THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


Ben Schoenecker is a highly skilled Director of Information Security at Hendrick Automotive Group, based in Charlotte, North Carolina. With over 15 years of experience in the field, Ben is a certified CISSP, CISM, and CCSP, and is recognized as a top voice in information security. He has been instrumental in securing enterprise environments, leading IT security teams, and driving the development and maturation of security programs within the nation’s largest privately held automotive group.
Through this article, Schoenecker highlights the potential impact of Artificial Intelligence (AI) on the cybersecurity job market. He compares AI to the Industrial Revolution, suggesting that it could revolutionize the way cybersecurity work is done.
One of my favorite analogies for the Artificial Intelligence movement is the Industrial Revolution. It brought us factories, machines, and mass production. It completely revolutionized society because it augmented our physical and logistical capabilities. For example, before bulldozers existed, it required great human effort to move a large mound of earth. Artificial Intelligence is similar in that it is augmenting the human mind. It’s evolving things in a way in which humans will require less cognitive effort than before. And it’s for this very reason that we wonder if it could make a difference in the cybersecurity jobs gap.
“The AI software market is exploding right now, and if a software product isn’t leveraging AI in some capacity, or if it isn’t on the roadmap, then it’s already behind the curve.”
First let’s talk about the cybersecurity job market. There is a growing feeling within the cybersecurity industry that the jobs gap may not really exist as most imagine it. People with this sentiment point to the many “ghost” jobs that are often posted on the internet and end up contributing to the unfilled jobs statistics. In a recent August 2024 article in Fortune magazine by Emma Burleigh, it was revealed that 8 out of 10 recruiters had admitted to posting fake jobs, while 25% of them said over half the jobs they posted were fake. According to a January 2024 article by Ernestas Naprys at Cybernews, it's now believed that half of cybersecurity jobs might not be real. There are no real concrete laws about ghost jobs, but it’s certainly a headache for candidates. We know there is a jobs gap, and it’s probably sizeable, but the numbers are fuzzy. Despite these issues, we know many jobs go unfilled every year and it’s hard for companies to find qualified candidates. We have a flood of newly graduating students majoring in cybersecurity who have difficulty finding jobs. On the other hand, we have tens of thousands of unfilled cybersecurity roles that need highly experienced and specialized workers. But I digress. How does AI play a role in all this? My hot take: It's probably not great news for entry-level cybersecurity candidates, but let’s discuss why.
The AI software market is exploding right now, and if a software product isn’t leveraging AI in some capacity, or if it isn’t on the roadmap, then it’s already behind the curve. Software companies are leveraging the power of AI to help customers save time and effort in a myriad of ways. But how does AI within software products apply to cybersecurity?
Here are some example areas of AI assistance at a product level:
● Anomaly and Zero-day detection
● Insider threat and UEBA (user and entity behavior analytics)
● Vulnerability predictive analytics
● Correlation of event logs
● Phishing analysis
● Malware analysis and reverse engineering
● Threat intelligence analysis
● Automated reporting
● Secure coding assistance
● And many, many more….
At a very basic level, these products are requiring less and less human effort and helping to automate tasks that once required human minds with skillsets. Leveraging AI within software products adds significant value and will continue to add efficiency to security teams, but it’s not the end of the story. After attending the CISO Summit at @BlackhatUSA2024 and listening to a fantastic talk by @Jason Haddix, it became clear that AI is already being used in compelling ways. Cybersecurity teams are starting to leverage custom-trained AI models and bots to perform various functions. For example, some organizations are deciding to leverage and host their own private Llama (Meta) models and training them on vast swaths of proprietary data sets. Others are training OpenAI’s Custom GPTs and Assistants. When you start to factor these in, things get much more interesting. Here are some ways in which teams are already leveraging custom bots:
● An augmented web scraper that searches the internet every morning looking for threat intelligence related to your company vertical. It finds new vulnerabilities and exploits pertaining to the products that your company uses, then compiles a nice report of the data and emails it to you daily.
● A surface-area analyst that is trained on all your asset, network, vulnerability, and software data from your CMDB that can make recommendations, answer questions, and provide feedback to your security team about indicators that are part of incidents.
● A chat assistant that is trained on all company policy, including security policies, and can answer questions that employees may have or give them proactive feedback on their decisions
● A documentation and training assistant that has been fed all the documentation about a particular product that can assist in generating configuration changes, detection rules, and plugins.
The potential today with customized AI assistants and proprietary data models is vast. As these models improve and become more accessible, we will see more and more companies harnessing AI in new and creative ways. I believe that as the AI movement matures further, more and more entry-level tasks will be handled by AI. Job roles like the “Level 1 SOC Analyst” may be highly augmented or even entirely replaced by highly trained AI. Companies will continue to have a need for higher experienced or specialized roles, especially around security engineering, and those roles will leverage AI to become much more efficient at what they do. AI will add efficiencies that shrink the cybersecurity job market by reducing the number of needed workers and greatly enhancing the higher-skilled roles by making them more productive. Will this close the cybersecurity jobs gap? No one can know for certain, but I believe it will at least make the market slightly smaller.