AI in cybersecurity: jobs shift, SOCs change
Experts say AI will transform security operations, vulnerability triage, and roles, but reproducibility and governance remain hurdles.
Software development has been reshaped by AI, with developers collaborating with chatbots instead of writing code alone. Now, security leaders are watching to see whether cybersecurity will undergo a similar upheaval. The shift is already visible in security operations centers, where AI agents are beginning to handle tasks once done by junior analysts.
From solitary coding to AI collaboration
Google Cloud's 2025 report on the State of AI-Assisted Software Development found that 90% of developer respondents used AI as part of their work, and 80% believed it increased their productivity. An earlier Microsoft study showed developers using AI completed 26% more tasks than those who didn't.
The productivity boost has come with job market effects. A March 2026 Federal Reserve Board working paper found that coder employment growth is about 3% lower now than pre-ChatGPT. Gartner predicts that 80% of organizations will evolve large software engineering teams into smaller, AI-augmented teams by 2030.
Cybersecurity's imperfect analogy
Experts expect similar changes in cybersecurity, but the comparison is not exact. "The hard part for us is, if we're talking about where engineering is moving — to fully looped autonomous agents, feedback loops, all the things that they're building now, and just having humans supervise the machines — security really requires reproducibility," David Lindner, CISO at Contrast Security, tells CSO.
Jim Reavis, CEO and co-founder of the Cloud Security Alliance, tells CSO that changes won't happen as quickly as in software. "I don't think cybersecurity will be completely changed that quickly, but certainly we will see month-by-month big changes, and two years from now, it may be unrecognizable from what it is today," he says.
The autonomous SOC is almost here
AI agents can already perform tasks that fully staffed SOCs do, often faster and better. Lindner describes an incident that came through Jira where an agent pulled information from GitHub and Datadog and provided initial triage. "I don't want to even call it a junior SOC analyst. It is a SOC analyst that does some initial triage," he says.
But not all CISOs are ready to give agents full authority. Lionel Litty, CISO at Menlo Security, tells CSO: "We're definitely leveraging AI tools, and maybe some of what would have been first-level triage is now being done by agents. But at this point, at least for us, we're not yet comfortable with just letting agents run wide in our SOC and make the ultimate decision of, 'Hey, this is something that we can ignore, or this is something that definitely we should look at.' We use them to help provide context and prioritize."
Reavis expects that much of the first-level work will move to agents, leaving humans to handle escalation and higher-level judgment. "Basically all of cybersecurity is going to need to operate at machine speed," he says. "SOCs absolutely are going to have a layer of activity where it's going to be all agents making the decisions and doing the triage. Then the human in the loop is going to be at a higher level, more senior."
Vulnerability discovery outpaces absorption
AI is accelerating vulnerability discovery, but fixing every flaw is a challenge. Reavis says the problem is absorption: "How do I absorb this information? How do I triage it? How do I fix it?"
Litty compares it to static analysis systems that generated too many findings. "You can find hundreds of things, but if you send hundreds of things to engineering and most of them aren't relevant, engineering will just ignore you," he says.
Caleb Sima, chair of the CSA AI Safety Initiative and founding partner of White Rabbit, tells CSO that autonomous validation in production environments is still difficult. "I think vulnerability discovery today in source code is done," he says. "But in terms of real vulnerability discovery in an autonomous way, in a real enterprise production network that produces valid vulnerability and exploitation, we still have a bit of ways to go."
Lindner adds: "We don't have a problem finding problems. We have a problem triaging and remediating all the problems that we find."
Machine-speed attacks and containment
Autonomous attacks may force defenders to respond at machine speed. Sima describes a scenario where an agent spawns 200 agents to rapidly move through an enterprise and exploit vulnerabilities. "It's no longer about a single attacker rooting through your network, but it's a landing of an agent that spawns 200 agents that rapidly move through your enterprise to identify and exploit its vulnerabilities," he says.
Defenders should be able to quarantine and adjust controls at machine speed without breaking production, Sima says. Litty advocates for least privilege and separation of duties to limit damage from any single exploited vulnerability.
Flatter teams, barbell workforce
Experts anticipate role restructuring rather than net job losses. Reavis sees a flattening of organizations: "I see a flattening of organizations between the leaders and the builders. The more senior people are going to have to go and build things."
Sima expects a barbell-shaped workforce with senior individual contributors and AI-native juniors, while middle coordination roles struggle. Lindner agrees that experience and judgment remain irreplaceable: "The things AI isn't going to be able to replace are experience and judgment. My team is uber-senior today, and I need that." Litty says he's not seeing humans go away in those areas for now.
From tool sprawl to AI control plane
LLMs may become the interface that connects existing security tools. Sima says AI can control firewalls and endpoint tools conversationally: "AI becomes the interface and the glue across all of these fragmented security products."
Reavis notes the technology footprint is exploding: "On the one hand, you see a lot of sprawl, and we're going to have trillions of agents." Litty, however, sees existing tools evolving rather than proliferating: "What we're seeing so far is that it changes the tools. It doesn't necessarily mean more tools."
What CISOs should do now
Experts recommend that CISOs identify bounded, high-volume tasks like alert enrichment, initial triage, and vulnerability prioritization where agents can be tested with restricted authority. Reavis advises senior people to build new ways of doing their jobs.
Litty suggests creating a governance discipline with an inventory of every agent and AI-enabled security function. "First, [have] a registry of where you are using AI, and then look at the quality of the output," he says. "How do you do drift detection for what your AI tools are doing? Is this still working? If you take the SOC example, how do you evaluate how well your AI agent is doing at triaging your vulnerabilities?"
Sima emphasizes that every agent should have a named human or team accountable for it: "There has to be a named owner. Whether that named owner is a team or an individual is all dependent upon what that AI agent is responsible for, what its goal and objective are, and the job that it does."
Implications for security leaders
The transformation of cybersecurity by AI is not a distant future; it is already underway. For businesses, this means rethinking team structures, investing in governance frameworks, and preparing for machine-speed threats. Security leaders who start now to test agents in controlled settings and establish accountability will be better positioned to adapt. The challenge is not to automate everything, but to understand where agents work, restrict their actions, and ensure human oversight for consequential decisions.
Sources
- CSO Online Original source
- working paper Also reporting
- predicts Also reporting
Continue Reading
Amazon Rolls Out Alexa+ Across India
Amazon has launched its Alexa+ assistant in India with Hindi and English support, priced at ₹2,000 a month for non-Prime users.
Microsoft's Classroom AI Privacy Pledge
Microsoft and the AFT agree on binding AI privacy standards for schools, as Google stays silent on similar protections.
The AI graveyard's hard lessons
A running record of AI products that shut down or missed expectations shows even the biggest players stumble.