Logo
Cybersecurity

Entry-Level Cybersecurity Is Getting a New Job Description

The first rung of the cybersecurity career ladder is moving. AI security is already becoming part of what beginners are expected to understand.

ITSEC AsiaITSEC Asia
|
Sep 03, 2026
Entry-Level Cybersecurity Is Getting a New Job Description

There used to be a fairly predictable starting point for a cybersecurity career. Learn networking. Understand access control. Get comfortable with security operations. Then, after some experience, start tackling the newer and more complicated stuff.

AI is messing with that sequence.

On 1 September 2026, ISC2 introduced its updated Certified in Cybersecurity exam outline, the first major content revision since the entry-level certification launched in 2022. Foundational AI concepts are now integrated into the material, including identifying AI assets, recognizing automated threats and supporting secure governance of emerging technologies.

Its updated AI guidance goes further. Cybersecurity professionals increasingly need competence in AI governance, model security, data integrity, prompt engineering, AI risk management and the security of AI-enabled systems.

That’s quite a list for something that was recently considered a specialist topic.

AI Security Is Moving Down the Career Ladder

There’s a practical reason for this.

AI-enabled systems are entering everyday business operations. At the same time, AI can be used for phishing, social engineering and increasingly automated attacks.

Indonesia is already preparing for that reality. On 20 August, Vice Minister of Communication and Digital Affairs Nezar Patria warned that AI had changed how cybercrime operates, pointing specifically to deepfakes and AI-assisted social engineering. He called for security to be considered from the beginning of technology development through a security by design approach.

For someone entering cybersecurity, that changes the baseline.

A junior professional may increasingly encounter questions such as: What data can this AI system access? Could its output expose sensitive information? Is an automated action behaving as expected? What happens if someone manipulates its input?

“AI security” can’t sit permanently in the advanced-course folder if those questions are already appearing in everyday systems.

The Fundamentals Still Matter

None of this means beginners should skip networking and jump straight into prompt injection.

The fundamentals remain fundamental.

Access control still matters. Networks still need securing. Incident response still needs people who understand what they’re looking at. The updated entry-level framework itself continues to cover security principles, business continuity, access controls, network security and security operations.

What’s changing is the layer sitting on top.

Tomorrow’s junior analyst needs the foundations and enough AI literacy to understand how those foundations apply when software can generate content, make recommendations or perform tasks autonomously.

That makes practical training especially useful. Reading about an AI security failure is one thing. Having to identify what went wrong and decide what to do next tends to stick better.

At ITSEC Cyber & AI Academy, that connection between cybersecurity and AI is built into the learning approach, supported by practical exercises and scenarios closer to the situations professionals can encounter at work.

Entry-level cybersecurity isn’t disappearing.

It’s simply getting a slightly longer job description.

Explore practical cybersecurity and AI training at ITSEC Cyber & AI Academy.

References: ISC2 updated entry-level cybersecurity outline, 6 August 2026 · ISC2 AI security guidance, 1 September 2026 · Komdigi on AI-enabled cybercrime and security by design, 20 August 2026

Share this post

You may also like

This is How Information Security Analysis Protects What Prevention Can't
Cybersecurity

This is How Information Security Analysis Protects What Prevention Can't

INTRODUCTION Organizations worldwide are investing more in cybersecurity than at any point in history, yet breaches are growing more frequent, more expensive, and more damaging. The global average cost of a data breach reached USD 4.88 million in 2024, the highest figure ever recorded. Even more alarming, the average time to identify a breach stood at 194 days, nearly half a year of undetected attacker activity inside a network before anyone realized something was wrong. These numbers raise an urgent question every business leader must answer honestly: if an attacker entered your network today, how long would it take your organization to find out? And once discovered, could you identify exactly what was accessed, how the attacker moved, and what vulnerabilities made it possible in the first place? For most organizations, the honest answer is: not fast enough, and not with enough certainty. That gap is precisely what Information Security Analysis (ISA) is designed to close. Prevention, including firewalls, antivirus, and multi-factor authentication, is necessary but not sufficient. When attackers

|
Mei 11, 2026 7 minutes read
What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026
Cybersecurity

What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026

INTRODUCTION What percentage of your last penetration test report was actually proven exploitable, and what percentage was a list of things a scanner flagged and nobody validated? Most CISOs cannot answer that question with confidence, and that is exactly the problem. Buyers guides published this year point to a pattern worth sitting with. If a quoted penetration test comes in at four to five thousand dollars or less, it is very likely an automated vulnerability scan wearing a pen test label, not manual work performed by a skilled tester. That gap between what is sold as a penetration test and what is actually delivered is why the selection conversation matters so much more than most procurement teams treat it. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across Indonesia, Singapore, Australia, and the UAE that have gone through this exact evaluation, and the questions that separate a genuinely useful engagement from an expensive checkbox exercise are more specific than most RFPs ever ask. Source: Six Questions to Ask a

ITSEC AsiaITSEC Asia
|
Jul 17, 2026 5 minutes read
Top Five Cybersecurity Threats to Small Business Owners
Cybersecurity

Top Five Cybersecurity Threats to Small Business Owners

According to a recent Verizon Data Breach Investigations Report, over the past two years, small and medium-sized businesses have become the primary target of cybercriminals, and they are now more affected by cyber breaches than large-scale businesses. Cyberattacks on SMEs have increased because cybercriminals have predicted that small and medium-sized enterprises have fewer resources to dedicate to their security. Most SMEs lack dedicated security professionals, and they are too small to afford them. This makes them vulnerable and easy targets for cybercriminals. In this context, neglecting security is no longer an option, and the assumption that your business is too small to attract the interest of cybercriminals is unrealistic. TOP FIVE CYBER THREATS AFFECTING SMALL AND MEDIUM-SIZED ENTERPRISES Incompatible Operating Systems and Software: Ensure that your computers and the software running on them are up to date. This is crucial and forms a solid foundation for good security practices. Hackers exploit vulnerabilities in outdated software and operating systems, often infiltrating organizations. Failing to apply software and operating system updates when they

ITSEC AsiaITSEC Asia
|
Jul 20, 2023 5 minutes read

Receive weekly
updates on new posts

Subscribe