Will AI take your security job?
Are you worried that AI will take your security job? You are not alone. AI now threatens a lot of IT jobs, and security is not an exception. Anthropic's own labour market research found computer programmers are the most exposed occupation, and saw a 14% drop in the rate at which 22 to 25 year olds found jobs in the most exposed fields (Anthropic, 2026). In September 2025 Anthropic disrupted a state-sponsored espionage campaign in which AI did 80 to 90% of the hacking work, with humans stepping in only at a handful of decision points (Anthropic, 2025). Its models already place in the top 3% of large CTF competitions (Anthropic, 2025) and have found over 500 vulnerabilities in open-source code that humans missed for years (Anthropic, 2026).
It is true that AI already beats most people at CTFs, does real pentest work, and will only get better. But what does it mean for you? Should you stop studying and requalify? I will say no.
It is true that it is now harder to land your first job as a junior. But the steps below will help you get in, or stay on top if you are already there. And I am not the only one who thinks so. In ISC2's 2025 study of over 16,000 security professionals, 73% said AI will create more specialised security skills (ISC2 via Network World), even though 52% in its AI pulse survey expect fewer entry-level roles (ISC2, 2025). Both are true at the same time. Fewer of the old junior tasks, more demand for people who understand AI, business and people. That second group is who you want to be.
So here are the steps to help you land your first job, or stay on top of it, in the age of AI in security.
Part 1. Soft skills
Learn to speak security in plain language
The age of the nerdy security guy is coming to an end. Your employer expects you to be a good communicator. As security people we had a privilege: we were the technical ones who never had to explain ourselves in non-technical language. That is gone. With AI, anyone can now translate your jargon in seconds. So what is left for you is how well you explain it.
Practise until you are a master of articulation. It only comes with practice. Join Toastmasters or a local conversation club. Speak slowly. Record yourself, listen back, and do it again until it sounds right. That is your first impression at work, at an interview, and at a conference.
Bring solutions, not problems
Non-technical colleagues and bosses do not like problems. They like solutions. "The server is vulnerable" is a problem. "The server is vulnerable, here is the fix, it takes two hours and we can do it on Sunday" is a solution. Show that mindset in interviews. Think like an engineer.
Speak the language of risk
Low, medium, high, critical. Learn to rate a vulnerability by how likely it is to be used and how much damage it would do to this particular business. Colleagues and enterprise people love that language, because it helps them decide what to spend money on first.
Have a can-do attitude
"Can-do attitude" was a buzzword in job adverts for years: roll up your sleeves and just do it. With AI it is even more important. You can now find answers and working solutions faster than ever, so the only thing stopping you is your own lack of competence or interest. Employers can tell. Show it with projects you built, or with real examples from past work.
Stay positive
Never criticise a past employer in an interview. Do not wash your dirty laundry in public. It tells the interviewer how you will talk about them one day.
My rule. Explain one security issue a week to someone who does not work in tech. A parent, a friend, your barber. If they understand it and care, you have done it right.
Part 2. Technical skills
Get the AI jargon right
There is a lot of confusing language in the AI hype. Many employers now expect you to be comfortable with AI. That can be unrealistic and unfair on their side, but it is the reality. At least know the difference between these:
- LLM. The model itself. It takes text in and predicts text out.
- Agent. An LLM running in a loop with tools, so it can take actions towards a goal instead of only answering.
- Harness. The software around the model that runs that loop: it gives the model its tools, memory, permissions and rules.
- Skill. A packaged set of instructions and files an agent can load for a specific job.
- API vs MCP. An API is how one program calls another. MCP (Model Context Protocol) is an open standard for connecting AI applications to tools and data, so an agent can use them safely and consistently.
Actually use AI
Many AI providers have free tiers or very cheap models. Use them. Understand how AI works, how it can be attacked and how it can be secured. Learn the problems with vibe coding: code that works but nobody really reviewed.
New models come out almost every month now, and new tools and agents with them. Be the first to try them on real security tasks and share what you found, good and bad. That is a genuinely useful contribution, and people remember it.
Know AI security inside out
If you work in security, you are now expected to know AI security well enough. Study the OWASP Top 10 for LLM and GenAI applications and MITRE ATLAS, the map of real attacks against AI systems. This is also where a lot of new work is.
Build a GitHub profile
With vibe coding, everyone can code now. Use that to bootstrap your GitHub profile. Build useful security tools or plugins (helpful ones, never harmful), write tutorials and write-ups of what you learned. Make a positive contribution. If you do not know where to start, look at AI security. There is plenty to do there.
But if you vibe code, do it securely. Scan your own projects and make sure there are no silly vulnerabilities. A security candidate with a leaked API key on GitHub is not a great look.
Certifications
They are relevant and important, and good to have on your CV. But they do not guarantee a job. A cool personal project or tool is often worth more, because it proves you can actually do the work.
Part 3. Go where the mess is
AI will make technical debt sky-rocket
Technical debt is software that works and delivers, but is badly out of date, and only a few people, or nobody at all, know how to patch or maintain it. Every company has some. With AI writing code faster than anyone can review it, many companies will soon have a lot more.
This is where I strongly believe security people will be needed: to help clean up the mess, or at least secure it. And there will be a lot of mess.
Move closer to engineering
If you are in an analyst role, I would recommend moving towards security engineering or DevSecOps, where you can actually make the change yourself. AI is likely to automate big parts of SOC operations. It is not there yet with the engineering work: fixing, hardening and rebuilding real systems inside real organisations.
Ask what problem it solves
If you are new to IT and security, you will meet internal applications with funny names and technologies nobody explains. Ask your colleagues one simple question: what problem does this solve? What is the purpose of this microservice, this middleware, this backend API, this proprietary software? That one question will help you understand what a piece of tech really is, and how to secure it. If nobody knows the answer, ask AI to help you work it out.
Why this matters
This is where I believe security engineers will make a real, positive impact. After so much AI-generated mess, even with the safest and most secure models, organisations will become more vulnerable than before. Script kiddies armed with AI, and state actors, will not hesitate to attack and exploit it. It is already happening: the espionage campaign Anthropic disrupted was run mostly by AI (Anthropic, 2025). Someone has to fix the foundations. That someone can be you.
Part 4. Get known
Go to conferences and meetups
There are dozens of security conferences and meetups in big cities and even smaller ones. Go as often as you can, so people start recognising you. The security world is very small, and people will notice you sooner than you think.
I am not saying go and beg people to hire you. Just wander around, make friends, ask people what they are working on, show curiosity. Good places to start, often free or cheap:
- OWASP chapter meetings. Free, regular, in most big cities.
- BSides. Community-run security conferences all over the world, free or very cheap.
- DEF CON Groups. Local monthly meetups.
- ISC2 and ISACA chapter events. Great for meeting people from the corporate side.
Dress well and always be professional. First impressions matter.
Keep social media professional
Do not use LinkedIn for emotional announcements, or posts about a company that did not hire you. LinkedIn is not Facebook or TikTok, and professionals notice. If you have a genuine contribution to share, a tool, a write-up, a talk, then go for it.
Part 5. Business skills
Understand how the company makes money
This is the one I want to stress most. It is now expected that a security person, even a junior one, understands the business. How does the company make money? Who are its customers? What would hurt it most?
If you get how your employer makes its money, you will be a better security person in that company. I guarantee it. It also puts you ahead of the many candidates swimming in technical jargon. Do not just be the Nmap or Burp Suite person. Be the businessman or businesswoman of the company. Feel its culture and dynamics. That is hard without experience, so do your research and watch a few videos about how companies in that industry work.
Expect to produce more
With AI, everyone will be expected to produce more, and higher quality, work. Prepare yourself for that. Even if it gets uncomfortable, it is coming.
Part 6. Landing the job
Write your own CV
AI is great at helping with a CV, but terrible at writing one. I cannot stress this enough. Everyone recognises AI writing, especially HR. A CV that reads as AI-written is a red flag. Write it yourself, then ask AI to correct mistakes while keeping your style.
If English is not your first language and you are applying to English-speaking countries, the same applies. Your own voice with a few corrected mistakes beats a polished text that sounds like everyone else's.
Use the STAR method
When you are asked about past experience, always answer with STAR: Situation, Task, Action, Result. Always. I will not go into it here, just look it up and practise a few stories.
Ask good questions at the end
Interviewers usually ask if you have any questions. Always ask. But do not ask boring standard questions, and do not mention salary. Ask what the team is working on, how they are adopting AI, what their AI and security strategy looks like.
Before the interview, use AI to do proper deep research on the company. Maybe you will not like what they do. Maybe they are involved in something unethical. Research helps you ask the right questions. Are you profitable? If not, how do you plan to stay afloat? Why were there redundancies a few months ago?
Handle rejection well
If you get rejected, ask for feedback. It shows you exactly where to improve. Otherwise accept it and move on.
Apply widely, and apply a lot
Do not apply only to security jobs. General IT, helpdesk, even reception or printer maintenance. Any entry-level job in IT is good for you, even if it is not directly security. In the long term it might even be better, because you learn how a real organisation runs.
Look at start-ups too. They might pay less, or offer shares instead. It does not matter. In the early days, any experience is good experience.
Ten years ago people applied to hundreds of jobs. It can be even harder now. So keep your chin up, stay positive, and keep applying anyway. You will get there.
Beware of fake recruiters
There have been many cases of fake job adverts and fake recruiters used to win professionals' trust, steal their secrets or infect their laptops. The UK's NPSA warns that foreign intelligence services use professional networking sites and job platforms this way (NPSA). North Korea's long-running "Operation Dream Job" sends convincing fake job offers with malware hidden in the "job description" (ESET). Always research a company before you send them your passport or personal details, and never run files a "recruiter" sends you.
Practise on CyberLearner
Here on CyberLearner there are labs that build exactly these skills, and give you real stories to tell in interviews:
- DF-01: WAFShield. Defend a web app with your own firewall rules while real attack tools run against it, without blocking real users. Great for blue team interviews.
- GL-04: Market Blackout. Rogue AI agents at a stock exchange. Investigate in an EDR console, preserve evidence, contain it without crashing the business.
- OP-01: Line Down. Lead the response to a cyberattack on a carmaker. Budget, stakeholders, the press. Pure business and risk skills.
- AI-01: ClockBot and AI-02: TrustFall. Hands-on AI security basics: how chatbots and AI tools get abused, and why guardrails alone are not enough.
So those are the steps to help you land your first job, or stay on top of it, in the age of AI in security. None of them is magic. Communicate well, understand AI and the business, get known for good work, and keep going. AI will change the job. It will not replace people who keep learning.
Sources
- Anthropic: Labor market impacts of AI, March 2026
- Anthropic: Disrupting an AI-orchestrated cyber espionage campaign, November 2025
- Anthropic: Claude does cyber competitions, August 2025
- Anthropic: Making frontier cybersecurity capabilities available to defenders, February 2026
- Network World on the 2025 ISC2 Cybersecurity Workforce Study
- ISC2: 2025 AI Adoption Pulse Survey
- OWASP GenAI Security Project: Top 10 for LLM applications
- MITRE ATLAS
- NPSA: Applicant beware, who is recruiting you?
- ESET: Lazarus and Operation Dream Job
CyberLearner.org is a free cybersecurity training platform, built on the curriculum of the International Cybersecurity Olympiad (ICO). Every lab is hands-on and runs in your browser. It is open to everyone, regardless of skill level.