:\/\/blogs.cisco.com\/our-corporate-purpose\/ai-workforce-consortium-building-a-cybersecurity-workforce-ready-for-whats-next\">AI Workforce Consortium<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Autrey of Fortium Partners warns that Tier 1 SOC and manual control-testing work, long the apprenticeships for tomorrow\u2019s senior analysts, are <a href=\"https:\/\/www.cio.com\/article\/4188578\/how-to-keep-your-it-talent-pipeline-from-collapsing.html\">going unfilled when someone leaves<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you automate the entry rung without replacing that learning path,\u201d he says, \u201cyou are trading a cost reduction today for a talent shortage a few years from now.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The 2026 SANS\/GIAC report confirms the pattern: the gap between the skills organizations need and the skills their teams actually have has widened from a four-percentage-point spread to 20 points in a single year, and AI is disrupting entry-level roles specifically.<\/p>\n<p class=\"wp-block-paragraph\">Skills gaps overtook headcount as organizations\u2019 top workforce problem for the first time in 2025, according to the report, and the gap kept widening. Twenty-seven percent of organizations now tie an actual breach to a skills gap on their own team.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat is not a training request,\u201d Lee of SANS Institute says. \u201cThat is an incident report with the training request stapled to the back.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Mario Platt spent part of last year eliminating a team. As CISO for online password management service LastPass, he shut down the company\u2019s dedicated vulnerability management function in late 2025, folding its responsibilities directly into IT and product security. AI and business intelligence tools now handle the triage and analysis that once required a standing [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9539,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9538"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9538"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9538\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9539"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}