Key Takeaways
- AI is changing cybersecurity roles by raising expectations for technical skills, judgment and adaptability.
- Cybersecurity training should focus on applied skills that reflect real job responsibilities, not just titles or credentials.
- Hands-on practice, simulations and performance-based assessments help L&D teams better measure job readiness.
There has been a lot of discussion recently about how artificial intelligence (AI) is disrupting the job market, yet cybersecurity remains a bright spot for job growth. The total employed cybersecurity workforce grew to 1.34 million in 2025 — the fourth straight year of growth — according to CyberSeek data.
Roles like information security analyst also remain among the fastest growing in the U.S., with the U.S. Bureau of Labor Statistics projecting 29% growth from 2024 to 2034. The average for all occupations is just 3%. Yet growth is only part of the story.
AI is changing cybersecurity jobs. It has raised the floor of expected skills — and how fast candidates are expected to master those skills. A role labeled “entry level” may ask for cloud familiarity, incident response judgment, documentation discipline, communication skills and enough AI awareness to question automated recommendations.
The question for employers and L&D teams is this: What kind of candidate is ready for the roles organizations need to fill now? Five years ago, the traditional path was easier to define. A new professional might start in IT support or a junior security operations center (SOC) role and build judgment through repetition. Today, AI, automation, managed services and cloud tools are changing the shape of those foundational experiences.
That raises a sharper question for training leaders: Are we still training for yesterday’s roles while hiring for tomorrow’s expectations?
Qualified Is a Moving Target
The cybersecurity market is sending mixed signals. Employers need talent, but they are less aligned on what “qualified” means. ISACA’s 2025 State of Cybersecurity report found that only 31% of respondents believe a majority of applicants are well qualified for the roles they are applying to. Adaptability was cited as the top factor in determining qualified candidates, slightly ahead of prior cybersecurity work experience. Credentials, hands-on training, cyber ranges and degrees still matter, but none ranked as highly as adaptability.
That pressure is not limited to cybersecurity. PwC’s 2026 U.S. AI Jobs Barometer found that the most AI-exposed junior roles are seven times more likely than the least AI-exposed junior roles to demand traditionally senior skills such as leadership and strategic thinking.
But adaptability, leadership and strategic thinking are much harder to validate than a degree or certification. A candidate may understand the vocabulary of incident response but struggle to prioritize during an investigation. Another may know how to use AI to summarize alerts but not how to verify whether the summary is accurate, complete or safe to act on.
More judgment is now expected earlier, while some of the lower-risk work that once helped people build critical judgment is being automated, outsourced or redesigned.
Cyber Roles Are Becoming Less Linear
The shift looks different at each level of the cybersecurity workforce, but the pattern is similar: familiar titles are carrying broader expectations.
- Early-career analysts may need to understand cloud identity, document findings clearly, collaborate with IT operations and know when to escalate.
- Mid-level practitioners may be expected to connect vulnerability management to business risk, interpret AI-generated recommendations and support compliance or resilience conversations.
- CISOs and security leaders need to go beyond technical expertise to translate risk into business priorities, justify investment, leverage influence across functions and communicate clearly with executives and boards.
The point is that familiar titles are absorbing a wider mix of expectations. Employers increasingly need people who can connect technical work to business context and emerging technologies.
That is a training design issue. If job titles stay familiar while the work inside them changes, learning paths built around static role definitions will struggle to keep up.
Training Has to Align With New Expectations
The solution is not to dismiss degrees, certifications or structured training. Those still matter. The problem is treating them as the finish line. For many cybersecurity roles, readiness now depends on whether someone can apply knowledge in context.
That means learning and development (L&D) teams should start with the work, not the title. Instead of building a generic “junior analyst” pathway, define the skills learners must demonstrate, such as triage an alert, document an incident, explain risk, validate an AI-generated recommendation and escalate with the right context.
It also means building more adaptable pathways before employment, or at least before full independence. Simulations, labs, cyber ranges, tabletop exercises, apprenticeships and internal rotations can give learners the practical reps that entry-level roles used to provide more consistently. These experiences should test judgment, not just recall.
Yet ISACA’s report suggests many organizations are moving in the opposite direction: Training nonsecurity staff to move into security roles fell from 41% in 2024 to 29% in 2025, while only 20% reported increasing performance-based training to attest to actual skill mastery. If adaptability is now a top qualification signal, training models need to become more adaptable too.
AI can help by personalizing learning, generating realistic scenarios, surfacing skill gaps and giving learners more frequent practice. But it should not remove the struggle that builds judgment. Learners should practice with AI in realistic environments, then be assessed on whether they can verify outputs, document reasoning and defend decisions.
Hiring managers can help by connecting assessments to development instead of using them only as filters. A candidate with strong analytical thinking and a cloud security gap may be a good candidate with a clear onboarding plan.
The New Mandate for L&D
Cybersecurity jobs are still growing, but the path into them is becoming less predictable. L&D leaders need to adapt as well by building training models that adapt as cybersecurity work changes.
That means defining skills clearly, giving learners practical experience earlier and validating readiness in ways that reflect the decisions they will actually need to make on the job. It also means treating adaptability as a trainable capability, not just a personality trait.
Organizations that get this right will be the ones that can show who is ready, where gaps remain and how quickly their people can learn as cybersecurity roles continue to evolve.

