How AI is Transforming Roles and Skills in Cybersecurity
The integration of AI into cybersecurity is not merely a trend; it’s a profound shift in how organizations approach their security frameworks. As seen with Mario Platt, CISO at LastPass, dedicated functions within cybersecurity teams are being reconfigured to leverage AI’s capabilities. He recently disbanded a specialized vulnerability management team, realigning its functions within IT and product security where AI tools now perform analysis at a speed unattainable by human specialists.
This trend is underscored by an alarming statistic—a staggering 87% of organizations cite AI-related vulnerabilities as their most rapidly increasing risk, as highlighted in the World Economic Forum’s 2026 Global Cybersecurity Outlook. Correspondingly, the 2026 SANS/GIAC Cybersecurity Workforce Research Report reveals that 74% of companies are adapting their security teams to align with AI’s influence.
Security Leadership is Consolidating, Not Multiplying
In organizations such as LastPass, this shakeup has led to a reduction in cyber roles, as Platt seeks efficiency in his governance, risk, and compliance (GRC) operations. Automating compliance tasks is intended to enable personnel to focus on more impactful advisory roles. Industry experts like Burke Autrey, president of Fortium Partners, advocate for consolidating roles under existing leaders instead of creating new positions. For instance, one client has combined infrastructure security and AI responsibilities under a single executive, avoiding the addition of more C-level titles.
Martha Heller, CEO of Heller, has observed a surge in demand for candidates who can manage both infrastructure and cybersecurity, especially those experienced in cloud migrations. However, many companies find themselves attempting to offload AI governance onto existing security leaders without proportional staffing increases. John Alford, CSO at Quant, warns that this approach inherently concentrates risk into a select few roles.
The Security Analyst’s Job is Evolving
The role of security analysts is shifting drastically from simply identifying issues to providing critical evaluation of automated responses. Robin Fewster, head of cybersecurity at Nexus Black, notes that automation is now a baseline expectation—tasks such as scanning security sources and verifying code compatibility are performed routinely by AI systems. Consequently, the distinction between security analysts and engineers is starting to blur.
Randy Gross, CISO at CompTIA, emphasizes the analyst's evolving role in explaining the business implications of security incidents. Although automation alleviates workload in some areas, it creates space for professionals to tackle GRC debts and sharpen incident response planning. New titles like "agent security engineer" are emerging to reflect these evolving responsibilities.
Judgment, Not Just Technical Ability, is Key
As AI assumes more technical tasks, the ability to make sound judgments is becoming increasingly valuable. Quant’s Alford points out that automated solutions may produce polished results, but they often overlook core business impacts. Despite fewer experienced professionals remaining in cybersecurity roles, the need for individuals with keen judgment—a skill that is scarce—is on the rise.
Interestingly, the need for identity engineers and specialists in identity and access management has surged; clients are seeking these skills while facing a dearth of qualified candidates. Rob T. Lee, chief AI officer at the SANS Institute, states that understanding when AI outputs are incorrect and knowing how to proceed afterwards has become critical.
AI Fluency as a Hiring Benchmark
Recent data shows that nearly 29% of cybersecurity job postings now require AI competencies, nearly doubling in one year as noted in a report by the AI Workforce Consortium. Yet, organizations are no longer just searching for technical expertise—they're also assessing candidates’ attitudes towards AI technologies.
Platt warns against hiring AI skeptics, advocating instead for candidates who possess a balanced enthusiasm for AI's potential, without being blind evangelists. However, there’s a misalignment; often organizations in need of AI specialists actually require foundational security capabilities—identifying underlying issues rather than new technological layers.
Furthermore, there's a growing concern over how effectively organizations can validate AI-related skills. Certifications have become the preferred method for assessing expertise, but Lee cautions that they merely indicate when skills were last confirmed rather than their current applicability.
A Diminishing Talent Pipeline Threatens Security
The automation of roles is increasingly closing off the traditional pathways for cybersecurity professionals to gain experience. As shown in recent hiring trends, senior role postings surged by 65%, but junior roles only saw a nominal increase of just 6%. This lack of entry-level positions is particularly alarming since they are vital for training the next generation of security analysts.
Autrey observes that many junior positions in Security Operations Centers are going unfilled, jeopardizing a foundational training ground for future leaders. He warns of the risks that arise when companies automate entry points without maintaining adequate pathways for professional development. The gap between required skills and actual capabilities has widened significantly, contributing to an alarming trend where organizations attribute breaches directly to insufficient expertise.
Lee provides a stark reminder that ignoring these underlying issues can lead organizations to trade short-term savings for long-term security challenges, highlighting the pressing need for thoughtful integration of AI within the cybersecurity domain. In light of these developments, firms must not only adapt to the new technological landscape but also ensure their workforce evolves alongside it.