Entry-Level Cybersecurity Is Getting a New Job Description
The first rung of the cybersecurity career ladder is moving. AI security is already becoming part of what beginners are expected to understand.

There used to be a fairly predictable starting point for a cybersecurity career. Learn networking. Understand access control. Get comfortable with security operations. Then, after some experience, start tackling the newer and more complicated stuff.
AI is messing with that sequence.
On 1 September 2026, ISC2 introduced its updated Certified in Cybersecurity exam outline, the first major content revision since the entry-level certification launched in 2022. Foundational AI concepts are now integrated into the material, including identifying AI assets, recognizing automated threats and supporting secure governance of emerging technologies.
Its updated AI guidance goes further. Cybersecurity professionals increasingly need competence in AI governance, model security, data integrity, prompt engineering, AI risk management and the security of AI-enabled systems.
That’s quite a list for something that was recently considered a specialist topic.
AI Security Is Moving Down the Career Ladder
There’s a practical reason for this.
AI-enabled systems are entering everyday business operations. At the same time, AI can be used for phishing, social engineering and increasingly automated attacks.
Indonesia is already preparing for that reality. On 20 August, Vice Minister of Communication and Digital Affairs Nezar Patria warned that AI had changed how cybercrime operates, pointing specifically to deepfakes and AI-assisted social engineering. He called for security to be considered from the beginning of technology development through a security by design approach.
For someone entering cybersecurity, that changes the baseline.
A junior professional may increasingly encounter questions such as: What data can this AI system access? Could its output expose sensitive information? Is an automated action behaving as expected? What happens if someone manipulates its input?
“AI security” can’t sit permanently in the advanced-course folder if those questions are already appearing in everyday systems.
The Fundamentals Still Matter
None of this means beginners should skip networking and jump straight into prompt injection.
The fundamentals remain fundamental.
Access control still matters. Networks still need securing. Incident response still needs people who understand what they’re looking at. The updated entry-level framework itself continues to cover security principles, business continuity, access controls, network security and security operations.
What’s changing is the layer sitting on top.
Tomorrow’s junior analyst needs the foundations and enough AI literacy to understand how those foundations apply when software can generate content, make recommendations or perform tasks autonomously.
That makes practical training especially useful. Reading about an AI security failure is one thing. Having to identify what went wrong and decide what to do next tends to stick better.
At ITSEC Cyber & AI Academy, that connection between cybersecurity and AI is built into the learning approach, supported by practical exercises and scenarios closer to the situations professionals can encounter at work.
Entry-level cybersecurity isn’t disappearing.
It’s simply getting a slightly longer job description.
Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.
References: ISC2 updated entry-level cybersecurity outline, 6 August 2026 · ISC2 AI security guidance, 1 September 2026 · Komdigi on AI-enabled cybercrime and security by design, 20 August 2026
.png)


