Cybersecurity has an experience problem, and AI may make it harder to solve

Employers want cybersecurity workers who can supervise AI agents and exercise good judgement. In South Africa, getting enough people to that level is already difficult.

Cybersecurity companies say they can’t find enough skilled people. At the same time, entry-level jobs often ask for practical experience, certifications and familiarity with the tools used inside large organisations. AI is now adding another requirement, because employers increasingly want people who know how to work with AI agents too.

The AI Workforce Consortium’s new AI Agents and the Impact on Cybersecurity report shows how quickly the job market is changing. Across the G7 countries it studied, senior-titled cybersecurity job postings grew 65% year on year between October 2025 and March 2026. Junior-titled postings grew by 5.9%, while overall cybersecurity demand grew 9.5%.

Those numbers don’t tell us that AI is killing junior cybersecurity jobs. The data covers G7 economies rather than South Africa, and Cisco uses job titles to separate junior and senior roles because employers don’t consistently state how many years of experience they require. It does show that companies are hiring far more aggressively for senior roles while asking for new skills from people trying to enter the industry.

Marci Paino, Chief Learning Officer of Enterprise Learning & Growth at Cisco, writes in the thought-leadership piece accompanying the research that cybersecurity work is moving “from building models to directing and verifying them”. That means knowing more than how to use an AI tool. Someone supervising an AI security system has to notice when it gets something wrong and know enough about the consequences to decide whether to stop it.

Cisco also surveyed 8,000 security leaders across 30 markets and asked what they struggled to find in entry-level candidates. Hands-on experience with AI agents was selected by 49%, technical cybersecurity depth by 48% and human skills by 45%. The numbers are close enough that it makes more sense to read them together: employers want people who understand cybersecurity, know how to work with AI and can make sensible decisions when the technology gets something wrong.

That’s a lot to expect from somebody at the beginning of their career. It becomes even more complicated if AI starts doing some of the work that used to help people gain that experience.

The boring work wasn’t always useless

A lot of work inside a security operations centre is repetitive. Analysts review alerts, clear false positives, check threat intelligence against what’s happening on the network and work through incidents that follow familiar patterns. AI agents can already take on some of that work, and the consortium expects them to do more of it.

There’s no good reason to make a person manually work through thousands of low-risk alerts if software can do it reliably and faster. Security teams have too much work already, and using AI to clear routine tasks can give analysts more time for incidents that actually need their attention.

The catch is that junior analysts learn while doing some of that work. Someone who has looked at hundreds of alerts starts to learn which strange activity is harmless and which tiny detail is worth investigating. They see how rules that look clear in a textbook become much less clear inside a real company with old systems, exceptions and users who don’t always behave as expected.

If AI handles most of the straightforward cases, a human analyst may end up dealing with more of the difficult ones. That makes sense if the analyst already knows what they’re doing. It’s less obvious how someone who is still learning gets enough exposure to become that analyst.

The same issue has come up in law. During an October 2025 Decoder interview with LexisNexis CEO Sean Fitzpatrick, The Verge editor-in-chief Nilay Patel questioned what happens when AI starts doing work that used to go to junior associates.

They were talking about AI generating questions for a deposition. A junior lawyer may not particularly enjoy doing that work, but Patel pointed out that doing it is also part of how someone learns to be a lawyer. He described the risk as “farming out the thinking”, while Fitzpatrick acknowledged that law has traditionally worked as an apprenticeship system.

The comparison with cybersecurity isn’t exact, but the concern is similar. A company can easily count the hours saved when an AI system does work that would have taken a junior employee half a day. It’s much harder to count what that employee would have learned during those hours.

The consortium’s job data shows another change happening at the same time. AI skills appeared in 28.5% of the G7 cybersecurity vacancies it analysed between October 2025 and March 2026, up from 14.2% a year earlier. People trying to get into cybersecurity are therefore being asked to prepare for jobs that are changing before they’ve even had a chance to do them.

South Africa already has this problem

South Africa’s cybersecurity industry doesn’t need G7 hiring data to know that getting into the profession can be difficult. In May, the Institute of Information Technology Professionals South Africa looked at why companies continue to complain about a shortage of cybersecurity workers while graduates struggle to get hired.

IITPSA’s cybersecurity specialists pointed to a gap between what people learn while studying and what companies expect them to be able to do on the job. Universities can teach cybersecurity principles and give students practical exercises, but they can’t recreate every system or incident a graduate will encounter inside a company.

Employers, on the other hand, often want people who can start contributing quickly. Musa Salmamza, Information Security Manager at NTT Data and chairman of the IITPSA Western Cape Chapter, criticised companies that treat hiring as “a procurement exercise instead of a development responsibility”.

Michael de Jager, a lecturer at North-West University, made a related point. Cybersecurity employers say there’s a talent shortage, but entry-level jobs can still require previous experience, certifications and familiarity with enterprise tools. Some of those skills are much easier to acquire once somebody is actually working with enterprise systems.

Companies aren’t unreasonable for wanting people who can handle the job. A mistake during a security incident can have serious consequences, and a small security team may not have someone available to spend months closely supervising a new employee.

But if most employers want someone else to do the training first, there eventually aren’t enough experienced people to hire.

South Africa is already short of them. Cisco’s 2025 Cybersecurity Readiness Index found that 78% of surveyed South African organisations said they didn’t have enough skilled cybersecurity workers, while more than half had over 10 positions they were trying to fill. Only 5% reached Cisco’s highest level of readiness, leaving South African organisations poorly prepared for cybersecurity threats increasingly shaped by AI.

The problem isn’t limited to South Africa either. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that 63% of organisations in sub-Saharan Africa didn’t have the people and skills needed to meet their cybersecurity goals.

This is exactly why companies will use more AI. If a team of five people can investigate far more incidents with the help of agents, a company dealing with a shortage of staff would be foolish not to look at it.

The answer isn’t to keep people doing repetitive work simply because previous generations had to do it. Companies do need to think about what replaces the experience people were getting while doing that work.

Paino argues that students should spend more time auditing and checking the work produced by AI agents. She also calls for more internships, apprenticeships and projects run with industry so that people can get practical experience before they’re expected to work independently.

That requires employers to be involved. A university can build labs and teach someone how an AI security tool works, but there are limits to how closely a classroom can recreate a real organisation with old infrastructure, badly configured systems and people making unpredictable mistakes.

Sooner or later, somebody has to let a new cybersecurity worker learn on real systems. They also need an experienced person around while they’re doing it.

Companies still have to train people

Cisco’s survey asked security leaders what they planned to invest in over the next two years. AI-powered defence was selected by 36% of respondents, while investment in people was selected by 25%. Respondents could choose several priorities, so this isn’t evidence that companies are replacing their staff budgets with AI spending.

It does show why AI will appeal to companies struggling with shortages. Buying software can give a security team extra capacity much faster than hiring a graduate and helping that person become an experienced analyst.

One company making that choice isn’t going to change an industry. If enough companies need fewer junior employees, though, there are also fewer jobs in which those employees can spend the first few years of their careers learning.

Paino expects people to remain responsible for checking AI systems even as agents take over more work. “People remain the final check,” she writes, which means analysts will still have to assess risk, check outputs and decide whether an AI system is making the right call.

The consortium is also seeing more demand for skills such as ethical reasoning, systems thinking and stakeholder engagement. Those aren’t really things someone learns by memorising another set of course material. They improve by making decisions, getting some of them wrong and learning from people who have already dealt with similar situations.

The same issue applies to human oversight of increasingly autonomous AI systems. If an AI agent is working too quickly or handling too many tasks for someone to approve every action, the human role becomes more about knowing when to step in. That only works if the person has enough experience to know what needs their attention.

South Africa also has a jobs problem sitting outside the cybersecurity industry. Youth unemployment among people aged 15 to 34 reached 47.4% in the second quarter of 2026, with five million young people unemployed.

Cybersecurity won’t make a meaningful dent in a number that large by itself. But an industry that says it urgently needs more people should be interested in why it remains so difficult for people to get their first job in it.

That doesn’t mean every cybersecurity graduate is ready to walk straight into a security operations centre. Some qualifications won’t prepare people well enough, and companies shouldn’t lower the standard simply because there’s a skills shortage.

It does mean companies can’t keep treating experience as something a candidate is supposed to acquire somewhere else. If AI changes junior cybersecurity work, training has to change with it.

That could mean more apprenticeships, more time working alongside senior analysts and more deliberate use of AI as part of the training itself. Junior workers can learn to check an agent’s decisions rather than spending years doing every task the agent has replaced.

None of that is free. It requires experienced employees to spend time teaching people, and it requires companies to accept that somebody who is new won’t be as productive as somebody who has been doing the job for five years.

There isn’t a shortcut around that last part. If companies want experienced cybersecurity workers, somebody has to employ them while they’re still inexperienced.

AI can change the work they do during those years. It can probably remove a lot of work nobody will miss. What it can’t do is make the years themselves unnecessary.

Patel’s point about junior lawyers applies here too. Some of the work AI is replacing wasn’t valuable only because of the document, investigation or alert review it produced. Part of its value was the person getting better while doing it.

Cybersecurity employers may eventually need fewer people doing that old junior work but the question of how to turn new people into experienced ones still remains.

Zeen Social Icons