The entry-level cybersecurity job isn’t disappearing. It’s becoming something very different.
As generative AI (GenAI) takes over more of the repetitive work that once served as a proving ground for junior analysts, employers are increasingly raising expectations for candidates entering the field.
Rather than spending their first year triaging alerts or reviewing logs, new hires are now expected to understand cloud environments, evaluate AI-generated outputs, write code and contribute to security operations almost immediately.
The result is a growing disconnect between what employers expect and how cybersecurity talent has traditionally been developed.
“We’re seeing a clear move toward more senior hiring in cybersecurity,” says Diana Kelley, chief information security officer at Noma Security. “AI is accelerating the shift. However, it’s not the only driver.”
She explains that budget pressure and a growing expectation that candidates arrive job-ready are pushing employers to hire fewer, more experienced practitioners.
AI Changing Entry Points
For years, entry-level cybersecurity roles gave new practitioners an opportunity to learn through repetition. Analysts reviewed security alerts, investigated suspicious activity, and gradually developed the judgment needed for more complex work — those tasks are increasingly being automated.
“AI is raising the floor for what entry-level cybersecurity means,” Kelley says. “Repetitive work that once helped people break in, like basic alert triage, log review, and first-pass analysis, is increasingly being automated or absorbed into platforms.”
That means junior candidates need to show more hands-on capability earlier: cloud and identity basics, AI fluency, strong judgment and the ability to validate automated outputs instead of simply trusting them.
Dave Gerry, chief executive officer at Bugcrowd, says he sees the same trend on the offensive security side.
“AI is squeezing the lower end of the skills curve,” he says. “A lot of the work that used to be a natural entry point for junior analysts, scanning logs, triaging alerts, running routine pen test scripts, can now be augmented or automated.”
Gerry adds organizations look at that and determine they don’t need three junior people but rather one senior person who can direct the AI and make the judgment calls it can’t.
That doesn’t mean AI is eliminating cybersecurity jobs. Instead, it’s compressing the learning curve by expecting new hires to perform work that previously required several years of experience.
Experience Starts Before the First Job
The biggest challenge for graduates and career changers is no longer finding educational resources. It’s demonstrating practical experience before getting hired.
Anthony Pillitiere, co-founder of Horizon3.ai, argues that AI has dramatically lowered the barriers to building those skills independently.
“The best way to break into cybersecurity today is to create your own experience,” he says. “With GenAI, open-source tools and free cloud resources, motivated candidates can build real skills long before they’re hired.”
Home labs, cloud environments, capture-the-flag competitions, GitHub projects and AI-assisted experimentation increasingly provide candidates with opportunities to demonstrate practical ability that extends beyond certifications.
AI can also accelerate learning itself, with the potential to make junior practitioners better, not just faster.
“When used well, it removes busywork and helps people learn while solving real problems instead of piecing together knowledge from dozens of disconnected resources,” Pillitiere says.
Employers aren’t simply looking for candidates who know how to prompt an AI assistant — they want people who can use AI to improve their own understanding while recognizing when automated recommendations are incomplete or incorrect.
Fundamentals Still Matter
With AI changing security operations, foundational technical knowledge has become even more valuable.
Shane Barney, CISO at Keeper Security, says understanding AI is now becoming a baseline expectation across nearly every IT discipline.
“Whether you want to work in cybersecurity, infrastructure or application development, understanding the basic operating principles of AI is essential,” Barney says.
From his perspective, future leaders of IT must be able to evaluate both the risks and opportunities of AI, including how adversaries weaponize it and how defenders can leverage it for real-time threat detection.
Barney cautions that does not reduce the importance of core technical skills.
“The cloud has redefined IT, and in this environment, infrastructure is code – and security is code too,” he says.
“Building a strong understanding of the basics of coding and application development will prepare you for a career where automation, secure development practices and identity-first security are the standard.”
Equally important is understanding business risk, something Barney says is developed through real-world experience rather than classroom instruction alone.
Petri Kuivala, CISO advisor at Hoxhunt, offers similar advice regarding certifications. They remain valuable, but only as part of a broader learning strategy.
“Certifications are useful, but they are time consuming and can be expensive and they don’t magically get you a job,” Kuivala says. “What they can do is help you get in the door and prepare you to succeed in an interview if you can show some fundamental skills and demonstrate how you think and solve problems.”
He encourages candidates to use AI as a learning companion rather than simply memorizing material.
“The candidates who stand out are the ones who go beyond the certification itself,” Kuivala says. “They discuss ideas with peers, use AI to explore topics more deeply, and can explain how they would apply what they’ve learned in a real situation.”
Industry Still Needs Junior Talent
While employers are demanding more from entry-level candidates, several security leaders caution against eliminating the pathways that produce future senior practitioners.
Kelley warns that organizations risk confusing entry-level hiring with experienced hiring.
“New professionals still need room to learn,” she says. “Cybersecurity has always built senior talent through real-world experience, mentoring, labs, adjacent IT roles, and on-the-job development. If we narrow those pathways too much, we won’t solve the talent gap. We’ll turn it into a talent chasm.”
Gerry makes a similar argument, particularly for offensive security, noting the most effective offensive security talent didn’t come out of a corporate training program.
“It came from people who started tinkering early, who had a place to build skills and develop the creative instincts that no AI system can replicate,” he says.
He cautions reducing opportunities for junior practitioners could have long-term consequences for the industry.
“You cannot automate your way to a safer internet,” Gerry says. “The creativity, the intuition, the adversarial thinking that makes a great security researcher, that’s still fundamentally human. If we don’t invest in developing the next generation of those humans, we will feel it very soon.”
Pillitiere says “Organizations should be asking not only whether the work is getting done, but whether their people are learning and improving.”
“The biggest risk isn’t AI replacing entry-level talent,” he says. “It’s people becoming dependent on it.”