Logo
Cybersecurity

Entry-Level Cybersecurity Is Getting a New Job Description

The first rung of the cybersecurity career ladder is moving. AI security is already becoming part of what beginners are expected to understand.

ITSEC AsiaITSEC Asia
|
Sep 03, 2026
Entry-Level Cybersecurity Is Getting a New Job Description

There used to be a fairly predictable starting point for a cybersecurity career. Learn networking. Understand access control. Get comfortable with security operations. Then, after some experience, start tackling the newer and more complicated stuff.

AI is messing with that sequence.

On 1 September 2026, ISC2 introduced its updated Certified in Cybersecurity exam outline, the first major content revision since the entry-level certification launched in 2022. Foundational AI concepts are now integrated into the material, including identifying AI assets, recognizing automated threats and supporting secure governance of emerging technologies.

Its updated AI guidance goes further. Cybersecurity professionals increasingly need competence in AI governance, model security, data integrity, prompt engineering, AI risk management and the security of AI-enabled systems.

That’s quite a list for something that was recently considered a specialist topic.

AI Security Is Moving Down the Career Ladder

There’s a practical reason for this.

AI-enabled systems are entering everyday business operations. At the same time, AI can be used for phishing, social engineering and increasingly automated attacks.

Indonesia is already preparing for that reality. On 20 August, Vice Minister of Communication and Digital Affairs Nezar Patria warned that AI had changed how cybercrime operates, pointing specifically to deepfakes and AI-assisted social engineering. He called for security to be considered from the beginning of technology development through a security by design approach.

For someone entering cybersecurity, that changes the baseline.

A junior professional may increasingly encounter questions such as: What data can this AI system access? Could its output expose sensitive information? Is an automated action behaving as expected? What happens if someone manipulates its input?

“AI security” can’t sit permanently in the advanced-course folder if those questions are already appearing in everyday systems.

The Fundamentals Still Matter

None of this means beginners should skip networking and jump straight into prompt injection.

The fundamentals remain fundamental.

Access control still matters. Networks still need securing. Incident response still needs people who understand what they’re looking at. The updated entry-level framework itself continues to cover security principles, business continuity, access controls, network security and security operations.

What’s changing is the layer sitting on top.

Tomorrow’s junior analyst needs the foundations and enough AI literacy to understand how those foundations apply when software can generate content, make recommendations or perform tasks autonomously.

That makes practical training especially useful. Reading about an AI security failure is one thing. Having to identify what went wrong and decide what to do next tends to stick better.

At ITSEC Cyber & AI Academy, that connection between cybersecurity and AI is built into the learning approach, supported by practical exercises and scenarios closer to the situations professionals can encounter at work.

Entry-level cybersecurity isn’t disappearing.

It’s simply getting a slightly longer job description.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ISC2 updated entry-level cybersecurity outline, 6 August 2026 · ISC2 AI security guidance, 1 September 2026 · Komdigi on AI-enabled cybercrime and security by design, 20 August 2026

Share this post

You may also like

Your Cybersecurity Skills Gap Might Be a Job Design Problem
Cybersecurity

Your Cybersecurity Skills Gap Might Be a Job Design Problem

Cybersecurity job descriptions can become ambitious documents. An organization needs someone who understands cloud security, investigates incidents, tests applications, manages risk, explains regulations, tunes security tools and perhaps briefs senior management when something goes wrong. Five years of experience preferred. The candidate sounds excellent. Finding this person may take a while. ENISA’s European Cybersecurity Skills Framework offers a useful reminder that cybersecurity isn’t one profession wearing several different badges. The framework separates the field into 12 professional profiles, including Cyber Incident Responder, Cybersecurity Architect, Penetration Tester, Cybersecurity Risk Manager, Digital Forensics Investigator and Cyber Threat Intelligence Specialist. Each profile has different tasks, knowledge and competencies. They also depend on one another. That changes how organizations should think about a “skills shortage.” CHECK THE JOB BEFORE BLAMING THE TALENT POOL Some roles will naturally overlap, particularly in smaller teams. ENISA’s own user manual treats the framework as flexible and shows how organizations can combine responsibilities according to their circumstances. The problem starts when overlap becomes accumulation. A useful workforce review can ask: * Which tasks genuinely

ITSEC AsiaITSEC Asia
|
Sep 22, 2026 — 3 minutes read
Stop Treating the Cybersecurity Skills Gap as One Big Gap
Cybersecurity

Stop Treating the Cybersecurity Skills Gap as One Big Gap

“Cybersecurity talent shortage” is a useful phrase until someone has to decide what to do about it. Hire more people. Train more graduates. Upskill employees. Fine. Train them in what? NIST’s latest cybersecurity workforce investment takes that question seriously. On 18 September, it announced more than $1.7 million for nine Regional Alliances and Multistakeholder Partnerships to Stimulate Cybersecurity Education and Workforce Development, or RAMPS, projects across eight U.S. states. The interesting part isn’t the funding figure. It’s the design. Each project is expected to connect the specific workforce needs of local businesses and nonprofit organizations with learning objectives based on the NICE Workforce Framework. The projects then translate those requirements into curriculum development, internships, apprenticeships, hands-on projects and other learning opportunities. In other words, training starts with the capability that’s missing. ONE SHORTAGE CAN HIDE SEVERAL GAPS Consider three organizations hiring cybersecurity talent. A financial institution may need people who can investigate identity abuse and respond to incidents. A cloud-heavy technology business may be struggling to find people who understand cloud configurations, IAM and

ITSEC AsiaITSEC Asia
|
Sep 21, 2026 — 3 minutes read
Four Strong Reasons to Use an MSSP
Cybersecurity

Four Strong Reasons to Use an MSSP

Test

The multitude of challenges to be faced is the main reason why most organizations today are turning to managed security service providers (MSSPs) to help them address these issues. The challenges of strengthening human resources, processes, and technologies as efforts to secure their intellectual property and data appropriately, while still complying with cybersecurity regulations, can be a daunting task even for well-managed IT departments. With these considerations in mind, here are four main reasons why I prefer MSSPs over in-house security. USING MSSP SAVES YOU MONEY Building, running, and maintaining a cybersecurity ecosystem comes with significant costs. One of the reasons is that many software solutions require specialized hardware and equipment to run, and they often come with recurring licensing costs. Additionally, the salaries of cybersecurity employees and the training they need to effectively utilize new tools and technologies add to the expenses. One of the CFO's favorite aspects of using MSSP is that it can replace the capital expenditures often needed to add new tools with a large

ITSEC AsiaITSEC Asia
|
Jul 10, 2023 — 5 minutes read

Receive weekly
updates on new posts

Subscribe