Is Cybersecurity Actually Cooked? The Honest Truth About AI and Your Career

An AI agent discovered 22 vulnerabilities in Firefox last week. No human involved. Zero. It just... did it
Is Cybersecurity Actually Cooked? The Honest Truth About AI and Your Career
Is Cybersecurity Actually Cooked? The Honest Truth About AI and Your Career

What no one is telling you about which specializations survive and which are already on borrowed time.


An AI agent discovered 22 vulnerabilities in Firefox last week. No human involved. Zero. It just... did it.

And a few days before I sat down to write this, a friend of mine an AI threat intelligence expert at one of the biggest companies on the planet told me on a podcast that AI can do malware reverse engineering better than any human alive. Not "almost as well." Better.

So let me ask you the question that's been bouncing around cybersecurity forums, LinkedIn threads, and late-night Discord servers: Is the field cooked?

My honest answer? It depends entirely on where you're standing.

Some specializations are genuinely at risk. Not "might change a little" risk. Real, get-your-resume-updated risk. Others? They're growing so fast that organizations literally cannot find enough people to fill seats. The problem is that most of the people chasing the risky roles don't know it yet and the safe roles are sitting there, wide open, because everyone decided ethical hacking was cooler.

Let me walk you through every major cybersecurity specialization. No sugar-coating.


Application Security: The One Making Headlines for the Wrong Reasons

Here's where I'll probably upset some people.

AppSec application security groups together some of the most technically impressive work in the field. Malware reverse engineering. Secure code reviews. Exploit development. If you've ever watched someone tear apart a binary at a competition and felt that particular kind of nerdy awe, you know what I mean.

But this is also the specialization most at risk from AI. Not "somewhat impacted." Most at risk.

The Firefox story isn't a fluke. It's a preview. AI agents are already being trained specifically to find vulnerabilities in code and they're good at it. Frighteningly good. The kind of good that used to take a senior engineer three weeks now takes an agent a few hours.

(I know what you're thinking "but AI makes mistakes, it needs human oversight." True. For now.)

What does this mean practically? If you're a senior AppSec engineer or a malware reverse engineer, you're not unemployed tomorrow. But your job is going to change faster than almost any other role in the field. You need to be the person directing the AI agents, not competing with them on code review speed. Start there.

And if you're a student trying to break into cybersecurity? Don't make AppSec your entry point. That's not passion that's a gamble with your next two years of study time.


Ethical Hacking: The Dream Job That Was Never as Available as You Thought

I have to be careful here, because I love ethical hacking. Most of us do. It's the reason half the people in this field got into cybersecurity in the first place that romantic idea of thinking like an attacker, finding holes before the bad guys do, the whole thing.

But here's the counter-intuitive truth that most "cybersecurity career" content won't tell you: even before AI, there weren't that many dedicated penetration testing roles.

Think about it. How many companies actually have a full-time internal pentest team? A handful. Most organizations outsource it once or twice a year and call it done. The market for dedicated penetration testers was always thinner than the YouTube tutorials made it seem.

AI makes this worse. Not catastrophically worse not yet but measurably worse.

A colleague of mine gave a talk at Black Hat Asia recently. He started an AI agent on a penetration test at the beginning of his presentation. By the time he finished his talk and took questions, the agent had completed the test. That's not science fiction. That's a conference room in 2024.

Now, AI isn't replacing experienced pentesters entirely. The best ethical hackers are now running AI agents rather than doing every step manually. That's a real skill gap and a real opportunity if you learn it. But if you're picturing a future where you spend 40 hours a week manually exploiting systems, that future is narrowing.

My actual advice: learn ethical hacking. Genuinely, learn it it makes you a much sharper defender. But don't build your entire career foundation on it. Get a job first. Then spend the rest of your life doing pentesting on the side, picking it up in competitions, maybe eventually working it into your role. That's sustainable. Going all-in on it as a first job? Much riskier than people admit.


SOC Analyst: The Role Everyone Writes Off and Why They're Wrong

People outside cybersecurity assume SOC analysts are going to be the first casualty of AI. The logic goes: "They just look at alerts all day. AI can look at alerts. Goodbye, SOC analyst."

This assumption is wrong in almost every possible way.

First, it assumes the SOC analyst job is simple. It's not. I consult with organizations regularly, trying to help them improve their security posture, and I almost always find the same thing: detection and response is broken. Not because the tools are bad. Because there aren't enough people to do the work. The analysts who do exist are buried. They're not sitting around waiting for something to happen they're overwhelmed, triaging constantly, managing context that no tool can fully replicate.

Second and this one gets missed completely hackers are also using AI. Every efficiency gain that defenders get, attackers get too. The volume of attacks isn't going down because AI made defense easier. It's going up because AI made attacking cheaper. Blue teams are busier than they were two years ago, not less busy.

Does AI help SOC analysts? Absolutely. Detection tools are getting sharper. Analysis that used to take three hours can happen in thirty minutes. Automated response is improving. All of that is real. But the underlying problem too many threats, not enough experienced people, an environment that changes every week isn't something AI solves. It just means analysts get to focus on harder problems instead of tedious ones.

If you're an existing SOC analyst, keep building your skills. Explore cloud security, threat intelligence, incident response leadership. And yes, get comfortable with AI tools they're going to be as normal as Google is now.

If you're just starting out, blue teaming skills are your fastest path into the field. More jobs, real demand, transferable to almost everything else you'll ever do in cybersecurity.


GRC: The Unglamorous Specialization That's Actually Winning

Governance, Risk, and Compliance. Even the name sounds like something you'd rather not deal with.

And yet GRC is quietly the most resilient specialization in the field, and one of the fastest-growing.

Here's why. GRC work is fundamentally about providing assurance to a business. Risk assessments. Compliance audits. Regulatory frameworks. Policy analysis. Every single one of these involves human judgment, legal accountability, and organizational context that AI genuinely cannot replicate. I can't throw a compliance audit at an AI and sign off on the output there are legal obligations, evidence requirements, and liability considerations that require an actual person.

In my own consulting work, AI helps me with things like summarizing long policy documents and drafting sections of reports faster. It's useful. But it hasn't touched the core of the job.

And here's the part nobody expected: AI created more GRC work, not less. Every organization I talk to is implementing AI in some form. And every single one of them has questions about governance, about risk frameworks, about how to handle AI in a regulated environment. That demand is landing in GRC teams. My calendar is busier because of AI, not despite it.

If you're an established cybersecurity professional looking to recession-proof your career, GRC skills are the play. You'll be able to speak the language of executives and boards, bridge technical and business concerns, and position yourself for senior roles that AI tools literally cannot compete for.

If you're newer to the field start here. Demand is real, supply of qualified people is genuinely short, and the skills transfer everywhere.


IAM and Security Engineering: The Specialists Who Need to Stay Broad

Identity and access management. Cloud security. Network security. Security engineering at large.

These roles matter. They're real. And they're also where I see the most dangerous career mistake people make.

The mistake is specializing too narrowly in a single tool or technology.

I've watched this pattern for over a decade. Someone spends five years becoming the best Cisco ASA firewall person on the planet. Then the organization migrates to a different architecture. Or the technology gets acquired. Or the market shifts. And suddenly that person has "10 years of experience" that is really one month of experience, repeated 120 times.

(That's not a dig at anyone I've seen it happen to genuinely talented people. The tools they picked just didn't last.)

AI accelerates this risk. If your job is configuring and maintaining a specific enterprise tool, AI is already making that tool easier to manage. Fewer people are needed to run it. The humans who survive that compression are the ones who understand the underlying principles, not just the interface.

The exceptions? Cloud security, specifically. This is the one area under the security engineering umbrella where demand is genuinely outpacing supply, and shows no sign of slowing. If you're going to plant a flag in one technical specialization, plant it in cloud.

One more warning for anyone whose job title includes "automation specialist" or involves primarily writing scripts: be careful. Basic scripting is something AI can already handle. If your value is "I write Python scripts to automate SOC tasks," that role is under real pressure. The value is in the security judgment that drives the automation not the automation itself.


What Actually Protects Your Career

Here's where I stop analyzing and just tell you what I think.

The cybersecurity professionals who are going to be fine in five years share one characteristic: they refused to become one thing.

The hyper-specialized pentest person. The single-tool security engineer. The analyst who only does one type of incident. These are the people who are going to feel the squeeze. Not because they're bad at what they do often they're exceptional but because the world around them is changing faster than they're adapting.

If you're already in the field, the floor you want to be standing on is three skills wide: defensive security, GRC, and cloud security. Together, those three areas cover more job descriptions than any single specialization, they transfer across industries, and they position you for senior roles where AI is an assistant rather than a replacement.

Beyond that if you're experienced enough to have an established workflow start building with AI. Not taking courses about AI. Not getting certifications with the word "AI" in the title. (Honestly, skip those. The CompTIA AI+ is not going to teach you anything you couldn't learn in an afternoon of actually using the tools.) Build agents. Experiment with automating your own work. Figure out what AI is genuinely bad at in your specific context. That knowledge is worth far more than any credential.

And if you're just starting out? Your job is simpler, even if it doesn't feel that way. Learn cybersecurity first. The AI layer comes later, after you have enough context to use it intelligently. Chase the demand blue teaming, GRC, cloud not the prestige. You can learn penetration testing on nights and weekends. You can't un-spend two years studying for a market that doesn't have enough roles.


Cybersecurity isn't cooked. But it's changing faster than most people in it want to admit.

The field will keep growing. Attacks are getting more sophisticated, regulations are multiplying, and organizations are increasingly aware that "we'll figure it out later" is no longer a viable security strategy. The humans who will thrive aren't the ones who are best at any single technical skill. They're the ones who can think across domains, communicate with the business, and use AI as a multiplier rather than competing with it as a replacement.

That's always been the ceiling. Now it's also the floor.

If you want a concrete starting point a structured roadmap that builds GRC, blue teaming, and cloud skills in the right order find a guide focused specifically on generalist cybersecurity careers. The path is there. You just have to be willing to follow it instead of the one that looks cooler on a YouTube thumbnail.


Post a Comment