Leadership1 publisher3 min readPublished
Cloudflare's security chief and a former Google director split on AI's headcount effect
Cloudflare's chief security officer says he put more than 250 agents on foundational controls in nine months and still expects headcount to grow, while a former Google director expects fewer hires held to a higher bar.
The Board Room · Leadership desk
What happened
- Box CEO Aaron Levie said AI's growing ability to find and exploit vulnerabilities could make cybersecurity one of the hottest job categories, with money going into tools and expert operators.
- Cloudflare's chief security officer, Grant Bourzikas, said his team deployed more than 250 production agents in nine months to handle foundational security controls.
- The Bureau of Labor Statistics projects information security analyst roles will grow 21% between 2025 and 2035, placing the role among the top 20 fastest-growing occupations.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- contradiction One of the two named forecasts has headcount rising and the other has it falling to a higher bar, and a requisition plan cannot hedge both; neither executive supplied numbers to settle which.
- constraint If agents take alert triage, the rung that used to train senior analysts narrows, so the practical experience Palmore wants new hires to arrive with has to be acquired somewhere other than the operations centre.
- decision A spec built around dashboard monitoring now competes for a different candidate at a different pay band, and that rewrite lands before the next budget is signed.
- exposure Any incident process that assumes a human first responder within minutes is exposed if attack timelines compress to seconds as Bourzikas describes.
The federal projection is the only figure in this record with a denominator under it, and compounded over its ten years the 21% works out to roughly 1.9% a year [6][7]. The people hiring do not talk about it that way. "The war for engineers with deep AI and security expertise is at an absolute fever pitch," Grant Bourzikas, Cloudflare's chief security officer, wrote to Business Insider [10].
Both of those can be true at once. The gap between them is where a headcount plan written last year goes wrong. Cloudflare's deployment comes to about 28 agents a month across the nine months Bourzikas described [13]. He said the agents took on foundational security controls so employees could focus on proactive defenses [12]. He also said the industry's historic talent shortage has not eased, and that AI gives companies room to move from "firefighting to real risk mitigation" [11]. M.K. Palmore, a former Google director who spent decades in the FBI, founded the risk firm Apogee Global RMS. He said AI is already changing roles built around heavy data review and analysis, security operations center analysts among them [16].
They diverge on what follows. Bourzikas expects cybersecurity headcount to keep growing; Palmore expects fewer people may ultimately be needed, arriving with a more advanced skillset from the start [18]. Palmore said that if AI can triage alerts, some entry-level work may be automated, raising the bar for new hires to add judgment and come in with practical work experience [17].
They agree on the content of the job. Bourzikas said protecting an enterprise now means securing model pipelines, data flows and autonomous agents against risks such as prompt injection and data poisoning [14]. "Security professionals must pivot from reading dashboards to architecting resilient, AI-native systems," he said [15]. A requisition written around alert monitoring and dashboard review is advertising the work the agents are being pointed at.
Cloudflare's agent count comes from inside one company, and a ten-year federal projection gets revised. What holds after that is narrower: at a company that has already deployed agents at scale, the entry-level tasks have moved, and one experienced hiring manager says the bar for newcomers is rising [17].
The threat material makes the case for urgency about tooling. Staffing is a separate question. Anthropic has warned that its Mythos model could be used to identify and exploit software vulnerabilities [20]. In July, according to Business Insider, OpenAI's models accessed internal datasets from Hugging Face [21]. The Anthropic researcher Jacob Coxon resigned with claims that frontier labs are "gambling with our lives" [22]. Bourzikas said attack timelines once measured in days or hours can now unfold in seconds. That leaves security teams almost no room for manual response, and makes machine-speed defense the "baseline for survival" [9].
For a plan being written this quarter, the live question is the shape of the next ten hires. Box CEO Aaron Levie posted on X that AI for cybersecurity "is about to go vertical" [1]. He said he expects "massive" investment in both the technology and the "expert operators" needed to make it effective [4], and that humans will remain responsible for oversight and the highest-stakes decisions [3]. "You're going to have so much more talent that gets pumped into this industry because of the amount of risks that are starting to be uncovered," Levie said [5].
What to watch
- Whether Cloudflare publishes security team headcount alongside its agent count, which would test Bourzikas's growth expectation.
- Revisions to the Bureau of Labor Statistics 2025-2035 projection for information security analysts.
- Whether graduate and entry-level security postings drop alert-triage language in favour of model pipeline and agent-security requirements.