Security2 publishersIndependently confirmed3 min readPublished
AI skills now in 28.5% of security job ads, and the SOC job family is being quietly rewritten
The AI Workforce Consortium says 28.5% of G7 cybersecurity postings required AI skills, up from 14.2% a year earlier. Senior postings grew 65% in six months; junior postings grew 5.9%.
The Watch · Security desk
What happened
- Research by the Cisco-founded AI Workforce Consortium analysed data from recruitment firms Cornerstone and Indeed on cybersecurity job postings across G7 countries.
- 28.5% of cybersecurity job postings between October 2025 and March 2026 required AI skills, up from 14.2% during the same period a year earlier.
- The report was published on August 20.
- The report found an "agentic skill stack" is emerging as a baseline for high-volume cybersecurity roles such as security engineering, cloud security, and detection and response engineering.
- AI systems are assuming high-volume repetitive tasks such as triaging alerts, correlating threat intelligence feeds and executing standard decision-tree workflows, so technical roles such as SOC analysts are becoming less technical and more "human" in nature.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The AI Workforce Consortium reported on August 20 that 28.5% of cybersecurity job postings across G7 countries between October 2025 and March 2026 asked for AI skills, up from 14.2% in the same six-month window a year earlier [11][1][12]. Job ads are where organisational design gets written down before anyone announces a restructure, so this is less a story about tooling than about who is expected to make decisions on a security team next year.
The report, which draws on data from recruitment firms Cornerstone and Indeed, describes an "agentic skill stack" becoming the baseline for high-volume roles including security engineering, cloud security, and detection and response engineering [11][13]. The mechanism it describes for the SOC is specific: AI systems absorb alert triage, threat intelligence correlation and standard decision-tree workflows, and the tier-one analyst moves from doing that work to supervising the systems that do it [2][3]. What is left for the human is validating outputs, assessing risk and judging whether a decision is sound [4]. Security engineers and SOC analysts remain the most in-demand positions [14], so this is a rewrite of the job family rather than a deletion of it.
The soft-skill numbers are the part to read carefully. The consortium logs ethical reasoning up 533% year over year, systems thinking up 251% and stakeholder engagement up 125% in postings [5]. As the secondary coverage notes, those skills are rising from a small base [6], which is what a 533% increase off almost nothing looks like.
The pipeline arithmetic is where consequence bites. Overall cybersecurity demand across the G7 rose 9.5% for the six months ending March 2026 [15], but senior-titled postings grew 65% while junior-titled postings grew 5.9% [7] - senior demand growing roughly eleven times faster than junior demand [21]. In a Cisco survey in May 2026, security leaders named the hardest competencies to find in entry-level candidates as hands-on experience with AI agents (49%), technical cybersecurity depth (48%) and human-centric professional skills (45%) [8]. That is an employer asking for supervisory judgment from people who have not yet been given the repetitive work that historically produced it. The report's own recommendation is experiential: lab exercises where students audit and critically evaluate AI-agent output, plus more internships and apprenticeships [16].
Provenance matters here. The consortium was founded in 2024 by Cisco alongside Accenture, Cornerstone, Eightfold AI, Google, IBM, Indeed, Intel, Microsoft and SAP [9], with a stated goal of upskilling 130 million people over a decade [10]. The demand data comes from two member firms, and the finding is that the market wants more of what members sell and teach. The direction still matches other evidence in the report: AI-powered defence is the top investment priority for 36% of leaders [17], the report cites a cyber-espionage campaign orchestrated using Anthropic's Claude and an autonomous ransomware operation documented by Sysdig [18], and the Five Eyes agencies have warned that the timeline on frontier model risk is months rather than years [19]. IBM's Cost of a Data Breach Report 2025 found higher breach costs at organisations with weak AI governance or significant shadow AI use [20].
Watch whether junior postings recover in the next six-month cut, or whether the gap widens. Watch whether "validate AI agent output" starts appearing as an assessable requirement with a rubric attached rather than a line in a job ad. And check your own escalation ladder: if triage is automated, name the person who signs off when an agent contains a host, and say what they are allowed to reverse.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence52
- Adoption58
- Hype gap+22
- Incentives74
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
28.5% of cybersecurity job postings between October 2025 and March 2026 required AI skills, up from 14.2% during the same period a year earlier.
- [2]
AI systems are assuming high-volume repetitive tasks such as triaging alerts, correlating threat intelligence feeds and executing standard decision-tree workflows, so technical roles such as SOC analysts are becoming less technical and more "human" in nature.
- [3]
Roles like the tier-one SOC analyst are being reshaped, shifting from manual triage to supervising AI agents.
- [4]
Workers in these positions have taken on more strategic and oversight functions such as validating outputs, assessing risk and ensuring decisions are sound.
- [5]
Postings show growth in strategic and human skills: ethical reasoning up 533% year over year, systems thinking up 251% and stakeholder engagement up 125%.
- [6]
Ethical reasoning and systems thinking are increasingly listed as required skills, though from a small base.
- [7]
Senior cybersecurity postings grew 65% between October 2025 and March 2026, while junior-titled roles rose only 5.9% over the same period.
- [8]
In a May 2026 Cisco survey, security leaders cited the three competencies hardest to find in entry-level candidates as hands-on experience with AI agents (49%), technical cybersecurity depth (48%) and human-centric professional skills (45%).
- [9]
The AI Workforce Consortium was founded in 2024 by Cisco alongside Accenture, Cornerstone, Eightfold AI, Google, IBM, Indeed, Intel, Microsoft and SAP.
- [10]
The consortium aims to upskill 130 million people over the next decade.
- [11]
Research by the Cisco-founded AI Workforce Consortium analysed data from recruitment firms Cornerstone and Indeed on cybersecurity job postings across G7 countries.
- [13]
The report found an "agentic skill stack" is emerging as a baseline for high-volume cybersecurity roles such as security engineering, cloud security, and detection and response engineering.
- [14]
Technical roles such as security engineers and SOC analysts remain the most in-demand cybersecurity positions.
- [15]
Demand for cybersecurity roles rose 9.5% across G7 countries for the six-month period ending in March 2026.
- [16]
The report recommends rethinking teaching through experiential learning and lab exercises where students audit, validate and critically evaluate AI agent-generated outputs, plus more internships, apprenticeships and industry-sponsored projects.
- [17]
Investment priorities for the next two years show AI-powered defence as the top choice for 36% of leaders.
- [18]
The report references recent AI-driven cyber incidents, including a cyber-espionage campaign orchestrated by Anthropic's Claude model and a fully autonomous ransomware operation documented by Sysdig.
- [19]
The Five Eyes cybersecurity agencies issued a joint warning on the rapid advancement of frontier AI models, saying the timeline for potential risks is measured in months, not years.
- [20]
IBM's Cost of a Data Breach Report 2025 found that organisations with weak AI governance policies or significant shadow AI usage face higher breach costs.
- [21]
Senior posting growth of 65% is about 11 times the junior posting growth of 5.9%.
Sources
2 independent publishers whose own reporting we read for this story.
- infosecurity-magazine.comCybersecurity Job Ads Requiring AI Skills Double
1 article · August 21, 2026
- scworld.comAI skills in cybersecurity jobs double, but junior hiring lags
1 article · August 20, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.