Every system connected to a network is a system someone is trying to break into. Cybersecurity is the field that stands between the attacker and the system, the vulnerability and the breach, the data that exists and the data that gets stolen. The structural pull at the field level is Protection. Whatever a particular security role looks like — a SOC analyst watching dashboards at three in the morning, a penetration tester probing a client's network for weaknesses, a security engineer hardening a cloud environment, a CISO presenting risk posture to a board of directors — the field exists because the move from vulnerable to safe requires sustained, skilled, adversarial attention. The threat does not sleep, does not take weekends, and does not care about your staffing budget.
Discovery is the offensive face of the field. Penetration testing, red teaming, vulnerability research, and threat hunting are all Discovery work — finding what is wrong before an attacker does. The structural similarity to investigative work is not a metaphor; the penetration tester is asking the same question as the detective: what is here that nobody has noticed yet? The difference is that the detective works after the fact and the pen tester works before. The people drawn to this side of the field are drawn to the hunt — the intellectual pleasure of finding the gap, the path, the overlooked assumption. The ethical dimension is real and unusual: the same skills, tools, and mindset that make a great penetration tester would also make an effective attacker. The field exists in a permanent structural tension between the offensive and defensive applications of the same knowledge.
🦊
There's a guide here if you want one
Kitsune can talk through anything on this page — whether it might suit you, what to do next, questions this page doesn't answer. Everything here is yours to read either way.
Solo security consulting at specialist scale
Inference
The barrier
A solo cybersecurity consultant competing for mid-market clients was constrained by throughput: compliance gap analyses, policy drafting, and vulnerability assessments each required significant manual work, making it difficult to serve multiple clients simultaneously at the quality level required to sustain a practice.
What changed
LLM-assisted policy drafting, AI-enhanced vulnerability scanning, and automated compliance reporting dramatically reduce per-engagement production time. A solo consultant with strong AI tool fluency can now deliver at the throughput of a small team. The judgment work — scoping, remediation prioritisation, client communication — remains entirely human; AI assists the production, not the strategy.
Behaviours involved
AdvisingSecuringAutomatingCommunicating
Assessed May 2026
Security generalist in smaller organisations
Inference
The barrier
Security expertise was so specialised and broad that a single person could not credibly cover threat monitoring, penetration testing, compliance, and incident response at a quality level that justified employment by a mid-market company. Most mid-market companies either outsourced to MSSPs or went without.
What changed
AI-enhanced tools (AI-native SIEM, automated compliance platforms, AI-assisted pen testing) extend what a single skilled security professional can monitor and manage. A security generalist with strong AI tool fluency can now maintain defensive posture for an organisation that previously had to choose between MSSP cost and security risk. AI tools are partially compensating for the talent gap rather than replacing existing talent.
Behaviours involved
MonitoringAnalyzingSecuringAutomating
Assessed May 2026
Threat intelligence as accessible practice
Inference
The barrier
Threat intelligence — tracking adversary groups, analysing TTPs, producing intelligence products that inform security decision-making — was largely the province of large security vendors, government intelligence agencies, and enterprise security teams with dedicated threat intelligence functions. The aggregation and synthesis burden was too high for smaller practitioners.
What changed
LLM tools that synthesise OSINT, structured threat feeds (STIX/TAXII), and MITRE ATT&CK data into actionable intelligence products dramatically lower the production cost of threat intelligence. A practitioner with strong analytical judgment but without a large team can now produce threat intelligence at a quality and frequency that previously required team-level resources.
These are real jobs that exist now and did not exist before the current wave of AI.
New title
AI Security Specialist
Secures AI systems themselves from adversarial ML attacks, model theft, data poisoning, and prompt injection. Distinct from general application security; requires ML system knowledge alongside security methodology. Early practitioners are arriving from security engineering, ML engineering, or research backgrounds.
Named job postings exist for this and adjacent titles; the specialisation barely existed two years ago. One of the clearest 'new role, not a retitled old role' patterns in the PurPassion field set. · current fact
Familiar title, new shape
AI-Augmented Threat Hunter
Threat hunter who uses AI to expand the range of environments they can investigate and the speed at which they can form and test hypotheses. The judgement layer — which hypotheses to test, recognising what the AI missed, understanding attacker psychology — remains human; the AI handles data aggregation and initial pattern-matching across large environments.
Configuration is viable today and visible in practice, but has no settled title in postings. Likely to become standard threat-hunting practice within 2-3 years. · early signal
New title
AI Red Teamer
Practitioner specialising in testing AI systems for security vulnerabilities — adversarial prompting, model extraction, data poisoning, inference attacks — alongside or instead of traditional penetration testing. Requires both security methodology and AI/ML model behaviour understanding.
A small and growing specialist community; the natural adjacent path for penetration testers who develop AI/ML system understanding. Likely to formalise into a distinct sub-field as AI system deployments expand. · early signal
CISO with AI Governance Scope
The existing CISO role expanding to cover AI risk posture, adversarial-ML exposure, AI ethics and AI-governance compliance (EU AI Act and equivalents) alongside traditional information security governance. Not a new title — a materially widened remit under the old one.
CISOs who built this expanded scope early are reported to command premium compensation and board-level authority their predecessors in traditional CISO roles did not have. · early signal
Familiar title, new shape
AI Security Educator / Upskilling Specialist
Practitioner who teaches AI-era security skills to the existing security workforce, in formal certification training or internal corporate programmes. Exists because the field's gap has shifted in character from headcount shortage to skills-composition shortage.
ISC2's 2025 reframing from 'workforce gap' to 'skills gap' is the structural driver: the constraint is increasingly that practitioners lack AI-era security skills, not that there are too few practitioners. · early signal
Only the AI Security Specialist is confirmed as a hired-for title with postings. The other four are role configurations inferred from structural trajectory and practitioner-community signal; they are graded accordingly and should not be read as documented labour-market facts. Novelty assessments for configurations without settled titles are provisional.
Bars above the line are the parts of this work that still need a person. Bars below it are what AI can already do. Tap any column to see the actual work behind it.
high ground · holds stronglydeep water · reaches furthest
yours, by strengthAI reach, by depth
The honest read. Cybersecurity is protected by an unusual combination: almost no physical protection and no licensing floor, but exceptionally strong creative-synthesis and ambiguity-navigation protection derived from the field's adversarial structure. Because the opponent adapts, the highest-value work has no stable pattern to learn from — which is precisely the condition under which current AI tooling is weakest. The practical consequence for a student is that the protection is concentrated at the top of the skill distribution rather than spread evenly: the routine, high-volume, pattern-matching end of the field (Tier 1 triage) is the most exposed work in the corpus, while the creative-adversarial end is among the least. This is the opposite of a field like veterinary science, where protection is broad and structural.
Cybersecurity is the only field in the PurPassion set where AI deployment on the attacker side is not only real but documented at the nation-state level. This makes AI adoption by defenders non-optional in a way that is structurally different from every other field: the question is not 'should we use AI tools' but 'how quickly can we match what attackers are already deploying.'
How AI is changing the way in
5 ways into this field, and AI is not doing the same thing to each of them.
Security Analyst / SOC — Tier 1 (sec_arch_001)Harder to enter
The highest-volume, most AI-tractable tasks in the field's widest entry ramp are under direct pressure from AI triage tooling. Vendor-published deployments report investigation time falling from 30+ minutes to under 2 minutes per alert; a SOC that needed 10 Tier 1 analysts to process a shift's alert volume may need 3-4 for escalation and oversight. Entry-level headcount growth at Tier 1 is expected to lag total security hiring growth. [survey_self_report for the time-reduction magnitude — vendor case studies, not independently audited; inference for the staffing-ratio consequence]
Security Engineer (sec_arch_003)Slightly harder to enter
AI-assisted code review and infrastructure scanning compress some junior production work, but security engineering entry has always required a software or infrastructure foundation rather than being a high-volume execution role. Augmentation dominates displacement. [inference]
Field aggregate — all security hiringSlightly harder to enter
The field's decade-long structural shortage absorbs AI efficiency gains into expanded capacity rather than headcount reduction: AI tools are helping the existing workforce handle more threat volume, not reducing the number of people needed. Total cybersecurity employment continues to grow. [current_fact for the shortage; inference for the absorption mechanism]
Creative adversarial thinking is where AI tooling is weakest. AI has raised the value of skilled human testing by lowering the barrier for unsophisticated automated attacks, so entry-level demand is not under AI pressure. The entry barrier here has always been skill acquisition, not headcount. [structural_inference]
Not an entry-level archetype; reached after a full career. Scope is expanding rather than compressing. Recorded for completeness of the role split. [structural_inference]
That is everything we currently know about AI in Cybersecurity / InfoSec. It shows where things are moving so you can choose which way in suits you.
People drawn to Cybersecurity / InfoSec are often drawn to these. Most sit in a different part of the terrain.