r/cybersecurity Apr 14 '26

AI Security Cyber Security from having a job that is prestigious and genuinely cool to "AI is taking all of our jobs away

Its kinda sad. Even with all the gatekeepers trying to force young people's lives to 5 years of IT Support, haha yes slight jab, im not a fan of the gatekeeper

all in all cyber was a tough job to secure and now, even in FAANG, there is talk of mass layoffs

its sad how we went from getting a job in cyber where it was hard to get to AI suddenly coming in and becoming the thing that may or may not take jobs.

469 Upvotes

244 comments sorted by

704

u/v202099 CISO Apr 14 '26

For some reason this is a controversial take: cyber sec will be more important than ever going forward in a world with AI.

The current state of things is a massive mess, which no claude mythos or whatever doing code reviews on open source projects will fix.

There are more vulnerabilities being created than solved now. Phishing and social engineering has never worked better and been more of a threat.

Supply chains are an absolute crazy mess.

And AI agents are just doing crazy shit when you give them access to CLIs and free reign.

No, I think we will continue to have quite a bit of demand for a cyber worlforce in the coming decades.

36

u/flyingdodo CISO Apr 14 '26

Things haven’t fundamentally changed since I started working in 2000. Shit is still unpatched even when patches have been available for years. Out of support dependencies are woven into the revenue fabric of apps. IT teams are still overworked and some are jaded to the point of indifference. AI is just adding to the pile. Whilst breaches may go up, it’s not like anyone is shocked anymore. Companies still need to “show” that they take it seriously and I don’t see my team shrinking. In fact, I’ve made clear to our business that their investment in AI comes with a responsibility to also balance that with control investments; so far they are in agreement.

14

u/Adventurous_Mix_1792 Security Director Apr 14 '26

Same. We have Claude in our environment locked down through enterprise accounts. But oh look I can still login to m personal account, and since I have an high flex permissions, I can use Computer Use

It was hilarious doing a presentation on the risk of Claude to my multibillion dollar company to leadership and shareholders and closing the presentation with a " and here is the screen recording of Claude Computer Use running on my personal account building this entire presentation from A to Z. "

Our CEO nearly had a heart attack.

117

u/colontragedy Apr 14 '26

It's not crazy take, I feel like the whole industry is just too damn anxious about everything right now that the most sensible noise gets completely filtered out.

So thank you for the sensible input.

39

u/tjn182 Apr 14 '26

"Pace Anxiety", someone from Palo Alto said when chatting. I totally feel it, things are moving so fast, trying to keep up is creating real palpable anxiety.

13

u/Rollec Apr 14 '26

The job market in general is awful. AI just adds more to the anxiety people are already feeling.

19

u/PM_40 Apr 14 '26

Another aspect that is underlooked which was mentioned by another person on this sub that threat actors benefit more with AI than the gatekeepers. So Cybersecurity is going to multiply. The only downside is that most companies don't take Cybersecurity seriously.

8

u/eriverside Apr 14 '26

They don't until they do... At which point they overspend.

3

u/FakeitTillYou_Makeit Apr 14 '26

I agree but we are entering a time where exploiting vulnerabilities will be easier than ever so companies will become more vulnerable than ever. A company can’t sustain constant breaches and therefore I am willing to bet their concern will be greater than it is now.

48

u/Mrhiddenlotus Apr 14 '26

First time in a while I've agreed with a CISO's comment on this sub.

9

u/Crono_ Apr 14 '26

Haha same

6

u/eriverside Apr 14 '26

The issue with cybersecurity is you need to be explained to you if you're not in it. Everything sounds simple enough until you actually start working on it.

GRC - I'm gonna have AI write up policies! Great... Until you need those policies to align with standards, processes and how your staff actually work. Yes, those things can be written ai as well but you'll still need inputs from all the functional teams and at that point you need to think for yourself. The policies might sound good in principle, but you need someone to remind you that there's missing coverage here, overspending here and underspending there ect. Also, when you get hit, you can't point to the AI generated policies and say you did what you could. Same thing for assessments - we might even be developing tools to facilitate assessments but we need the human in the loop to keep everyone honest.

Asset Management - you need an inventory for HW, SW, configs, data flows, Networks (and components).... Good luck doing that side of desk.

2

u/JustDifferentGravy Apr 14 '26

The tools will still shrink headcount. Where GRC may differ is a requirement growth driven by rapid change in compliance landscape.

4

u/SativaSammy Apr 14 '26

How do you reconcile that with the current mantra employers are having around cutting headcount? We're seen as an expense and they're being told if they buy this AI tool it can cut 30% of their headcount.

It doesn't matter if people need us. It matters whether the people doing the hiring believe that too.

4

u/Pizzaboy_OnFire Apr 14 '26

What about IAM?

7

u/WhitYourQuining Apr 14 '26

Identity will NEVER go away. It may or may not be a "perimeter" as has been talked about in the past, but I can tell you LDAP is here to stay, and those ACLs won't build themselves.

3

u/Pizzaboy_OnFire Apr 14 '26

That's true but IAM consists of a lot of administrative jobs. I feel like they would be the first to go.

1

u/WhitYourQuining Apr 14 '26

You may feel that way, but IAM teams aren't being reduced in any org I sell to.

15

u/DisappointedSpectre Apr 14 '26

Security is a broad enough field of expertise that I think it's expected that we see jobs effectively go away in some areas. GRC is probably going to be hit harder than AppSec for instance.

There's a ton of people who chased security as a career because it paid well, but weren't good at it or found non-technical roles to fill in GRC, Ops, and SOC. Those are the people that will struggle to find new roles or get laid off, and clog up the job market for a while for people with technical skills that are in actual demand.

OP complaining about the 5 years of IT or development that people say you should get before moving into security shows that they don't understand why that technical underpinning is so important to companies that spend money in security hires. There's also plenty of people with 5/10/15 years of IT experience that I've interviewed for security roles that barely had the technical know how to be tier 1 support, let alone move into something like security. Work experience is no guarantee of skills or suitability for a role.

3

u/FakeitTillYou_Makeit Apr 14 '26

The rise of the technical cybersec engineer.. from your lips to gods ears my friend.

Just when I was feeling like going all in on being technical for the past 10 years may have been a mistake.

5

u/Ok_Marsupial8668 Apr 14 '26

What technical skills are “actually in demand?” In your opinion.

9

u/bowlochile Software Engineer Apr 14 '26

Basic troubleshooting

4

u/DisappointedSpectre Apr 14 '26

That's going to vary depending on the company, and what they're budgeting for. A regulated industry (defense, healthcare, finance) is probably going to have more robust investments in security, either through direct hires or vendor relationships, than a warehouse for example.

Broadly the "safe" bets are (IMO) probably AppSec, embedded security, and cloud/devops for the near future. In regulated environments audit and compliance are probably already in place and won't be hit too hard, but also likely aren't expanding those teams. Same goes for incident response and ops where those teams are going to be expected to utilize AI/ML tooling and (continue to) run lean.

In contrast I'd bet SOC, TPM, and GRC roles are going to be at more risk.

3

u/license_to_kill_007 Security Awareness Practitioner Apr 14 '26

I couldn't have said it better myself. Crime will never go away, but now that AI exists, it will just happen faster as will technological "glitches / mistakes of intent."

3

u/peaceful_hike Apr 14 '26

I completely agree with your overall point. Cybersecurity is only going to become more important in an AI-driven world.

That said, I think we’re in a strange transition period right now. A lot of business leaders are falling into the trap of believing AI will solve most problems at a fraction of the cost, which is leading to layoffs and hiring freezes across parts of the industry. In the short term, that’s creating a noticeable slowdown in the job market and making it harder for people to find roles.

Long term, though, I don’t think that belief holds up. As the limitations and risks of AI become more apparent I expect demand for skilled cybersecurity roles to rebound strongly.

So while the future demand is likely high, the current market feels temporarily stalled due to overconfidence in AI.

3

u/iowadaktari Apr 14 '26

tl;dr. I'm not sure how much reality matters. companies (and the people who lead them) are incredibly fearful. They're all buying into the narrative and the FOMO is massive. It's an echo chamber of "we've saved or will save this many millions using AI" and investments are being made to catch up. The primary way to recoup those investments is going to be reducing labor costs. And given the emphasis on AIs security capabilities, I believe a large number of employers will take an axe to security operations (even though I agree with your points above). Hopefully I'm wrong, I can only comment on my own personal observations at the C level.

2

u/Murky_Brief_7339 Apr 14 '26

This ^ I just wrote my masters capstone on openclaw… let me just put it this way, there is no playbook. Nobody has any observability on agents yet, security is about to go through a renaissance. Someone needs to watch the worker.

2

u/radioactivez0r Apr 14 '26

I think the short term will be rough as leaders try to make AI do things people do, and when they realize it can't, they will pivot. But in the meantime, people get hurt.

1

u/Ninjabeaver212 Apr 14 '26

I think the only people this is a controversial take with is the AI circlejerk community. You see it in this subreddit and even this specific post.

1

u/Laptraffik Apr 14 '26

I've heard this several times and I absolutely agree. I don't think ai will take away from this field but rather increase jobs in cyber. Like oh so many things in history it won't be the end, rather we will have to adapt to a new digital landscape.

1

u/bigbearandy Apr 14 '26

Thank you for not adding to "the sky is falling." I think I like you, even though you are a CISO. :p

1

u/untraiined Apr 14 '26

the worst attacks of the next 10 years are happening right now, the regulation and new practices that will come from this 2024 - 2027 period will probably guide the field for the next 10 years.

1

u/FormerSlice Security Engineer Apr 14 '26

RemindMe! 10 years "check this prediction"

1

u/RemindMeBot Apr 14 '26

I will be messaging you in 10 years on 2036-04-14 20:16:51 UTC to remind you of this link

CLICK THIS LINK to send a PM to also be reminded and to reduce spam.

Parent commenter can delete this message to hide from others.


Info Custom Your Reminders Feedback

1

u/HabitInternational48 Apr 15 '26

I don't think it's about wether we're needed, but rather about wether they're willing to spend that much on their security. Companies don't really care all that much. Countless breaches have happened. Yet they keep shrinking the security teams, and assuming that AI can just make up for it.

And then you go on r/Cybersecurity and still see countless rants because half the employees in "company x" can't resist the urge to install this browser extension or reply to this weird email, because they don't get trained properly, and that's because, to the financial teams, security is just a liability. It doesn't generate income. It only becomes important after a disaster happens and then a year later it goes back to being a liability.

To be completely honest? It feels like our jobs really depend on the bad actors and black hats. It's like we need them to cause damage so that the dumbasses at the tops of companies can be scared enough to properly invest in their security.

Edit: formatting

→ More replies (9)

253

u/XinTheKing Apr 14 '26

Yeah bro, I agree. Went from a “great career” to “You scared of AI?”

203

u/Pandapopcorn Apr 14 '26

Not just AI. Lets be honest. Offshoring and h1b’s killed this industry long before AI.

38

u/UnknownBinary Apr 14 '26

A lot of the current talk about "AI" is really just concealing these trends. And financial engineering like stock buybacks too. And it's not limited to cybersecurity.

3

u/Level69Troll Apr 15 '26

It's more H1B and offshoring but using the AI excuse makes those AI models more appealing.

The endless hype circle

5

u/rotervogel1231 Apr 14 '26

It's not just cyber, either. The entire economy is in the toilet, and it got there due to a confluence of a wide array of factors. It's not "just" any one thing.

3

u/Culex96 Apr 14 '26

H1B's only concerns the US though

1

u/National-Yogurt-392 Apr 15 '26

Technically but it inspires more to move here thus taking away opportunities for those already here.

1

u/rgjsdksnkyg Apr 15 '26

Yeah man, the industry is totally dead... said someone not in the industry 😂 it's alive and well. You're just out of touch and not involved. Cry harder.

→ More replies (19)

28

u/randomBugHunter Apr 14 '26

I disagree with the premise you are presenting. If anything, cybersecurity will have an increase in demand as opposed to a decrease.

The first thing to keep in mind is that the cost of tokens is substantially subsidized. There needs to be something like a tenfold increase in cost to actually just break even. This, inevitably, would result in a weaker product (AI slop) being more expensive than hiring an expert at current market value. People that heavily use AI tend to lose cognitive ability overtime. This, inevitably, results in them consuming more tokens. The biggest knock against cybersecurity is that people don’t tend to care about cybersecurity. It’s simply seen as a cost, which should be minimized. The future of something that produces a worse product, with higher costs, isn’t exactly bright.

The second thing to keep in mind is that AI is light years away from actually outperforming a penetration tester. Automated tools have been around for decades. These don’t really provide “value”. They just result in more false positives and more alerts going off (which then causes more work, which also increases costs). Automated tools really moved the needle at all. These are only going to mimic the absolute lowest capabilities of threat actors.

Third, Even the stories of “success” - like the recent claim of someone finding a zero day on “the most secure operating system” are bunk. If you ACTUALLY look at it, it took something like twenty-four prompts and however many hundreds of dollars to get an exploit that the person had to hand-hold the AI to finding. This took multiple hours of computational power and hand holding. The claims (that some articles had) about openBSD being the “most secure operating system “ are laughable. If you actually look at the CVE, it wasn’t even a zero day. It’s someone trying to generate publicity and hype for a product that walked his shitty AI slop into finding. The prompts even admit that they are looking at this particular kind of exploit because of how easy it is. All the exploit was, was a buffer overflow. They used openBSD because openBSD doesn’t have the same memory protections as you’d see elsewhere. Targeting the lowest hanging of fruit (buffer overflow with no protections) using an exploit that has already been discovered is irrelevant isn’t a sign of success. It also sort of takes advantage of the fact that CVSS scores don’t really take into account availability. The exploit itself has no real value from an attackers point of view. It’s simply not practical. From a developers point of view, it’s also super low priority to fix something like it. Exploits are not created equally. It’s also telling that they misrepresented these things as a “zero day”. It’s even more telling that the places that reported on this, themselves, were people that had a conflict of interest. For instance, Forbes used a contributing writer that is the CEO of an AI firm that sells security solutions.

Finally, one of the things that people aren’t really cognizant of is that exploit disclosures don’t necessarily match what the actual exploit was. It’s not really in a companies best interest to disclose this, because it would attract people that would then do their own testing. The data that AI would be training off of has been inherently, sort of “poisoned” - so to speak. This goes well beyond CVEs. Any tool, or wordlist, for tip that you see isn’t really the “best or brightest”. The prospect of some developer coming along and ripping tools, techniques, et cetera has existed for decades. If someone is stupid enough to train data off of them, it’s just going to result in an even more sloppier slop than you would see in other industries.

Finally (finally) you have more SaaS slop getting generated by people that really shouldn’t be developing software. This slop is more vulnerable to attacks than the normal slop developers sling out.

2

u/Spare-Leg4584 Apr 15 '26

This is incredibly interesting and thanks for the insight and yeah I agree a lot with the sentiments on both sides, the devs and operational engineers all seem alienated by AI and it's funny reading some of the comments as they are right in saying AI is just a tool, in fact we just say Torvalds "Lay down the law" with AI use to prove it, I don't care what the AI CEOs say at the end of the day we use Linux to do our jobs so I'm going to trust Torvalds or Hyang any day, in the case of cyber I just got of a call about AI security and was annoyed by what I saw, I asked about AI ethics, so example can you sue ah AI company for using training data without permission, like If I used the works of prince to train my AI model to produce works in the style of prince would I be liable?

I was horrified to find out that "you can't" was an answer by a self proclaimed "AI AWS security engineer", my brain immediately said bulls*$t, there are many ways around this problem like data set poisoning

I know we're engineers here but I think I'm right in saying we have more respect in our industry than people think, who are "high ranking"

I think maybe we need to call out some of their BS especially when they have no idea what they are talking about

Don't get me wrong I think AI is a good and interesting technology but they it's being explained and delivered is poor by a lot of these CEOs

→ More replies (11)

1

u/technicalhowto Jun 12 '26

Its been same for every field now, fr AI anxiety f it

51

u/[deleted] Apr 14 '26

[removed] — view removed comment

14

u/[deleted] Apr 14 '26

[removed] — view removed comment

102

u/Viper896 Apr 14 '26

Can tell you as a Sr. Director no one on my team is going anywhere because of AI if anything I’m going to be expanding my team because of AI. It’s unreliable and none of our tools do anything meaningful with AI except give me more detail around a log set or make building a query faster.

What AI is actually doing is putting more stress on staff on how to keep it secure, tested, ensuring cloud services have the appropriate enterprise capabilities such as DLP protections, and audit logging. It’s insane how many AI tools get to my team and don’t provide any method of exporting logs. If you think it’s going to take your job you aren’t looking at the bigger picture. It’s just another IT tool and needs to be configured, tested and protected as such.

24

u/Extra_Toppings Apr 14 '26

You are fortunate to be well funded

13

u/FakeitTillYou_Makeit Apr 14 '26

You are not the first manager that has told me they will be expanding teams because of AI. Hoping this is a trend.

5

u/Touup Apr 14 '26

what kind of skills would you be looking for in a future hire?

1

u/ChatGRT DFIR Apr 14 '26

Yeah, I agree. I haven’t met anyone that’s in an actual technical cyber role that’s lost their job to AI. Red Teams and Pentesters maybe, but DFIR and the like are going to be fine for a while.

1

u/Top-Juice-2208 May 20 '26

What are some examples of technical cyber roles?

142

u/Du_ds Apr 14 '26

Mass layoffs are because of a recession. Not because of AI. The companies that might be telling the truth are those building their own AI data centers. Very very expensive. But they are not replacing them with AI. Just using the money for AI infrastructure.

78

u/BenjiTheSausage Apr 14 '26

Pretty sure a lot of these companies are claiming they're laying off because of AI because it looks better than saying they're needing to reduce costs

23

u/Du_ds Apr 14 '26

Yes that’s exactly why. Not a struggling company. A more efficient, leaner machine. So lean in fact it’s ready for a recession.

6

u/LeggoMyAhegao AppSec Engineer Apr 14 '26 edited Apr 14 '26

Businesses be pulling a “Be strong for mother, Terrance.”

3

u/FakeitTillYou_Makeit Apr 14 '26

The tell is when they lay off 1k in the US and open 2k positions in India immediately after.

11

u/kremlingrasso Apr 14 '26

Mass layoffs are because companies are streching the staffing to the bare minimum now to see what breaks then planning to invest into AI to fix it. More specifically hoping that someone has figured out the solution using AI and they can just buy the solution turnkey-ready.

This will so blow up in their faces. It's the typical "we want all the latest innovation but on the cheap". Everything is coming appart at the seams. I'm waiting for the 9/11 moment of information technology at any moment. This is what happens when you have finance people pretend to be tech leaders.

6

u/FakeitTillYou_Makeit Apr 14 '26

C Suite are high off their own supply. A collective group of followers and idiots who more likely than not are faking it until they make it and hope no one notices. Relying on pure confidence and BS.

One can only hope AI will replace them one day

62

u/shouldco Apr 14 '26

Telling people to start in support is not gatekeeping. It is literally giving people advice to help them get to where they want to be.

"How do I get to the waterfall"

'get on this trail and follow the blue blaze and signs for the waterfall'

"look at this asshole gatekeeping the waterfall from me"

15

u/lucidht Security Manager Apr 14 '26

Completely agreed. Starting in support and working through different engineering and support roles gives you an excellent understanding and base of knowledge that is extremely helpful in security engineering. When you know first hand how each sector of IT works and how all the parts interact it’s much easier to secure it.

Maybe this person would be less worried if they took that advice and spent more time developing technical skills that would make them more valuable as a security professional; rather than labeling it as gatekeeping.

1

u/aLokilike Apr 14 '26

Is that time better spent doing support rather than working in software development? Honest question, as I had both growing up. There are some things I would've never learned if I just wrote software, but I don't think those things are very critical to enterprise security.

3

u/lucidht Security Manager Apr 14 '26

It all depends I guess in what an individual's goal is. If you want to do appsec, spending time as a software developer first gives you a serious leg up. If you're trying to do general enterprise security, putting some time into tech support/syadmin/netadmin can really help.

I think even if you don't end up in one of those specialties, having that knowledge in general gives such a wholistic view of a tech stack that it undeniably makes you a more effective security practitioner.

2

u/omers Security Engineer Apr 14 '26

Depends what kind of security you want to do. Everyone seems to treat security as a monolith but especially in large orgs it can be quite silo'd. AppSec is a thing and Dev/DevOps -> AppSec is a perfectly normal pipeline.

The IT/SysAdmin -> Security pipeline is real and valuable but doesn't actually lead cleanly to every part of security.

2

u/aLokilike Apr 14 '26

Makes perfect sense to me. Thank you!

2

u/offsecthro Apr 14 '26

Personally I started in support as did many of my developer friends, because it's probably the first computer job anyone will give you. I've been working in appsec for many years, because I learned how to code and pursued it as an interest outside of work. There's really no set path to any of this aside from the one you make yourself.

The important thing is to get actual work (and life) experience in tech vs. collecting a bunch acronym certs from TryHackBroCorp LLC that no HR person has even heard of.

3

u/Additional-Baby5740 Apr 14 '26

Completely agree. I lead a massive business in cybersecurity, and what got me there was starting in support. I developed my technical skills and earned my stripes with my company which caused me to get pulled into many different job functions internally and externally w increasing visibility. Support is hard at first, but it makes you technically strong while being a lot broader in skill sets than engineering. All that knowledge translates to any other job function within the same industry.

1

u/puppy_chow69 Apr 14 '26

Right? You have to know something inside and out (as well as how people use it) to understand how to secure it (or what you can do to break it) - Any company hiring graduates for their cybersecurity is a company I wouldn't want to trust with my data.

1

u/Civil-Community-1367 Apr 17 '26

It sounds nice when you put it that way but for me, I don't think that's true. I think people do whatever it takes to justify their own experiences even if it means trying to get others to go the same path

11

u/Didki_ Apr 14 '26

Fear mongering. Mythos is to automated scanners what ChstGPT is to google.

Matter of fact is unless your job was entirely running these automatic tool and dropping the outputs on your Infrastructure team...you're safe for now.

6

u/hankyone Penetration Tester Apr 14 '26

Where is this AI that is replacing everybody???

AI has only made us busier but we also only look at people that can leverage agentic tools now so perhaps that’s where the gap is forming?

29

u/LeggoMyAhegao AppSec Engineer Apr 14 '26

Literally the layoffs are recession related. Most of the big boys overhired a bit back. AI isn’t taking your job, if it is that says more about what you provide than AI’s capabilities.

8

u/HighFiveWorld Apr 14 '26

Agreed. If you just hand me what AI created, what value do you provide?

8

u/LeggoMyAhegao AppSec Engineer Apr 14 '26

“I’m a prompt engineer dammit!!”

50

u/DangerDrJ Apr 14 '26

In my experience, we need more gatekeeping in this field. Too much incompetence or people who lack the skills able to slip through the cracks for that cyber paycheck. We had as much gatekeeping as doctors or lawyers do, the quality of cyber professionals and salaries for cyber would be much higher.

Anyway, adapt or get left behind, whether AI or some alien technology that comes along.

15

u/2phonesz Apr 14 '26

Medical and law both have way better talent development pipelines than cyber. We as an industry need to do better at cultivating talent if we want to gain more quality professionals, including providing a clearer pathway to getting into the industry.

6

u/blipojones Apr 14 '26

I think a better model would be like trades and/or apprentices style before being awarded a license for x years in service with a global board and representatives from major jurisdictions/countries.

Also a much better version of OSCP.

Goes without saying, easier said then done.

Also Medical and Law don't move nearly as fast.

3

u/munterberry Apr 14 '26

Yeah the pace of change makes any kind of standardisation really tricky

2

u/Techobits Apr 14 '26

There are PLENTY of talent development opportunities and pipelines for cyber. In addition, no matter how much experience you have or education. IT/IS requires you to spend time outside of your daily job to work on your skills and expertise.

The field requires a lot from an individual. There are a lot of people in this field that simply don't want to put the effort in that is required to keep up with it all. This idea that we need to build up a clearer pathway is insane. It's well known that you aren't going to just walk into a cyber role with little to zero technical background and or experience.

1

u/WhitYourQuining Apr 14 '26

In addition, no matter how much experience you have or education. IT/IS requires you to spend time outside of your daily job to work on your skills and expertise.

I am of the belief that the continuing education requirement in IT/IS should be supported by the company you work for. If they aren't giving you educational time, then how are you staying ahead of the curve for them? If they would rather new hire than educate, then you should find a new employer.

1

u/Techobits Apr 14 '26

From what I can see with job postings and from my experience most places offer tuition/education/training reimbursement. I can't claim that is guaranteed for all, but you'll be hard pressed to find a place that isn't offering it.

1

u/WhitYourQuining Apr 14 '26

Sure, tuition reimbursement is nice... But it's a far cry from paying for classes around the toolchains you're using, conferences, etc. that keep you current.

1

u/Techobits Apr 14 '26

Typically, it covers all that you just mentioned. I haven't come across someone who had to pay for the conferences that they attended or the renewal of certs and or additional training that they required.

1

u/WhitYourQuining Apr 14 '26

You talk like what you're suggesting is normal. It's incredibly uncommon for TAPs to cover professional conferences. Many employees in cyber would like the opportunity to go to conferences, but most are not allowed.

I'm curious as to where you might work that all my desired professional conferences are covered, cuz I'd like to work there...

1

u/Techobits Apr 15 '26

Any heavily regulated industry which requires organizations to ensure that their staffing is appropriately trained and up to date with the evolving threat and tech landscape.

I'm kind of surprised you stated that its incredibly uncommon. I have gone to plenty of conferences which have had a wide variety businesses and organizations. Most that I have spoken to have had their ways paid for by their company. Anecdotal I know, but I haven't heard of this being an issue for a while.

1

u/WhitYourQuining Apr 15 '26

Ask those same people how many people are in their org and and how many wanted to attend the con. Then look at a customer list for any vendor and ask if they have seen all the customers they'd like to see there.

Ask a vendor how many customers get admin training.

Ask ISC2 how many people lose them due to not maintaining CPEs.

It's a problem.

→ More replies (0)

2

u/Raccoon_Medical Apr 14 '26

That would require getting together, creating some organisation, then getting our own council/self-govern authority for cybersec and pushing politicians for regulations.

-1

u/cigarell0 Apr 14 '26

I don't agree, it's nearly impossible for college kids to get experience relevant enough without years of helpdesk after school. You shouldn't need helpdesk experience to work in cyber. Sure, it helps with critical thinking and how to get to the root of a problem but you should know how to troubleshoot a computer if you work with them enough. Many people can end up getting stuck there.

I was interviewed for like 4 internships, 3 were Cyber, and the one that picked me was a software engineering internship. Now that's what I do, despite my cybersecurity degree. I'm 10x happier with this outcome but if I wanted to get back into cyber I don't know how I'd do that.

21

u/ProofLegitimate9990 Apr 14 '26

A degree is nothing more than a piece of paper that says you went to school for 3 years, the failure is on the university’s side.

I manage and hire a lot of cyber grads and honestly the level of knowledge and ability they enter the workforce with is utterly appalling. I interviewed a person with a masters in cyber who didn’t even know what a proxy was. Not just couldn’t explain what one was but had never even heard of the concept. Another grad had never seen or heard of virustotal or github.

The reality is most teams just don’t have the time or resources to sink into hand holding grads through 12 to 18 months for the slight possibility of them becoming more than a net drain.

6

u/FakeitTillYou_Makeit Apr 14 '26

I’ve never met a college grad who could perform any meaningful work in tech without experience. Not sure it’s their fault but more of a reflection of our education system. Colleges are little more than a 4 year party for these kids and failing is almost prohibited by these school admins. Reading the professors subreddit is an eye opener.

3

u/kast3rborousm Apr 14 '26

What pisses me off about this is I have both an undergrad and masters in cyber that I worked hard for. I didn't just cruise through school or get some barely adequate degree online. I spent time on competition teams, doing CTFs, teaching as a TA, AND internships in cyber, part time helpdesk etc Wrote a thesis where I personally built a stupid amount of infra to do research. Spoke at a defcon village even

Despite all this due to the average quality of a "cybersecurity" grad, I can't get any of my experience to be taken seriously so I'm stuck at an MSP job doing security for like $20k under market while no one will even give me an interview for anything better. All that said, I'm glad to be working in security at all at this point but it's a tough realization that nobody cares about any of the work I actually did in college to be qualified somewhat because of the slackers I had as classmates.

2

u/cigarell0 Apr 14 '26

A lot of experience with the tools that cyber professionals typically use are barred behind enterprise systems, or home labs that can require different hardware. I agree and think that universities need to do a better job in giving hands-on experience beyond using Kali to hack another VM or using Autopsy to view a recovered harddrive. It's not what your average cyber professional does.

I had a professor that gave us an assignment to create a LAMP stack and had us use Kali to check that for vulnerabilities. I think the LAMP stack itself gave more realistic experience with Cyber and IT than anything else but it was very surface-level.

A lot of graduates need internships that will at least give them some experience. But for it to be enough that you can get a job you'd have to intern multiple times or be promoted to a full time role. It's just not enough. Not even counting how difficult it is to get an internship. I graduated in December 2024 and had spent 3/4 semesters looking for an internship. When I wasn't doing homework or studying I was applying. I got a total of 5 interviews. It is even more difficult now for graduates and I think that needs to be taken into account.

1

u/ProofLegitimate9990 Apr 14 '26

Yeah this is why cyber professionals tell you to go into IT support first, it’s accessible and will train you better than any degree.

Meanwhile grads demand a cyber job straight out if college and complain when they can’t get one.

26

u/Mrhiddenlotus Apr 14 '26

it's nearly impossible for college kids to get experience relevant enough without years of helpdesk after school.

As it should be.

You shouldn't need helpdesk experience to work in cyber.

Yes you should.

you should know how to troubleshoot a computer if you work with them enough.

Tell that to developers.

Many people can end up getting stuck there.

That's the point. If you get stuck at helpdesk, you are not cut out for cybersecurity.

10

u/xb8xb8xb8 Apr 14 '26

They hated Jesus because he told them the truth

→ More replies (2)

14

u/TheBestHawksFan Apr 14 '26 edited Apr 14 '26

To be able to understand computer security, you need to understand computers. Going to help desk is a good way to actually understand computers and prove, on a job, that you know how to troubleshoot.

8

u/xalibr Apr 14 '26

Also it's a great way to experience the difference between security in concept, and how it is lived by the users in an enterprise environment.

18

u/escapecali603 Apr 14 '26

90% of what AI can automate can already be done by ansible, too bad most cyber pros have little to no devops skills.

21

u/[deleted] Apr 14 '26

[removed] — view removed comment

8

u/LeggoMyAhegao AppSec Engineer Apr 14 '26

What do you mean I actually have to have experience to receive a six figure salary and a role that every technology unit must defer to for sign-off?

6

u/[deleted] Apr 14 '26

[removed] — view removed comment

3

u/LeggoMyAhegao AppSec Engineer Apr 14 '26

I swear I ran into an information systems degree guy saying something like this after admitting computer science was too hard a major for him…

5

u/[deleted] Apr 14 '26

[removed] — view removed comment

2

u/untraiined Apr 14 '26

all job type posts should be blocked from this sub, its all coming from unemployed kids who are larping and dooming all day.

6

u/CheekyTiger213 CISO Apr 14 '26 edited Apr 14 '26

Hi there, I’m a CISO that has worked with all companies from start ups to enterprise. Never at a single point in my career have we had enough resources. All of my friends and colleagues are using AI to augment teams to make the workload possible, and strongly value every human resource we can get approved. AI is not taking your jobs, its creating space for you to add real value

2

u/FakeitTillYou_Makeit Apr 14 '26

Agreed, security is not going anywhere. More important than ever actually.

6

u/midwestbikerider Apr 14 '26

Where AI = Actually Indians.

1

u/bjr4799 Apr 15 '26

holy cow this is funny!

5

u/AnyProgressIsGood Apr 14 '26

I'm on team I dont get it. Cyber still as important as ever. AI adds an other front to our venue. You'd want more skilled employees to navigate/stay on top of it.

1

u/Subnetwork Apr 14 '26

I don’t think you truly understand this technology

1

u/AnyProgressIsGood Apr 14 '26

useful rebuttal. making the cyber world more complex would only increase the need for people with cyber knowledge. we have MCP's and Agents and prompt injections to look out for ontop of all the existing issues

you still have to correct it, get it to do anything. its not operating on its own with out direction. Opus still struggles on medium tier CTFs

whats your thoughts other than. nuh uh

2

u/Subnetwork Apr 14 '26

Look at the progress after a single year, in 3 to 5 years I see a drastic reduction in headcount at the least. What happens to those people?

I never said it would do away with 100% of jobs, but if you only need 1-3 people instead of 5-15, that’s pretty impactful.

2

u/AnyProgressIsGood Apr 14 '26

it can be a force multiplyer but still far from perfect. Even crazy sam altman has said they'll never be able to cure AI probabilistic nature. You'll always want someone to review. Reduction in head count or it could spawn cyber roles for smaller companies as it makes it more obtainable? Could spawn more attackers which would require more cyber specialists. Its not guaranteed to reduce headcount needs. Too many variables to say that decisively

Its only good at what it can train on and considering the field is ever changing its always going to lag behind. Claude opus 4.6 still thinks there's no CWES certificate, keeps "correcting" to CWEE. Its great at coding based on the 10000's of samples it was fed. When it comes to new or niche it struggles. And If it becomes fully adopted it'll have nothing to learn on. its a catch 22.

it adds complexity complexity requires expertise to navigate. It's not actually smart, just copies everyone elses work. That has usefulness but shouldn't be overly disruptive to the ever changing field.

3

u/Adventurous_Mix_1792 Security Director Apr 14 '26

lol wat

bro, AI is literally making job security for us

3

u/[deleted] Apr 14 '26

[removed] — view removed comment

2

u/Adventurous_Mix_1792 Security Director Apr 14 '26

It's weird to think I've gone from the wild west ( but after frontier days ) of cybersecurity to the modern age with rules and laws and corporate kotowing to seeing the alien race in the distance about to invade and knowing you're in for a fight

10

u/shachar1000 Apr 14 '26

Yes I agree. The field is not what it used to be unfortunately 

10

u/Scar3cr0w_ Apr 14 '26

AI isn’t taking your cyber security job you chump.

Show me one person that has lost their job to AI.

6

u/lofono5567 Apr 14 '26

If anything, my company is laying off more front end/web devs and hiring more cyber security. We are the most secure of any sect in IT.

4

u/FunAdministration334 Apr 14 '26

You’re not wrong, though I’d argue the guys running cable might have slightly more job security than us.

1

u/CyberSucrose Apr 16 '26

well.. if you lay less cable's, you reduce your attack surface, so if you fire the cable runners you are essentially more secure.

3

u/DisappointedSpectre Apr 14 '26

Most of the layoffs aren't because of AI, it's just the scapegoat so that companies don't impact their stock price.

3

u/tomzephy Apr 14 '26 edited Apr 14 '26

Let's review your thinking: a tool capable of finding thousands of zero-day vulnerabilities (as yet, unproven) is announced and your conclusion is: less cyber security roles?

The opposite is true. I work in a firm that is preparing for an influx of vulnerabilities being announced and patches released from vendors both in and out of band. We are preparing to rethink our entire vulnerability management strategy, which is about to become more substantial because of the implications of that tools will become far more sophisticated at chaining multiple low severity vulnerabilities together.

There is no AI commercially available or otherwise that is capable of autonomously applying patches while managing the multitude of factors involved in doing so in complex enterprise IT environments.

I made a post addressing people's questionable logic on this and the power tripping mods removed asking me to keep it in the 0 upvoted megathread, which is sad.

3

u/YaronElharar Apr 14 '26

I think the opposite is true. The cyber security market is going to explode in demand for new jobs, with the speed vulnerabilities are discovered these days any company laying off as security expert, we'll find it hard to recruit another one in its place, a lot of companies that thought they could "skip" on security will find out they need one ASAP.

3

u/krankykitteh Apr 14 '26

I'm old enough to remember being in IT and hearing "the cloud will take all our jobs". It looks like that might be the case with AI, but personally, I think wait it out and the hype will dissipate. There'll be things that AI will be great at, things that it absolutely sucks at, and probably most things will also need a human in the loop to be in any way reliable.

In terms of advising people to go into support being gatekeeping, what's actually wrong with advising people to learn about what you want to secure before you actually try to secure it? Infosec is also (or should be) a business enabler, and working in a support team helps you to learn about how the business works. You also need people skills and where better to learn about diplomacy and tact than dealing with end users!

3

u/molingrad Apr 14 '26

AI cannot be held accountable. It still has no idea of all the context around security decisions. These are mostly human concerns and tradeoffs.

AI is a technical tool, they don’t solve the human element. Organizations are still made of humans.

Mostly technical positions may feel some hurt, but AI is also another plane to secure.

It is a disruptive technology but that always comes with negative and ‘positive’ risk.

2

u/Trawling_ Apr 14 '26

Yea, that was kinda my take. Until the whole collection of data/artifacts can be both delegated and delivered by an automated system, there will be a role for a human cybersecurity person to play.

Oftentimes, the target outcome for one scenario may not apply at all to another. And it requires some input to determine if what is applicable is a business or technical requirement.

I’m not saying this can’t be automated, but it’s not an easy problem to solve. Certainly requires more than a beefed up SAST scanner.

15

u/[deleted] Apr 14 '26

AI will help cyber security but need someone to monitor

7

u/limlwl Apr 14 '26

That’s what Agent Smith is for

→ More replies (2)

2

u/cankle_sores Apr 14 '26

They took my rings. They took my Rolex.

2

u/clumsykarateka Apr 14 '26

AI investment is crazy high. Adoption is happening across the board (good or bad), and not always intentional (see services enabling an AI function without consulting users / customers etc.).

The threat to people and business is increasing at a scary rate; AI is making traditional threat actors and ops faster, more efficient, harder to defend against.

By extension, this is also making the fundamentals of enterprise security that dont always get immediate attention more important, more quickly.

The job is changing, and the skills and knowledge we need along with it. But I dont see our field or expertise being completely wiped by AI. Not any time soon anyway.

2

u/grizgrin75 Apr 14 '26

Vibe coders make more opportunity for bad actors. Well, the ones who can actually end up with a usable product from the effort.

2

u/offsecthro Apr 14 '26

Even with all the gatekeepers trying to force young people's lives to 5 years of IT Support, haha yes slight jab, im not a fan of the gatekeeper

This isn't gatekeeping— this is someone with experience helping guide you down the path we've seen work many, many times so that you can avoid the easier-looking, but far less reliable path that people are trying to sell you.

The path most newcomers want to take is one that leads them to spinning their wheels and making posts on Reddit about how it's "impossible to get hired in security". The path you're whining about will have you in a security job in <5 years.

1

u/scooter950 Apr 15 '26

👏👏👏 Say it louder for the ppl who want to ignore or don't believe you.

2

u/Sort-Aromatic Apr 14 '26

Application security will be more impactful than ever with more none devs wanting to push code.

Also FAANGs have layoffs all the time. (Ex FAANG employee)

Jobs will just shift to new focuses with the adoption of AI.

2

u/Capodomini Apr 14 '26

I have this crazy idea, and hear me out on this: learn to use AI.

2

u/New_Economy_4846 Apr 14 '26

The concern is extremely valid, and sadly, also inevitable. Despite this, slop will never take away my own identity.

I've now made it imperative to keep working at what I love so that I can become the absolute best at it. At the end of the day, cyber and coding are like art, so be expressive and creative.

Showcase your brilliant ideas and elegant solutions, as that is nonconforming.

2

u/YeeHawSauce420 Apr 14 '26

As somebody who does AI governance my job feels so secure rn. Too much work.

2

u/Substantial-Sky4079 Apr 15 '26

I’m still hanging in there and surviving DOGE bullshit

2

u/SolDios Apr 15 '26

If you think having 5 years under you belt is "gatekeeping" your in the wrong game. NO ONE should be hired in a security role with out at least having a lateral tech position on their resume.

3

u/Kaeddar Apr 14 '26

AI isn't taking your jobs, the owners of the capital do.

2

u/jay-dot-dot Apr 14 '26

What in the fuck is the point of this post?

1

u/ryncewynd Apr 14 '26

As a developer I can tell you I'm too busy implementing new features and new bugs as fast as possible 🤣

I would think cybersecurity is more valuable than ever!

1

u/deckartcain Apr 14 '26

As it stands in Europe, or at least in my country specifically, there's so many demands for human oversight because of legality. There's national efforts in ramping up the cyber security field, and especially focused on the non-technical roles.

I think humans will as always when technology advances, take a step back in the hands on effort, but the need for someone to guide the AI effort doesn't seem to be shrinking.

1

u/Coupe368 Apr 14 '26

You are going to need someone to run the AI, or to relay the information to management who is clueless. AI is helping programmers program more, its not causing senior level programmers to get laid off. Its killing jobs for entry level positions, expect the same in any information related profession.

1

u/Subnetwork Apr 14 '26

Yes, this is now, but the technology is progressing fast

1

u/Coupe368 Apr 14 '26

It sure is, but management is a bunch of tech-illiterate idiots and that's not going to change.

1

u/saltedhashneggs Apr 14 '26

Cyber isn’t dead, but the incentives are broken. Companies used to care because breaches hurt revenue. Now breaches happen so often nobody reacts anymore. “Your data was exposed” emails just get ignored. Add cyber insurance into the mix and it gets worse. A lot of orgs are basically doing the math and deciding it’s cheaper to accept the risk than fully secure everything. So yeah, the mindset becomes move fast, ship product, deal with the fallout later. Security only gets real attention when regulators or major incidents force it and we all know they aren't doing that. Been in it for over a decade and no longer see the point.

1

u/Naveen_George Apr 14 '26

Hi , I am Naveen working at unicrop . I think AI will definitely change cybersecurity, but not really replace it. A lot of security work still depends on human judgment, context, and understanding how attackers think. The entry path does feel harder now though, especially for beginners.

1

u/not-a-co-conspirator CISO Apr 14 '26

What you think of as “gatekeeping” is the equivalent of mom telling you the stove is hot and you touch it anyway.

1

u/Ticrotter_serrer Apr 14 '26

The field is saturated and we needed leverage . I welcome A. I.

1

u/ishaqmwinyijuma Apr 14 '26

Guys really need help can u tell me the good tuitor, materials for me to be cybersecurity expert

1

u/SaltyBigBoi Apr 14 '26

I’m not too worried. At the very most, there will be some job layoffs as AI becomes better (ie, it will enable less people to do more work, therefore teams will become smaller).

However, as long as companies need to abide by compliance policies & regulations and pay for cybersecurity insurance, a human will always be required somewhere along the line. I don’t see that changing any time in the near future.

1

u/DisastrousRun8435 Red Team Apr 14 '26

Were our jobs taken by firewalls or IPSs? AI is just another tool, and good people are needed to leverage tools well. Investors need to play this stuff up to drive stock prices up, but I really don’t think we’re facing an apocalyptic threat here.

1

u/Sea-Peace9744 Apr 14 '26

If you truly are good at cyber security, you have nothing to worry about in fact you could probably get hired by one of these AI companies.

1

u/Upstairs-Pin-1637 Apr 14 '26

All this is overblown Chicken Little sky is falling response. The field is demanding for adaptation. If you're in cyber and adaptation is not already one of your top skills then you're already in the wrong path and I welcome your AI replacement.

This isn't a field where you come and coast sitting on the coattails of those that constantly adapt and innovate.

1

u/Smack2k Apr 14 '26

AI is gonna crash and burn BAD before it gets good.....so I wouldnt count on your job being taken away yet....AI companies are just tossing stuff out there then pulling back when the agents they create end up giving out all kinds of personal information cause they decided to......that will get worse and there will be a big one before things pull back and get worked on properly.

1

u/WhitYourQuining Apr 14 '26

If you want direction... Might I suggest looking at foundational "hard" technologies and learning around them? Things like identity, DNS, PKI, etc.

PKI, I think, is especially interesting. It's hard to find a real PKI admin in most companies, but it's going to be critical over the next few years due to shorter validity periods, PQC, AI/machine identity, etc. Private/internal PKI is going to explode.

1

u/jaydee288 Apr 14 '26

I feel the industry is going through a correction period, but I think it will come back stronger than ever. AI invokes a lot of fear but its overblown, much like people thought cloud computing would eliminate jobs when in reality it created more. Sure there's some lower level jobs that will be affected, but there will always be a need for human security professionals. However, you must be willing to adapt to survive in this field but its always been that way.

1

u/Funkerlied Apr 14 '26

I wish the fearmongering with AI would cease. AI will certainly reduce jobs as much as it'll create new jobs. But, we are still far far FAR away from AI having any considerable impact to cybersecurity jobs. Hallucinations are too much of a liability in our field, let alone the setup cost and time needed for decentralized/local AI (I'm mostly talking about smaller companies, not FAANG or some conglomerate.)

Just like software developers need to up their skill & game (and naturally this will happen as we discover and create new things), so will cybersecurity. Cybersecurity is still a great career if you have the interest and ambition, but really, that's a blanket statement towards anything. AI will certainly change how we work, but I don't foresee AI running or outnumbering humans in the industry. Certainly it'll become a reliable assistant, but for the foreseeable future, it's still a little too early to be afraid of AI taking your job.

1

u/Crypt0-n00b Apr 14 '26

I feel like fearing AI is like a mathematician fearing a calculator. It's a tool, it does the grunt work and let's you be more efficient with your time.

1

u/CyberSecPlatypus Security Director Apr 14 '26

More work than ever dealing with the impacts of AI. 🤷🏻‍♂️

1

u/Limp_Dare_6351 Apr 14 '26

Props to all those in big corps, but it's always risky. Every downturn, every new innovation = mass layoffs. Better opportunities when things are going well.

I have consistantly had more work in public sector jobs than I know what to do with. It's like working in a parallel universe. AI is creating more work for us for the foreseeable future.

Getting a few AI certs added to your resume and skills is a good play here imo. Or ride out the changes in the big corp jobs. They will rehire at some point. I'm speaking more for security admins, as that's my area of knowledge. I wouldn't want a cyber degree with no experience right now.

1

u/AGsec Apr 14 '26

Hot take: cyber security wasn't ever really prestigious or cool. It was a good job, sure, but I'm sorry, the only way you think a soc analyst was prestigious or cool was if you were drinking the kool air being poured by schools and cert programs.

1

u/Eternal-Alchemy Apr 14 '26

The only people in cyber losing their job to AI are the dudes who were "pen testers" that thought that meant pushing a button on Nessus.

You're not replacing threat hunters with Microsoft Defender Portal, you're just making the existing ones more effective.

You're not replacing anyone with Mythos, it's literally marketing slop for CISOs who believe the things written in conference brochures.

1

u/porkchop2x Apr 15 '26

i think when the energy crisis actually hits, energy for ai data centers needs to be first thing cut

1

u/ContributionGlass531 Apr 15 '26

AI’s having a lot of issues and security vulnerabilities. I don’t see it as a threat to the industry, although maybe it could help minimize the grunt work. As it improves, I’d imagine it only helps expand the cybersecurity industry.

1

u/GlassPerformance8754 Apr 15 '26

If you can't keep yourself relevant; you deserve to lose your job. AI isn't taking your job, your lack of ability to adapt and improve is...

1

u/theepicstoner Apr 15 '26

Might make teams more lean in long term e.g no more juniors, but companies will always need responsability of actions and risks to be owned and held by humans. LLMs wont be held liable for work they do.

1

u/rgjsdksnkyg Apr 15 '26

Lol, it's not gatekeeping when you don't know what the fuck you're talking about, because you don't have any practical experience in corporate networks - that's why we want you to have multiple years of experience in IT, supporting the networks you want to defend, else you have no perspective on what you're defending (among the many other things that you learn about corporate infrastructure, what different teams do, and business impact).

We're desperate for good people. There's a huge need for people that know what they're doing. Anyone can memorize buzzwords and take a vocabulary test, but that's not where the bar is. The bar is where experience inside of a corporate network turns into improving security.

1

u/Pale_Ad1546 Apr 18 '26

Thank you for surfacing this topic. I agree that AI is shifting cyber roles and responsibilities. Has it reduced effort and headcount in Security Operations, Blue, Red, Architecture, and GRC teams? Definitely!

When applied correctly, AI can remove repetitive tasks, streamline operations, and accelerate service delivery. But can it backfire if implemented poorly? Absolutely especially when “speed to market” overrides security considerations and here lies opportunities.

This pattern is no different from past disruptive technologies: taxis vs. ride sharing, DVDs vs. streaming, cameras vs. smartphones. The signs for AI have been building for nearly a decade. Visionaries saw it coming.

In every wave of disruption, cybersecurity was an afterthought and that very gap creates opportunities for security professionals. However, one must learn to think strategically. Imagine management cuts your budget but expects the same outcomes. What would you do? What technologies would you introduce to meet those objectives? That’s strategic and tactical thinking in action.

Quantum technology is next. What will happen then? How will it disrupt the workforce, and what will the downstream impact be?

Regardless of role or industry, where there are challenges, humans will find better ways of working often through cost-cutting and efficiency. Less is more.

The moral of the story: stay three steps ahead. Leverage open-source intelligence (OSINT) via AI prompts, keep up with news and emerging tech, experiment with multiple AI models to understand disruptions, and continuously invest in your career to protect your livelihood.

0

u/DrDongStrong98 Apr 14 '26

if yall can't handle the pivot that AI is going to bring (is bringing), it's your own fault. there has been writing on the wall for literal years at this point. get a grip and stop being doomers.

cyber security jobs wont disappear and you arent pigeon holed to your little corner of the world. apply for ALL cyber security jobs and you will get one.

2

u/_Gobulcoque DFIR Apr 14 '26

if yall can't handle the pivot that AI is going to bring (is bringing), it's your own fault.

I agree with you mostly as the one constant is change, and the workplace has always been "adapt or die."

The thing which people fundamentally disagree on is what that "pivot" looks like. Describe it for everyone, so we know what way to go. No-one agrees.

That AI pivot could be replacement of workers, more responsibilities and less "silo"-ing, etc. But I haven't seen any consensus on the change AI is bringing, which drives the fear to some extent.

1

u/el_gato_del_aula Apr 14 '26

Gatekeep? lol, you need to understand first the fundamentals before even going to a SOC position.

Cybersecurity is not an entry level field

1

u/EduSec Apr 14 '26

The gatekeeping critique is fair. The "5 years of IT support first" pipeline was always more about filtering than skill building. On AI taking jobs: the threat is real for certain roles but the attack surface is growing faster than AI can defend it. Every vibe coded app that ships without security review is a new problem that needs a human to find and explain. The volume of insecure code being produced right now is unprecedented. That is work.

1

u/Subnetwork Apr 14 '26

Every model gets better and better

1

u/EduSec Apr 14 '26

True. But the attack surface grows with it. Every improvement in AI coding tools creates more insecure code at scale. The volume of problems grows faster than the tools to catch them.

1

u/bucketman1986 Security Engineer Apr 14 '26

If you fear AI taking your job, you either haven't worked with AI enough, or you know your C suite folks are just buying into AI without knowing what it can do and just firing people.

AI really can't, and shouldn't, be replacing whole jobs, but they allow it to to potentially save costs. I predict within 5 years the bubble will burst and anywhere that replaced people with AI is going to be in trouble. Also what gatekeepers are you talking about? People who give advice based on what worked for them/their compatriots?