56%
Report AI has reduced the need for entry-level roles over the past year
41%
Cite AI as their single most pressing cybersecurity skill need
75%
Of hiring managers planned to hire more cybersecurity professionals in 2025

SponsoredHorizon3.ai

Proactive Security for the AI Era

NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.

See NodeZero WebApp in action

A single statistic from ISC2's ongoing workforce research has been circulating in security hiring conversations this year: 56 percent of cybersecurity professionals say AI has somewhat or significantly reduced the need for entry-level positions over the past year. Read on its own, that number reads like confirmation that AI is quietly hollowing out the bottom of the security career ladder, the same Tier 1 alert triage and report writing work that has traditionally been how analysts break into the field.

The same body of ISC2 research does not actually support the flat "AI is cutting entry-level jobs" framing, though. In the same survey data, 44 percent of respondents report no impact on entry-level hiring from AI adoption at all, and 28 percent say AI is creating new opportunities for entry-level talent rather than closing them off. Meanwhile ISC2's broader 2025 Cybersecurity Workforce Study, a separate but related survey of 16,029 cybersecurity professionals published in December 2025, found budget cuts (36 percent) and layoffs (24 percent) affecting the workforce broadly, alongside skill gaps so widespread that 95 percent of respondents report at least one unmet skill need. AI is one pressure on entry-level hiring among several, not an isolated force acting alone, and the honest reading of the data is a workforce that is split roughly down the middle rather than one undergoing a wholesale collapse of its junior tier.

This matters for anyone building a hiring plan, because reacting to the headline version of this finding by freezing junior hiring or assuming certifications alone will fix the pipeline is not what the underlying research actually recommends. Below is what ISC2's research genuinely shows about AI and entry-level hiring, what else is driving the same pressures, and how to adjust your own hiring and junior-analyst development plans against the real data rather than the shorthand version of it.

What ISC2's Research Actually Found on AI and Entry-Level Roles

The 56 percent figure comes from ISC2 survey research on AI adoption and hiring, covered in ISC2's own reporting and in outlets including Infosecurity Magazine and PR Newswire's coverage of ISC2's findings on cautious AI adoption across security teams. The finding itself is specific: a majority of surveyed security professionals say AI has "somewhat or significantly" reduced the need for entry-level positions over the past year, and the mechanism they point to is concrete, AI tools taking over tasks that have historically been the on-ramp into a security career, particularly alert triaging and first-pass report writing.

That is a real and worth-taking-seriously finding. It is also not the whole picture from the same research. Alongside it: 44 percent of respondents report no impact on entry-level hiring from current or expected AI adoption, and 28 percent say AI is creating new opportunities for entry-level talent rather than eliminating them, most plausibly in AI oversight, prompt and output review, and the growing set of AI-security-specific tasks covered below. Those numbers do not average out to "AI is not a factor." They average out to a workforce whose own practitioners are genuinely divided on the direction and magnitude of the effect, which is a meaningfully different planning problem than a one-way contraction.

The Broader Workforce Study Context: Budget and Skills Pressure, Not Just AI

ISC2's flagship 2025 Cybersecurity Workforce Study, based on 16,029 respondents and published in December 2025, is the study most people mean when they say "the ISC2 workforce study," and its headline findings are about budget and skills, not primarily about AI displacement. The study found that 36 percent of organizations reported budget cuts (essentially flat versus 2024) and 24 percent experienced layoffs. At the same time, 95 percent of respondents report at least one unmet skill need, and 59 percent describe that need as critical or significant, up 15 percentage points from the prior year.

Read against the entry-level AI finding above, this context matters: a hiring manager who cut a junior req in 2025 was as likely to be responding to a flat or shrinking budget and a mandate to backfill hard-to-find senior or specialized skills as to any specific decision that "AI now does that job." ISC2's own leadership framing in the December 2025 study release leans toward this more mixed read as well, describing AI as "perceived as less of a threat to the workforce than anticipated," with many respondents viewing it as an opportunity for career advancement rather than a threat to their own role. Treating every 2025-2026 hiring slowdown as AI-caused risks misdiagnosing a problem that is at least partly budget and skills-gap driven, and building the wrong fix for it.

Free daily briefing

Briefings like this, every morning before 9am.

Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.

The Entry-Level Bar Is Moving Toward AI Literacy, Not Just Shrinking

ISC2's 2025 Workforce Study also found that AI is now the single most cited skill need in the field: 41 percent of respondents name it as their most pressing skill gap, ahead of any other category. Within that, respondents ranked specific AI-related needs by importance: AI in threat detection and response (42 percent), defending AI models from attack (35 percent), securing AI integrations in cloud and edge deployments (31 percent), and AI governance and policy implementation (30 percent).

That pattern is hard to reconcile with a simple story of AI eliminating junior work outright. It reads more like a shift in what junior work consists of: fewer entry-level hours spent on manual first-pass alert triage that a tool now handles reasonably well, and a growing expectation that even junior hires understand how to review, validate, and act on AI-generated output rather than only human-generated ones. A junior analyst who can competently sanity-check an AI triage verdict, flag a wrong one, and explain why is doing work that is different from, not smaller than, the entry-level job of five years ago. This is the same logic covered in our comparison of AI-powered SOC tools and our review of autonomous AI SOC analyst agents from Dropzone AI, Radiant Security, and Prophet Security: these tools change what a human in the loop needs to know how to do, they do not remove the need for a human in the loop.

Hiring Managers Are Still Investing in Junior Talent, According to ISC2's Own Data

If AI adoption were simply closing off the entry-level tier, ISC2's own hiring-focused research would be expected to show hiring managers pulling back from junior investment. It does not. ISC2's June 2025 report on entry- and junior-level hiring, based on a survey of 929 hiring managers across Canada, Germany, India, Japan, the UK, and the US fielded in December 2024, found that 75 percent of hiring managers planned to hire more cybersecurity professionals in 2025, and nearly 90 percent had open positions at the time of the survey.

That same report shows hiring managers are still spending real money to develop junior talent rather than writing off entry-level hiring as obsolete: 45 percent reported spending between $1,000 and $4,999 to train an entry-level hire, with 31 percent spending under $1,000, figures that reflect a workforce still actively bringing junior analysts in and investing in their ramp-up rather than one that has stopped hiring at that level. Taken together with the AI-and-entry-level finding, the more defensible read is that hiring managers are adjusting what they expect a junior hire to already know and what they train them on, not abandoning the junior tier altogether.

What This Means for Your Hiring Pipeline and Analyst Development Plan

Given what the actual data supports, three adjustments are more defensible than either ignoring the AI finding or treating it as proof the entry-level SOC job is disappearing.

First, redefine what an entry-level SOC role actually covers before you decide whether to cut it. If your Tier 1 job description is still built entirely around manual first-pass alert triage, you are hiring against a task an AI tool may already be doing reasonably well, and you risk both a bad hire (someone whose only skill is a task being automated) and a bad automation rollout (no human positioned to catch the tool's mistakes). Rewrite the role around AI-output review, escalation judgment, and the specific AI-security skills ISC2 respondents ranked highest (threat detection tuning, model defense awareness, cloud AI integration security) rather than the pre-AI version of the job. Our SOC staffing guide covering analyst tiers, headcount models, and shift coverage and our guide to building a SOC from scratch both work from the assumption that tier definitions need to be deliberately designed rather than inherited, which is exactly the exercise this data calls for.

Second, do not use the 56 percent figure to justify freezing junior hiring outright, since the same research shows 44 percent of your peers seeing no such effect and hiring managers overall still actively recruiting and training at that level. If your organization has a genuine budget or headcount constraint, name it as that, rather than backing into a junior hiring freeze under the banner of "AI made this role obsolete" when the broader data does not support that as a universal conclusion.

Third, treat mentoring and structured development as the differentiator ISC2's own leadership points to, not an afterthought. ISC2 CEO Clar Rosso's public framing of this research has emphasized using AI to remove repetitive work while deliberately preserving the learning and mentoring opportunities that used to come bundled with that repetitive work by default. If a junior hire is no longer learning triage fundamentals by doing hundreds of manual alerts, someone has to design a substitute path, whether that is structured shadowing of AI-assisted investigations, deliberate rotation through the AI-security skill areas the study flags as highest-demand, or a formal mentoring program that does not depend on volume-based repetition to build judgment.

The bottom line

The real ISC2 research does not support a simple headline that AI is cutting entry-level cybersecurity jobs. A slim majority of surveyed professionals do report AI reducing the need for entry-level roles, but a similarly large share report no impact, and a meaningful minority see AI opening new entry-level paths, while ISC2's own hiring-manager data shows most organizations still actively hiring and investing in junior talent. The defensible response is not to freeze entry-level hiring or assume it will disappear on its own, it is to redesign the entry-level role around AI-output review and the specific AI-security skills the same study shows are now in highest demand, and to build mentoring and development paths that do not depend on the manual, repetitive alert volume that used to teach junior analysts their craft by default.

Frequently asked questions

Does the ISC2 workforce study show AI is cutting entry-level cybersecurity jobs?

Partially. ISC2 research finds 56 percent of professionals report AI reduced entry-level hiring need, but 44 percent report no impact and 28 percent see AI creating new entry-level opportunities, so the data shows a divided workforce, not a wholesale collapse of entry-level roles.

What specific entry-level tasks does ISC2's research say AI is affecting?

The research points to alert triaging and first-pass report writing, tasks that have traditionally been the on-ramp into a SOC career and that AI tools are now able to complete, which is why entry-level role definitions built solely around those tasks need to be reconsidered.

Is the broader cybersecurity workforce shrinking because of AI, according to ISC2?

No. ISC2's December 2025 Cybersecurity Workforce Study, covering 16,029 respondents, attributes most workforce pressure to budget cuts (36 percent) and layoffs (24 percent), alongside skill gaps affecting 95 percent of respondents, with AI cited as one factor among several rather than the dominant cause.

Are hiring managers still investing in entry-level and junior cybersecurity talent?

Yes. ISC2's June 2025 hiring trends report, based on 929 hiring managers, found 75 percent planned to hire more professionals in 2025 and nearly 90 percent had open positions, with most spending $1,000 to $4,999 to train entry-level hires.

What AI skills does ISC2 say cybersecurity teams need most right now?

AI ranked as the single most cited skill need at 41 percent, with respondents specifically prioritizing AI in threat detection and response (42 percent), defending AI models from attack (35 percent), securing AI integrations in cloud and edge environments (31 percent), and AI governance (30 percent).

How should a security team adjust its hiring pipeline based on this data?

Redesign entry-level roles around AI-output review and the highest-demand AI-security skills rather than manual triage alone, avoid freezing junior hiring based on a single statistic that the same research contradicts, and build mentoring paths that do not depend on high-volume manual alert work to develop judgment.

Sources & references

  1. ISC2: 2025 ISC2 Cybersecurity Workforce Study
  2. ISC2: ISC2 Study Finds Cybersecurity Budget Constraints Remain, But Do Not Worsen, While Skill Needs Grow
  3. ISC2: 2025 Cybersecurity Hiring Trends: Why Investing in Entry- and Junior-Level Talent Is Key
  4. ISC2 via PR Newswire: ISC2 Research Reveals Cybersecurity Teams Are Taking a Cautious Approach to AI Adoption
  5. Infosecurity Magazine: Hiring for the AI Era: A New Challenge for CISOs

Free resources

25
Free download

Critical CVE Reference Card 2025–2026

25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.

No spam. Unsubscribe anytime.

Free download

Ransomware Incident Response Playbook

Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.

No spam. Unsubscribe anytime.

Free newsletter

Get threat intel before your inbox does.

50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.

Unsubscribe anytime. We never sell your data.

Eric Bang
Author

Founder & Cybersecurity Evangelist, Decryption Digest

Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.

Giveaway: InfoSec World 2026 All Access Pass ($3,895 value)

Details →
Daily Briefing

Subscribe to enter the giveaway

Every subscriber is automatically entered. You also get daily threat intel every morning: zero-days, ransomware, and nation-state campaigns. Free. No spam.

Already subscribed? You're already entered.

Giveaway

Win a $3,895 InfoSec World 2026 pass.