How AI Is Reshaping Cybersecurity Careers — Not Replacing Them

Transcription

AI is changing cybersecurity jobs, and here's what you need to know. Joining me now is cybersecurity expert Kim Underhill. Kim, thanks for being with us today. Thanks for having me, Caleb. So, how is AI actually changing the jobs on a day-to-day basis? So, um we're seeing some organizations using AI agents to automate ticket writing and updating tickets automatically. I think around 70% faster. AI can do it faster than humans. Um we're seeing it being able to respond to more of the what we call the L1 or level one SOC analyst um types of things as far as the ticketing.

So, it's able to triage incidents a lot faster than a human. Um there's also the caveat there. We always still want to have the human in the loop so we can ensure that the AI is actually doing what it's supposed to be doing. Who's benefiting more right now from AI, the attackers or the defenders? And why? Um I I would say both. Skilled attackers are able to leverage AI to do um more advanced attacks or different types of attacks. Um it's allowing attacks to speed up.

It's allowing an attacker to exploit vulnerabilities faster once they're made public. Um but on the flip side of that, there are some threat actors out there that are doing things like live coding, and they're not using secure software development practices as part of that. So, they're exposing their infrastructure. I think right now both sides are benefiting from AI. Um again, traditionally the attackers just have a little bit of an edge just because, like I said, they only have to be right that one time.

So, realistically, what can AI handle on its own versus where we still need to have human interaction? Yeah, I think a lot of the the mundane tasks that all of us hate doing, for example, like um with GRC compliance, so like an audit. Um I think where we need the human element is still to check the AI, make sure it's actually doing what it's supposed to be doing, and at the same time, the AI is freeing us up to do some some of the more advanced things we want to do, like threat hunting or, you know, deeper threat intelligence.

Whereas, like I mentioned, we might be stuck doing a bunch of ticket writing. >> Because of AI, what things do people need to focus on if they want to grow in the field of cybersecurity? So, my recommendation is you focus on the fundamentals. So, learn basic networking, learn how data flows across the network and across systems for an organization. I still think a lot of people should start in the IT help desk cuz you get to see how an enterprise actually functions.

Plus, you get the benefit a lot of times they'll pay for your training. But the key takeaway is is focus on the fundamentals. Those don't change. >> We break down the threats that you need to know every week in the cybersecurity insider newsletter. I have the link in the description if you want to stay ahead of it.

This transcript was generated automatically from the video's captions and may contain errors.

AI is shifting cybersecurity roles from manual tasks to decision-making and analysis.

Written By
Ken Underhill
Ken Underhill
Published: Apr 10, 2026
Updated: Apr 27, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Artificial intelligence (AI) is rapidly transforming cybersecurity roles, but not in the way many expected. 

Rather than just eliminating jobs, AI is redefining how cybersecurity professionals work, shifting the focus from manual task execution to higher-level decision-making and analysis. 

The work of security professionals “becomes less about processing and more about applying strong judgment, logic, and reasoning,” said Maruf Ahmed, CEO of Dexian in an email to eSecurityPlanet.

How AI Is Changing Day-to-Day Cybersecurity Work

This evolution is creating both new opportunities and new challenges for organizations and professionals alike.

Contrary to concerns about job displacement, AI is increasingly embedded in day-to-day cybersecurity workflows, particularly within security operations centers (SOCs). 

AI-driven agents now handle tasks such as alert triage, ticket generation, and initial incident investigation — functions that were traditionally performed by L1 SOC analysts. 

In many cases, these tools can process and respond to incidents significantly faster than humans, accelerating workflows and reducing manual effort. 

It also frees up L1 analysts to upskill for threat hunting and deeper threat intelligence tasks.

Where AI Falls Short: The Need for Human Judgment

However, this shift does not eliminate the need for human expertise. Instead, it changes where that expertise is applied.

As AI takes over repetitive and time-consuming tasks, cybersecurity professionals are increasingly responsible for evaluating AI-generated outputs. 

This includes assessing the accuracy of alerts, determining business impact, and making informed risk decisions. 

The work is becoming less about processing large volumes of data and more about applying judgment, reasoning, and contextual understanding. 

Advertisement

While AI reduces the burden of initial analysis, it simultaneously increases the number and complexity of decisions that must be made on the back end.

How AI Is Impacting Pen Testing and GRC

This transformation is evident in areas such as penetration testing and governance, risk, and compliance (GRC). 

In penetration testing, AI can rapidly identify potential vulnerabilities and map attack paths. 

However, it often lacks the contextual awareness needed to understand how those vulnerabilities behave and impact a specific environment. 

As a result, security professionals may spend less time discovering issues and more time validating, prioritizing, and chaining them into meaningful attack scenarios. 

Similarly, in GRC, AI can assist with control mapping and identifying compliance gaps across frameworks, but it cannot effectively communicate risk to business stakeholders or translate technical findings into organizational impact.

Rethinking Cybersecurity Talent and Job Requirements

The growing reliance on AI is also exposing a critical gap in how organizations approach hiring. 

Many job descriptions still reflect outdated expectations, emphasizing task-based responsibilities that AI agents can perform. 

As a result, organizations often struggle to find candidates who match these legacy roles. 

The issue is not necessarily a shortage of talent, but rather a mismatch between hiring criteria and the current demands of the role. 

Modern cybersecurity positions increasingly require professionals who can interpret AI outputs, apply domain-specific context, and make informed decisions — not just execute predefined tasks.

Addressing this gap requires organizations to rethink their talent strategies. Job descriptions and hiring requirements must evolve to reflect the changing nature of cybersecurity work. 

This may involve prioritizing skills such as critical thinking, communication, and business acumen alongside technical expertise. 

Advertisement

In some cases, domain-specific knowledge — such as understanding clinical environments in healthcare — can be essential for accurately assessing risk and impact.

Why Fundamentals Still Matter in an AI-Driven World

For individuals pursuing careers in cybersecurity, the rise of AI underscores the importance of foundational knowledge. 

Core concepts such as networking, operating systems, data protection, and how data flows across systems remain critical, as they form the basis for understanding more advanced technologies. 

While AI tools can enhance productivity and automate workflows, they are built on these underlying concepts. 

Professionals who develop a strong foundation are better positioned to adapt as new technologies emerge and integrate AI effectively into their workflows.

How Cybersecurity Professionals Should Work With AI

At the same time, cybersecurity professionals must learn how to work alongside AI. 

This includes understanding where AI can add value, how to integrate it into existing processes, and how to validate its outputs. 

Rather than focusing solely on using AI tools, professionals should consider how AI can enhance specific tasks within their role and workflow, from incident response to threat intelligence.

Ultimately, the impact of AI on cybersecurity careers is less about replacement and more about evolution. 

Organizations that recognize this shift and align their hiring, training, and technology strategies accordingly will be better equipped to build effective security teams. 

Those that continue to rely on outdated role definitions risk falling behind, both in talent acquisition and in their ability to respond to modern threats.

As AI continues to mature, cybersecurity roles will continue to evolve, placing greater emphasis on human judgment, adaptability, and strategic thinking in an increasingly automated landscape.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.