Friday, September 25, 2026
Ghost Signals

Transmissions from the information front.

Academic

AI Isn't Killing Cybersecurity Jobs — It's Rewriting the Entry Ticket

Why the cybersecurity ladder just got steeper, and what it takes to climb it now

Written by Dr. K. Merrill Perkins

April 19, 2026 · 9 min read · STEM Education

AI Isn't Killing Cybersecurity Jobs — It's Rewriting the Entry Ticket

There's a story you've probably heard a hundred times: the cybersecurity industry has millions of unfilled jobs, the pay is great, and anyone willing to put in the work can break into the field.

Most of that is still true. One part of it isn't.

The workforce gap is real — ISC2's 2024 research put it at 4.8 million unfilled positions globally, a figure that grew 19% year-over-year while the active workforce barely moved (ISC2, 2024). CyberSeek tracks roughly 514,000 open cybersecurity roles in the United States alone, with employers filling only about three out of every four positions they post (StationX, 2026).

Yet if you've tried to land your first cybersecurity job recently, the numbers feel like they're describing a different planet. Every entry-level posting demands three to five years of experience. Résumés disappear into black holes. Hiring managers explicitly say they want "senior-level thinking" from junior-level pay bands.

Both realities are true. The industry is desperate for talent, and the entry-level door is getting narrower. Understanding that paradox — and what it actually means for the next wave of cybersecurity professionals — is the most important conversation happening in this field right now.

Here's what's really going on.


The talent shortage isn't going away. It's changing shape.

Image 2 - Article 1.png

Walk into any SOC, SecOps team, or compliance shop in 2026 and you'll hear some version of the same sentence:

"We don't need more bodies. We need better ones."

That shift matters. For a decade, the cybersecurity talent gap was described as a pure headcount problem — too few people, too many empty chairs. In the 2024 ISC2 Workforce Study, for the first time on record, lack of qualified talent was displaced by budget as the number-one cause of staffing shortages (ISC2, 2024). Ninety percent of cybersecurity teams report skills gaps that matter more to them than open headcount (ISC2, 2024).

Translation: organizations aren't short on résumés. They're short on people who can actually do the work the moment they sit down.

AI is accelerating that shift.


Why entry-level is getting squeezed

Image 3 - Article 1.png

This is the most immediate, most misunderstood impact of AI on the cybersecurity workforce.

For years, the path into the industry ran through a predictable set of jobs: Tier 1 SOC analyst, junior IT support, help desk, log reviewer, alert triage. These roles were the apprenticeship. You cut your teeth watching a SIEM dashboard, learning what "normal" looked like on a network, and slowly graduating to more complex work.

AI is now doing significant portions of that work:

  • Log analysis and correlation

  • Alert triage and initial classification

  • Routine incident response playbooks

  • First-pass threat hunting

Organizations respond to that in one of two ways — and both of them compress the bottom of the hiring funnel. They hire fewer juniors and ask the remaining ones to operate at what used to be mid-level. Or they skip the junior tier entirely and look for people who can supervise AI output on day one.

Data from ISC2 and industry research now points to something uncomfortable: entry-level is the most competitive tier of the cybersecurity job market, not the least. Some estimates suggest a modest worker surplus for roles requiring zero-to-two years of experience, even as the overall field carries millions of unfilled positions (EntryToCyber, 2026). Job seekers routinely report applying to 300-plus postings before landing a first role.

The ladder into cybersecurity didn't disappear. It got steeper.


The compression effect: one analyst plus AI equals what used to take a team

Think of AI in the SOC as a force multiplier, not a replacement.

One analyst paired with modern automation can now handle a queue that used to require three or four people. SOC automation platforms have made it possible for AI-assisted workflows to absorb a substantial share of repetitive Tier 1 work — across vendor and analyst reporting, the directional trend is consistent even if specific percentages vary by environment. That's extraordinary for organizations trying to keep up with rising threat volume. It's also the reason team sizes are shrinking while expectations rise.

Net effect: total cybersecurity jobs don't collapse. But the shape of a cybersecurity team changes. Fewer people. Higher skill floor. More leverage per person. More judgment required per decision.


The pipeline problem nobody's talking about

Image 5 - Article 1.png

Here's the part most workforce analyses miss.

If entry-level hiring shrinks today, the mid-level pipeline shrinks in five years. You can't have senior architects without mid-level engineers. You can't have mid-level engineers without juniors who got real reps under their belt. The traditional cybersecurity career pipeline was built on apprenticeship — and AI is eroding the apprenticeship tier faster than the industry is replacing it.

Paradoxically, AI may worsen the long-term talent gap rather than fix it. We're optimizing for short-term productivity at the cost of long-term capacity. The organizations that will win the next decade of cybersecurity hiring aren't the ones buying the most AI tools. They're the ones figuring out how to develop junior talent in an environment where the on-ramp just got narrower.

That's not just a corporate problem. It's a national security problem. The Bureau of Labor Statistics projects 29% employment growth for information security analysts between 2024 and 2034 — making it one of the fastest-growing occupations in the U.S. economy (U.S. Bureau of Labor Statistics, 2025). That growth isn't happening without a new model for how people enter the field.


Where the work is moving: judgment, not execution

As AI handles the repetitive layer, the human work shifts upward. The job is no longer "review the alert." It's:

  • Interpret AI output and know when to override it

  • Make risk-based decisions under time pressure

  • Design and defend security architectures

  • Hunt advanced threats that don't trip automated detections

  • Translate technical risk into business language for boards and executives

Less execution. More judgment, reasoning, and strategy. That shift is driving salaries upward at the top end — median wages for information security analysts now sit well into six figures, and the broader computer and IT occupations category carried a median annual wage of $105,990 as of May 2024 (U.S. Bureau of Labor Statistics, 2025). Top specializations in cloud security, AI security, and application security command significantly more.

It's also driving a demand for hybrid skill sets. The most valuable cybersecurity professionals today aren't pure defenders — they're people who combine security fundamentals with cloud engineering, software development, data analysis, and increasingly, AI literacy.


And then there's the adversary

One thing the "AI will take cybersecurity jobs" crowd consistently misses: attackers are using AI too.

AI-generated phishing is now indistinguishable from legitimate email in many cases. Deepfake voice attacks targeting executives are a standard tactic. Exploitation timelines that used to take hours are dropping to seconds. Attack volume is scaling in ways that no human-only defense team can match.

Every capability AI gives defenders, it also gives attackers. The arms race doesn't reduce the need for cybersecurity professionals — it raises the stakes of every defensive role. AI is increasing demand for skilled cyber defenders, not decreasing it. The people who win in this environment are the ones who can direct AI, not just operate alongside it.


The new model: human + AI teams

Image 4 - Article 1.png

The cybersecurity workforce isn't moving toward automation replacing humans. It's moving toward what security leaders now call co-teaming.

AI handles speed, scale, and repetition. Humans handle judgment, creativity, and decisions that carry real consequences. The professionals who thrive in this model share a common profile:

  • They treat AI as a capable but fallible teammate, not a magic box

  • They have deep fundamentals in networking, systems, and security architecture

  • They've practiced under realistic conditions, not just read about them

  • They can communicate risk clearly to technical and non-technical audiences

  • They keep learning, because the tools will keep changing

That profile doesn't come from a weekend bootcamp. It also doesn't require a four-year degree and three internships. It requires a deliberate, structured path that builds real skills in the areas employers actually hire for.


What this means if you're trying to enter the field right now

Image 6 - Article 1.png

If you're reading this and you're thinking about a cybersecurity career — whether you're a student, a career changer, a veteran transitioning out of service, or an IT professional looking to move up — the honest takeaway is this:

A certification profile alone will not save you.

Certs are table stakes. They get your résumé read. They don't get you hired. What gets you hired — and what gets you kept — is the ability to sit down at a workstation on day one and actually do the work. Academic credentials without demonstrable competence are worthless in this field, and hiring managers can smell the difference from across a conference table.

Specifically, employers in 2026 are looking for candidates who can:

  1. Demonstrate the fundamentals, not just recite them. Hardware, operating systems, networking, and basic scripting are the floor. You should be able to build, break, and rebuild a system under your own power — not describe the process from a textbook.

  2. Show a certification profile that maps to real skill areas. Foundational IT, networking, security, systems administration, and cloud — each carries a recognized credential track, and employers scan for them specifically. But a cert is a marker that a skill was validated at a point in time. It's not a guarantee the skill still lives in your hands.

  3. Walk a hiring manager through their troubleshooting methodology out loud. This is the single biggest differentiator in a technical interview, and the one most candidates fail. Anyone can memorize answers to a multiple-choice exam. Very few can sit across from someone and explain, step by step, how they'd actually approach a problem — what they'd check first, what they'd rule out, why. If you can't narrate your own thinking, you can't lead a response under pressure.

  4. Put real hands-on reps behind every claim on the résumé. Virtual labs where you've stood up environments, broken things on purpose, hunted for the cause, and documented what you found. Home labs. Capture-the-flag challenges. Volunteer work. Something beyond "I finished the course."

  5. Translate technical findings into business impact. Cybersecurity is a business discipline. People who can tell an executive what a finding actually means — and what to do about it — are rare and valuable.

The people who get hired in this market aren't the ones with the longest cert alphabet soup on LinkedIn. They're the ones who can walk into a room and say, "Here's what I've built, here's what I broke, here's what I'd do if this happened tomorrow" — and back every sentence up with clear reasoning, not buzzwords.


The strategic takeaway

AI is doing three things to the cybersecurity workforce at once:

  1. Reducing demand for low-skill, repetitive labor

  2. Increasing demand for high-judgment, high-skill labor

  3. Breaking the traditional talent pipeline between the two

That combination is why the industry feels contradictory. "We can't find talent" and "we're not hiring juniors" are both true statements. They're describing the same structural shift from two different angles.

The cybersecurity profession is becoming a high-skill, high-barrier field. That's not a reason to stay out. It's a reason to enter with a real plan — one that treats your early career as a deliberate skills-building project rather than an attempt to check boxes on a generic checklist.

The door is still open. It just swings differently now.


About the Author

Dr. K. Merrill Perkins is a U.S. Navy veteran, cybersecurity professor, and founder of the Morse Group Institute of Technology (MGIT), an online academy preparing the next generation of IT and cybersecurity professionals. MGIT's Nano-Degree program stacks nine globally recognized CompTIA certifications — A+, Network+, Security+, Linux+, Cloud+, and beyond — with hands-on virtual labs, real-world scenarios, and direct instructor support, taking students from beginner to job-ready in just over a year. Learn more at mgit.io.


References

EntryToCyber. (2026, February 14). Entry-level cybersecurity jobs: Complete 2026 guide. https://entrytocyber.com/article-entry-level-cybersecurity-jobs.html

ISC2. (2024, October 31). Results of the 2024 ISC2 cybersecurity workforce study. https://www.isc2.org/Insights/2024/10/ISC2-2024-Cybersecurity-Workforce-Study

ISC2. (2025, December). 2025 ISC2 cybersecurity workforce study. https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-Study

StationX. (2026). Cybersecurity job market statistics and trends [2026]. https://app.stationx.net/articles/cybersecurity-job-market-statistics

U.S. Bureau of Labor Statistics. (2025). Occupational outlook handbook: Information security analysts. https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm

ShareEmail

More from Academic

All Academic →

More essays are on the way.