While the artificial intelligence job apocalypse appears on hold for now, cybersecurity experts have underscored that security professionals who understand the technology and can grasp its potential and limits are in the best position to land jobs and move up the career ladder.
The big question, especially in an age of rapid developments and uncertainty over what comes next, is how cybersecurity professionals can reskill and develop skills amid increasing AI deployments.
A study published by the Cisco-founded AI Workforce Consortium, using data from Cornerstone and Indeed, seeks to answer this question and others about cybersecurity and AI skills. First, the report found that about 29 percent of cybersecurity job postings listed between October 2025 and March 2026 required some type of AI skills.
That’s an increase from 14 percent during the same period a year prior, the report noted.
A deeper look at the data also finds that traditional cybersecurity skills frameworks such as the National Institute of Standards and Technology Workforce Framework for Cybersecurity (NICE Framework) and the EU’s European Skills, Competences, Qualifications and Occupations (ESCO) are not designed for a time when workers can use autonomous AI agents to perform tasks while remaining responsible for the outcomes and risk.
“When the work is done with AI, people cross the boundaries of their roles. The person moves from directly performing the task to delegating it to an agent while remaining accountable for the outcome,” according to the AI Workforce Consortium report. “Workflows and teams organized around scarcity, such as hunting for a new vulnerability, become work organized around abundance, where triaging many findings is the constraint rather than producing one.”
Instead, the report suggests that cybersecurity and other tech professionals focus on what it calls a unified skills framework that adds to existing frameworks such as NICE but moves beyond a static set of skills to more fully encompass a changing skill set that evolves as AI and agentic AI technologies evolve and change workflows across organizations.
Cybersecurity experts noted that this approach can address issues that have come to the forefront with AI – as well as create fresh ways for cyber pros to keep up to date on the skills needed to remain valuable in the workforce.
“We’re already seeing a shift away from purely repetitive, entry-level cybersecurity tasks toward higher-context work involving threat modeling, event investigation, agentic governance, validation and operational decision-making,” said Diana Kelley, CISO at Noma Security. “The future security practitioner will increasingly need to understand how to work alongside AI systems, how to use AI to optimize their own work and how to recognize when those systems fail, hallucinate, or behave unpredictably.”
How Best Can Cyber Pros Develop AI Skills
The report proposes breaking cybersecurity skills down into five categories to help better address AI:
- Business Context
- Interpersonal
- Intrapersonal
- Technical Domain
- Lead AI Agents
Each of these five categories within the framework offers multiple ways cybersecurity professionals can improve their skill sets when it comes to managing AI.
Under the Technical Domain category, for instance, the document details three specific ways that cybersecurity professionals can improve how AI agents are used and ensure that use is secure and reduces risk. These are the key skills:
- Technical breadth. Including institutional and industry tacit knowledge. Learn how your organization and sector actually work.
- Foundational depth. Master the key principles and big ideas: identity, protocols, operating systems, data, cryptography and threat modeling.
- First-principles reasoning. Hold a model of the system strong enough to contest an answer you did not produce.
The report also notes that organizations that prize security should avoid “vibe coding” since it lacks solid cybersecurity and risk management. Instead: “A solid appreciation of software engineering principles – development lifecycle, version control, testing – lets a non-technical product manager build a prototype for idea socialization and validation.”
Randolph Barr, CISO at Cequence Security, noted that when employees delegate execution to an agent but stay accountable for the outcome, cybersecurity professionals are operating outside their old role boundaries. Although it previously took years to develop security skills, the rapid pace of AI technology demands a new approach that speeds up this process.
“On technical skills, the report argues depth matters more as AI takes over execution, not less, since you can't judge what an agent hands back if you don't understand the domain,” Barr told Dice. “I'd bring my own 30 years in IT and security into this: I've lived through plenty of ‘go learn the new thing’ transitions, from thicknet to structured cabling, Novell to Microsoft networking, server rooms to data centers to cloud, and every one of those gave us years to adapt. AI doesn't. GenAI hit in 2023, agentic tooling and the Model Context Protocol followed in 2024 and 2025, and we're already on frontier models like Mythos in 2026, finding vulnerabilities better than most humans can. The real skills gap isn't ‘AI is new.’ It’s that the adoption cycle has compressed from years to months, and it's still compressing.”
Barr added that when it comes to developing business skills, cybersecurity professionals need to take a bigger role in questioning business decisions about whether an organization should deploy AI tools, whether it’s possible to secure these technologies, and what risks are involved.
Interpersonal skills are also an important — and often overlooked — part of the cybersecurity skills question.
“What's left for the human is explaining a decision to an auditor, negotiating guardrails with a product team, telling an exec the fast AI answer is the wrong one. That's not a technical skill, and it's the hardest one to teach in a course,” Barr added.
Rethinking AI and Cybersecurity Skills
The AI Workforce Consortium report, along with other studies, shows that some of the biggest shifts in the industry involve how cybersecurity professionals are moving from being individual operators to managers of machine labor, said Aviv Nahum, co-founder and CEO of Above Security.
Previously, a strong analyst was measured by how well they could investigate an alert, write a detection or analyze an incident. Increasingly, that same security analyst is measured by how effectively they can define the objective, give the right context to a set of agents, evaluate the result and decide what should happen next.
“I don’t think the answer is to artificially preserve every manual skill that AI can perform better. We stopped expecting engineers to calculate everything by hand when calculators arrived. The same thing will happen in cybersecurity. If an agent can write a query, correlate telemetry or reconstruct an incident faster and better than a person, we should let it. The human value moves up a layer,” Nahum told Dice. “That makes technical depth more important, not less. You need enough understanding to know when an agent is wrong, what context it is missing and whether the result makes sense in the environment.”
At the same time, business and communication skills outlined in the report can also play a significant role for cybersecurity professionals.
“Security professionals will increasingly have to translate between agents, technical teams, and business stakeholders,” Nahum added. “In that sense, prompt engineering is probably the least interesting long-term skill. The durable skill is orchestration: breaking a complex objective into work that agents can execute, supplying the right context, and being accountable for the outcome.”
Noma Security’s Kelley also believes that cybersecurity professionals need to take a more rounded approach to AI development and security risk.
“Today, organizations need enterprise security teams that can ask the right questions and deploy the right controls to ensure that when AI shows up, it can be adopted quickly without introducing unnecessary risk,” Kelley added.