5 ways AI is reshaping the cybersecurity job market

Mario Platt spent part of last year eliminating a team. As CISO for online password management service LastPass, he shut down the company’s dedicated vulnerability management function in late 2025, folding its responsibilities directly into IT and product security. AI and business intelligence tools now handle the triage and analysis that once required a standing group of specialists.

It’s a concrete example of a trend that’s largely lived in the abstract: security work reorganizing itself around what AI can now do faster than people can. The pressure to rethink cybersecurity roles for this new era is profound: 87% of organizations cite AI-related vulnerabilities as their fastest-growing risk category, according to the World Economic Forum’s 2026 Global Cybersecurity Outlook. Companies are already responding. The 2026 SANS/GIAC Cybersecurity Workforce Research Report found that 74% of organizations say AI is already affecting the size of their security teams and the shape of the roles within them.

Ask security leaders and staffing experts whether AI is creating new jobs, killing old ones, or just changing what the people already there do, and they’ll tell you it’s a bit of each. Here are five ways that’s playing out across companies.

1. Security leadership is consolidating, not multiplying

Some cyber roles were eliminated alongside consolidation at LastPass. Platt is also partway through a similar shakeup in his governance, risk, and compliance (GRC) function, automating the routine compliance work so the group can take on a higher-level risk advisory role, with staff evolving into full business information security officers aligned to specific business units.

Elsewhere, entire functions are consolidating under one executive rather than splitting up among new ones. Burke Autrey, president of technology consulting and executive services firm Fortium Partners, says his firm’s standard advice to clients wrestling with AI governance comes down to one simple rule: Don’t invent another C-level title. One client recently consolidated infrastructure, information security, and AI/ML under an existing senior technology leader and promoted that person rather than recruiting a separate CISO and AI leader.

Martha Heller, founder and CEO of executive search firm Heller, sees the same pattern in her practice. Clients increasingly want a single leader to run both infrastructure and cyber — particularly candidates who cut their teeth on a cloud migration. “Anybody who’s led a really successful cloud migration will know a thing or two about cyber,” she says.

Most companies are still in an earlier, messier phase: piling AI governance duties onto existing security and privacy leaders without adding staff to match, says John Alford, CSO at Quant, where he leads security, compliance, and AI governance for the company’s agentic AI platform.

“Companies will eventually formalize these responsibilities,” Alford says. “The current model puts too much risk into too few roles.”

2. The security analyst’s job is changing from finding answers to evaluating them

At Nexus Black, the AI accelerator unit within enterprise software company IFS, head of cybersecurity Robin Fewster built an automation that scans security sources daily, checks affected packages against the company’s source code, and flags exposure. That kind of capability, he says, is becoming the baseline expectation rather than a specialty. And the line between security analyst and security engineer, Fewster says, is blurring.

Detection tools already handle the who, what, when, and where of an incident quite well, says Randy Gross, CISO at CompTIA; the SOC analyst’s real value now is in answering the why. “‘Why’ unlocks business impact, appropriate response, and long-term mitigations,” Gross says, “and, as a bonus, it’s also moving some senior InfoSec functions left.”

That doesn’t necessarily equate to fewer jobs, though. Automating a process or enriching telemetry won’t eliminate the person who did it, says Gross; it clears space to deal with GRC debt, incident response planning, and the rest of the backlog every security team has.

Today’s analysts spend less time working the queue and more time designing, tuning, and validating the systems that work the queue, says Autrey of Fortium Partners.

That evolution is producing new titles that didn’t exist 18 months ago, says Heller, including one companies are now asking for by name: agent security engineer.

3. Judgment, not technical knowledge, is the scarcest skill

Judgment is “the hardest trait to hire for,” says Quant’s Alford. AI can produce a technically polished answer that ignores business impact or architecture, he says, and reduced cyber staffing leaves fewer experienced people around to catch it.

Gross of CompTIA frames what’s happening in cyber hiring as a value shift: judgment, he says, is now in high demand.

But it may also be in short supply, according to Autrey. Verifying an automated conclusion “takes more seniority than producing the finding ever did,” he says, “and that is the seat almost nobody has staffed.”

That shortage is most acute for identity engineers and identity and access management (IAM) architects who understand machine and agent identity, a specialty nearly every client asks for and almost none can find, Autrey says.

The mechanical work of parsing logs, correlating alerts, and first-pass triage has mostly moved to the model, says Rob T. Lee, chief AI officer and chief of research at SANS Institute. “What is left is judgment: knowing when the output is wrong, what to ask next, when to stop and escalate.”

The problems compound when AI starts checking AI. Alford calls it the “AI loop”: one system drafts a policy or control, a second evaluates it, and a third produces the risk rating an executive actually sees — each layer potentially reinforcing the assumptions of the one before it.

“The final report can look sophisticated even when the original assumption was wrong,” Alford says. Automation, he warns, “can fail confidently and at machine speed.” Breaking that loop still requires an experienced person to check the output against the actual architecture and business impact.

4. AI fluency has become a baseline hiring filter

The share of cybersecurity job postings requiring AI skills doubled year over year across G7 countries, from 14.2% to 28.5%, according to an August 2026 analysis of recruitment data from Cornerstone and Indeed by the Cisco-founded AI Workforce Consortium.

But it’s no longer enough for a cybersecurity professional to be technically strong. Candidates are also being screened for how they relate to the tools they use.

“No company can afford to hire a new AI skeptic,” says LastPass’ Platt, adding that outright AI evangelism isn’t the goal either, because many of these capabilities haven’t been around long enough to prove themselves. “Assessing AI enthusiasm is key.”

However, the appetite for AI-fluent hires runs ahead of what most organizations actually need right now, Fortium Partners’ Autrey cautions. Many clients ask his firm for AI security talent when what they most need is asset inventory, identity hygiene, data classification, and least-privilege capabilities.

“AI did not invent a new control set,” he says. “It exposed the companies that never finished implementing and automating the old one.”

Even when organizations try to validate AI competence, the tools they use may be lagging, too. Certifications are now the leading way organizations validate skills, ahead of degrees, says Lee of SANS Institute. “A certification is a timestamp,” he cautions. “It tells you when someone last proved it, not whether it is still true.”

5. A shrinking pipeline is becoming a security risk

The same intelligent automation that’s driving cybersecurity role consolidation and boosting the importance of judgment is also closing off the paths cybersecurity pros traditionally took to develop their very human skills. Senior-titled cybersecurity postings grew 65% in the six months ending March 2026, while junior-titled postings grew just 5.9%, according to the AI Workforce Consortium.

Autrey of Fortium Partners warns that Tier 1 SOC and manual control-testing work, long the apprenticeships for tomorrow’s senior analysts, are going unfilled when someone leaves.

“If you automate the entry rung without replacing that learning path,” he says, “you are trading a cost reduction today for a talent shortage a few years from now.”

The 2026 SANS/GIAC report confirms the pattern: the gap between the skills organizations need and the skills their teams actually have has widened from a four-percentage-point spread to 20 points in a single year, and AI is disrupting entry-level roles specifically.

Skills gaps overtook headcount as organizations’ top workforce problem for the first time in 2025, according to the report, and the gap kept widening. Twenty-seven percent of organizations now tie an actual breach to a skills gap on their own team.

“That is not a training request,” Lee of SANS Institute says. “That is an incident report with the training request stapled to the back.”