AI & ML

Transformations in Cybersecurity Roles Driven by AI: A New Era of Staffing and Skills

AI is reshaping cybersecurity roles, changing job functions, and creating new hiring demands while highlighting a critical skills gap in the industry.

Sep 21, 2026 3 min read
Sign in to save

Mario Platt's experience as CISO at LastPass illustrates a significant trend in cybersecurity: roles are being streamlined in response to AI's capabilities. With the closure of dedicated vulnerability management roles, Platt integrated responsibility into IT and product security, relying on AI and business intelligence tools for tasks once performed by specialized teams. This shift signifies how organizations are adjusting to AI's growing presence and its ability to perform tasks more efficiently than humans.

According to the World Economic Forum’s 2026 Global Cybersecurity Outlook, a staggering 87% of organizations regard AI-related vulnerabilities as their fastest-risks. Further exacerbating the issue, the 2026 SANS/GIAC Cybersecurity Workforce Research Report indicates that 74% of companies have already seen AI impact their security teams' structure and size. Such extensive changes prompt a reevaluation of job functions within the sector.

1. Consolidation of Security Leadership

The consolidation of cybersecurity leadership is evident; many functions are merging rather than expanding. Platt is automating routine compliance tasks within his governance, risk, and compliance function to enable personnel to adopt more strategic roles, evolving into business information security officers who align closely with various business units.

Industry experts like Burke Autrey from Fortium Partners advocate for a unified approach, discouraging the creation of additional C-level positions. Instead, companies are promoting existing leaders over introducing new ones to tackle AI governance. Recruitment patterns reflect this wish for a singular leader adept at managing both infrastructure and cybersecurity functions, particularly those experienced in cloud transitions.

Despite this trend, many organizations are still in a transitional phase, assigning AI governance responsibilities to current security leaders without increasing team size, leading to potential risk concentration. Quant's CSO, John Alford, emphasizes the future necessity for companies to formalize these evolving roles to reduce systemic risk.

2. Redefining the Role of Security Analysts

The role of security analysts is shifting significantly. At Nexus Black, Robin Fewster has developed an automation that continually scans security sources and checks code packages, which has become an expected norm rather than a unique advantage. This progression raises questions about the distinction between security analysts and engineers.

As Randy Gross, CISO at CompTIA, points out, current detection tools are adept at addressing the logistics of cybersecurity incidents. Analysts now derive value from discerning the reasoning behind incidents—the "why"—which informs business impacts and efficient responses. The focus on higher-level analysis rather than merely troubleshooting is growing, generating demand for new job titles like agent security engineer.

This evolution doesn't necessarily spell doom for existing jobs; instead, it opens opportunities for security professionals to address lingering backlogs in compliance, incident response planning, and governance issues that previously remained unaddressed.

3. The Rising Importance of Judgment Over Technical Skills

As the landscape shifts, organizations are prioritizing judgment, a trait that's increasingly challenging to find. Less experienced staff may miss critical analyses, particularly as they pertain to business implications. Alford notes that AI can generate polished answers, but these often lack the necessary contextual understanding or integration with real-world architecture.

CompTIA's Gross highlights this shift as a change in hiring priorities, but Autrey warns of potential oversights: confirming an AI's conclusion requires more seniority than producing the finding itself. This skill shortage notably impacts roles such as identity engineers and IAM architects, where experience is in high demand yet short supply.

As automation overtakes entry-level tasks, the remaining responsibilities necessitate discerning judgment, especially when navigating AI-generated outputs. Alford references the "AI loop" phenomenon, where automated systems may perpetuate flawed assumptions without adequate human oversight.

4. AI Fluency as a Hiring Requirement

Job postings requiring AI skills in cybersecurity surged from 14.2% to 28.5% among G7 countries in just a year, according to an analysis by the AI Workforce Consortium. Yet, simply being technically proficient is no longer sufficient. Companies are increasingly assessing candidates' attitudes towards AI, eager to avoid hiring those skeptical about its potential.

Although the demand for AI-driven talent is rising, Autrey warns that many firms misidentify their primary needs. Reckoning with fundamental cybersecurity controls, such as asset management and data security, should take precedence over solely fortifying AI capabilities. He emphasizes that AI did not introduce a new operational framework but revealed existing deficiencies in previous implementations.

With certifications overshadowing degrees as prime indicators of expertise, the challenge remains for organizations to accurately gauge ongoing competencies, as skills can quickly become outdated and require continuous validation.

5. Talent Pipeline Risks in Cybersecurity

The growth of intelligent automation in cybersecurity has implications not only for roles but also for the development of talent. In the last six months leading to March 2026, senior cybersecurity roles surged by 65% while junior roles barely increased, according to the AI Workforce Consortium.

Autrey warns that the automation of entry-level functions without creating fillable roles could lead to a critical skills gap in the future. The increasing need for senior personnel may not align with the availability of candidates ready to fill those shoes.

The SANS/GIAC report corroborates this trend, revealing that the disparity between the skills required and those available within organizations widened significantly over the past year. Alarmingly, nearly 27% of security breaches now correlate with skills shortages on teams, highlighting the urgent need for effective training mechanisms and structured pathways for professional development that harness emerging AI tools.

Source: Michael Garcia · www.csoonline.com

Comments

Sign in to join the discussion.