Blog / AI Security Roles: Why the Skills Gap Beat the Headcount Gap

AI Security Roles: Why the Skills Gap Beat the Headcount Gap

    Cybersecurity hiring is shifting from more headcount to different skills. Here's what that means for AI security roles, hiring managers, and engineers planning their next move.

    Cybersecurity teams don't just need more people anymore. They need different people. Security leaders are finding that staff without AI-specific skills can't secure AI systems, validate automated outputs, or govern how models get used. That mismatch, not an empty headcount line, is now the bottleneck.


    You've felt this if you're hiring right now. You post a cybersecurity role. You get plenty of applicants. Almost none of them can talk credibly about securing an AI pipeline or reviewing what a model actually did.


    That's not a sourcing problem. That's a market shift. And it changes how hiring managers write job specs, and how engineers plan their next career move.

    Why the old talent shortage story doesn't hold up anymore

    For years, "we can't find cybersecurity people" meant one thing: not enough bodies. That framing is outdated. The real issue now is capability, not capacity.


    SANS research puts numbers on this. 60% of organizations now say the lack of the right skills is the bigger problem, versus 40% who point mainly to too few staff, according to SANS/GIAC research. That's a full reversal from how this problem used to get described.


    "It's really not a shortage that we have anymore, it's a mismatch," said a global cybersecurity strategy and risk lead at a major consulting firm, as reported by Axios.

    Here's the practical fallout: 27% of organizations report breaches tied directly to capability gaps, per the same SANS/GIAC data. Not a lack of tooling. Not a lack of budget. A lack of the right people doing the right checks.


    For a hiring manager, this means your job description from two years ago is probably wrong. For an engineer, it means the skills that got you hired last time might not be the ones that get you hired next.

    What's driving demand for AI-native security roles

    Companies are creating brand-new security job titles because the old ones don't cover what needs protecting. AI systems have their own attack surface, and someone has to own it.


    72% of organizations are creating or filling new AI-related security roles, according to a recent SANS-linked report. The specific titles gaining ground: AI/ML security specialist (34%), AI security engineer (32%), and AI governance analyst (30%).


    This isn't a rebrand of existing jobs. It's new scope. Someone now needs to test whether a model can be manipulated, whether its outputs can be trusted, and whether the whole pipeline, from training data to deployment, holds up under attack.


    Fortinet's global skills-gap report backs this up from the hiring side: 60% of respondents cite finding cybersecurity talent with specific AI experience as their top recruiting challenge. That's not a niche complaint. That's the majority of security leaders naming the same gap.


    We see this in our own intake calls. A hiring manager wants a "security engineer." Ten minutes in, it turns out they need someone who understands both classic infrastructure security and how large language models get attacked. That's a different search than it was eighteen months ago.

    The skills that actually separate candidates now

    Hands-on AI experience beats theoretical knowledge, and hiring teams are struggling to find it at any level, including entry-level.


    Cisco surveyed 8,000 security leaders and found the hardest entry-level competencies to hire were hands-on experience with AI agents (49%), technical cybersecurity depth (48%), and human-centric professional skills like clear communication (45%).


    Job ads reflect this shift directly. Cybersecurity postings demanding AI skills have doubled in a year, according to reporting covered by SC World, with recurring requirements including Python, prompt and context engineering, agent orchestration, and MLOps.


    The engineers who stand out added AI-specific depth on top of solid fundamentals, rather than trading their old skills for AI buzzwords. Cloud security, identity and access management, incident response, threat detection: none of that went away. It just got paired with a new layer.


    If you're an engineer weighing your next move, that combination is worth building deliberately. A cloud security engineer role that also touches AI pipeline defense is a stronger long-term bet than a narrow specialism in either direction alone.

    Why governance and compliance roles are becoming security jobs

    Security hiring is expanding past pure engineering into oversight and risk. That's a real shift in what counts as a "security role."


    63% of respondents in Fortinet's research expect they'll need more AI oversight and governance roles within three years. That means compliance and risk functions are becoming core hiring lanes for security teams, not side functions handled by legal.


    In the EU, this lines up with what NIS2 is already pushing companies to prove: stronger cyber risk management, governance, and incident readiness. In the Netherlands, that pressure is especially relevant for firms building AI-enabled products or falling under NIS2 scope, and it's changing what "security hire" means on a job req.


    Practically, this means security engineering, GRC (governance, risk and compliance), privacy, model risk, and DevSecOps are converging into overlapping profiles. A candidate who can bridge legal, operational, and technical domains is no longer a rare edge case. That's becoming the job.


    An information security analyst today is expected to understand model risk, not just network logs. That's a wider brief than the same title carried a few years back.

    What delayed hiring actually costs a business

    An unfilled AI security role isn't just an HR line item. It slows down product timelines and increases exposure to attacks that specifically target AI systems.


    57% of organizations report delayed projects because of the skills shortage, according to the same SANS-linked report cited above. That's not abstract. That's a launch pushed back, a compliance review stuck in queue, a model shipped without proper adversarial testing because no one on the team had time to run it.


    The risk compounds as AI gets embedded deeper into SOC workflows and business processes. Without the right people validating outputs, teams face slower AI deployment, weaker model governance, more exposure to adversarial attacks, and a heavier burden on whoever's left doing incident response.


    Companies that build hiring plans around hybrid profiles, and invest in training current staff on AI threat modeling, are the ones adapting fastest. Waiting for the "perfect" AI security hire to appear fully formed is a losing strategy. Building the skill in-house while hiring for it externally works better.

    How Doghouse approaches AI security hiring

    We don't send you ten CVs and hope one sticks. For a role this specific, that approach fails fast, because the market for AI security talent is too thin to spray-and-pray your way through it.


    Our Delivery Sprint process starts with a real intake: what does this role actually need to defend, what's the AI maturity of the team, what governance load comes with it. That shapes sourcing before a single candidate gets approached.


    We're not chasing volume. We're chasing fit. A senior recruiter who understands the difference between an infrastructure software engineer profile and one built for AI-native security work saves everyone weeks of wasted interviews.


    That's the whole idea behind niche bemiddeling: fewer, better matches, delivered by people who've done the homework on the role before the first call happens.

    Frequently asked questions
    Is AI security a good career choice?

    Yes. Demand is rising fast: 72% of organizations are creating new AI security roles, and 60% of employers say AI-specific skills are their top recruiting gap. Building this expertise now puts you ahead of a market that's still catching up.

    What skills do AI-native cybersecurity roles require?

    Core requirements include AI/ML security knowledge, LLM attack and defense understanding, agent orchestration, MLOps, prompt and context engineering, and Python for security automation, layered on top of classic skills like cloud security and incident response.

    How is AI changing hiring in the cybersecurity sector?

    Hiring is shifting from headcount to capability. Job ads demanding AI skills have doubled in a year, and new titles like AI security engineer and AI governance analyst are emerging as standard roles rather than experiments.

    Where can companies find qualified AI security talent?

    Through recruiters who understand both the tech stack and the AI-specific attack surface well enough to properly screen for it, rather than matching on keywords. A structured intake process that maps the actual role, before sourcing starts, finds better fits faster.

    Conclusion

    The cybersecurity hiring problem changed shape. It's not about finding more people anymore. It's about finding people who can secure, govern, and validate AI systems, on top of the fundamentals that never stopped mattering.


    That shift rewards engineers who build hybrid depth and hiring managers who write specs that reflect it. It punishes anyone still hiring, or job-hunting, like it's 2022.


    If you're building an AI security function or wondering where your own skill set fits next, that's exactly the kind of conversation worth having early, not after the role's been open for three months.

    Sources
    1. [PDF] 2026 Cybersecurity Skills Gap Global Research Report - Fortinet
    2. The cybersecurity workers employers want are in short supply
    3. AI-related job cuts mostly hit entry-level roles, as AI skills become essential
    4. The Cybersecurity Talent Shortage Narrative Is Wrong. ...
    5. AI Cybersecurity Skills Gap: Career Paths & Skills You Need
    6. Beyond hiring: tackling the cybersecurity skills gap in the age of AI

    Written by our AI, read by a flesh-and-blood recruiter.