Last week, I tested whether an average AI model can pass the CISSP exam-style questions I created. As we now know, all three tested models scored 150/150.
Not one wrong answer.
If you’re trying to break into this field, that number probably hit you in the stomach.
You’ve spent months studying. Maybe you paid for courses. Maybe you’re about to spend €700+ on an exam. And a free chatbot just answered every question perfectly.
So the thoughts start:
Why would anyone hire me when AI already knows all this?
Am I preparing for a job that won’t exist in two years?
Should I even keep going?
I get it. And I’m not going to tell you the fear is stupid, because part of it is real.
But most people are panicking about the wrong thing.
Let’s separate what you should actually worry about from what you shouldn’t.
What you can expect from this article
Why passing an exam and doing the job are not the same test
What AI actually changed about entry-level hiring, and what it didn’t
The one skill that got more valuable, not less, because of this
Why I think AI passed so easily
Look at how an exam question is built.
A clear scenario.
Four options. Multiple technically correct answers, but only one BEST answer. Everything you need is inside the question somewhere.
That’s exactly what AI is built for. That’s where it thrives.
Now look at the same situation at work.
Exam version:
“A user reports a suspicious email requesting an urgent wire transfer. What should the security professional do FIRST?”
Real version:
A Slack message from the CFO’s assistant. It has a screenshot, not the original email. The CFO is on a flight. Finance wants to pay the invoice today because the vendor is “critical.” And nobody knows if this vendor changed banks last month.
AI answers the first one in two seconds.
The second one has no four options. Nobody tells you what the question is. You have to:
Figure out what you’re actually looking at
Work out what’s missing and who has it
Decide what matters more: stopping the payment or keeping the business running
Explain your decision to people who don’t care about security
The exam tests whether you know the answer. The job tests whether you can figure out what the question is.
So let’s stop confusing passing an exam with being a good cybersecurity professional.
So, should you panic or not?
So am I saying that you shouldn’t be worried? Not really.
The whole industry is changing, there is no doubt about that.
Pretending otherwise would be lying to you.
Some tasks that used to fill a junior’s week now take minutes:
First drafts of policies and procedures
Explaining what a log line or alert means
Summarizing a CVE
Writing a quick script to parse a file
Answering “what does this acronym mean?”
If your plan was to get hired to do only these things, you have a problem.
But in my personal opinion, if you’re reading this, that was never your goal.
On the other hand, thanks to AI, the number of attacks is increasing rapidly. So many vulnerabilities can now be exploited basically for free.
And that also means you need more and more people who continue to monitor your network.
Yes, AI helps analysts spot anomalies. But anyone who has ever run a SIEM or XDR knows the tool doesn’t make the call. You still need an analyst who can decide whether an alert actually matters.
And that’s the pattern. AI changed the tasks. It didn’t change who’s responsible:
Someone has to own the risk: “The chatbot said it was fine” doesn’t pass an audit.
Someone has to know the environment: AI doesn’t know your undocumented legacy server.
Someone has to check the output: A fluent wrong answer is more dangerous than an obvious one.
The skill that just got more valuable
For years, knowledge set you apart. Ports, frameworks, acronyms.
Now answers are free. What’s scarce is the ability to judge them.
And you can’t judge what you don’t understand.
Say AI tells you to block an IP that’s generating strange traffic. It’s confident. It even writes the firewall rule for you.
But what if that IP is your own email gateway? Or a partner integration finance depends on?
Plausible answer, but completely wrong for your environment.
The junior who catches that gets hired. The one who copies and pastes it is a liability.
So remember: AI doesn’t make fundamentals less important. It makes them even more important.
The real question
This brings me back to one of my past ideas: entry-level cybersecurity jobs don’t really exist.
Even junior cybersecurity roles expect experience in IT or another relevant field.
So maybe the real question isn’t whether AI will take entry-level cybersecurity jobs.
It’s whether AI can take something that may never have existed in the first place.
The path in was always the same: build real fundamentals, then move into security. AI didn’t change that. It just made skipping them far more difficult.
Want a step-by-step plan for your first role? The 90-Day Cybersecurity Job Blueprint shows you what to learn, what to build, and how to prove it to employers, week by week.
Conclusion
I don’t think AI is coming for entry-level cybersecurity jobs. I think it’s coming for the version of the job that was already the weakest way to break in: pure recall, no judgment, nothing you actually built yourself.
That’s not a reason to panic. It’s a reason to stop preparing for a job that was disappearing anyway, and start preparing for the one that’s actually available.
If you’re trying to figure out exactly which path to prepare for and what to actually study first, that’s precisely what the 90-Day Cybersecurity Job Blueprint walks you through, path by path, without wasting a year on the wrong certifications.
Tell me in the comments which role you’re aiming for (SOC, GRC, cloud, or something else). I’ll reply with the one fundamental I’d go deep on first.
Let’s Connect
If you want to collaborate, discuss, or just geek out over networking and cybersecurity, reach out:
Email: erich.winkler@decodedsecurity.com
LinkedIn: Erich Winkler
Gumroad community: Decoded Security
Start Here: Decoded Security Roadmap
Enjoyed this article? Like it or drop a comment. I’d love to hear your thoughts and questions!
Let’s learn and grow together!







I definitely think there will be an impact on entry level jobs in cybersecurity, but I also feel that this entry level group is also best positioned to confront this situation, it’s very easy for them to learn AI skills and quickly convert their roles into an AI enabled role, so if someone is targeting to become app security tester and defender, instead of writing own exploits, they can quickly learn to use AI to create the exploits and they spend time in refining the output
But I also think that invariably the number of positions will become less at entry level, because even if everyone has these skills, the number of humans required to do the job will come down. This is definitely the reality
I don’t really know where this is going. I’m very sceptical that AI works financially as an industry, and I suspect that in any case it’ll become politically unacceptable long before it becomes technically unstoppable. But on the question of AI replacing low‑level cybersecurity roles, there’s an obvious problem: how can an AI be held responsible if it messes up? Cybersecurity is a risk profession. Someone must be accountable for decisions. AI can assist, but it cannot own a decision. Can it? And will people try to use it to dodge responsibility?
“Ah, yes, the AI did that. Bit moody this week.” "The AI told me to do it. In fact, it insisted."
Where exactly does an AI fit in a responsibility matrix?
More likely is that — just like legacy automation — it lets teams do more with less time. But the roles themselves still need to exist, because otherwise… where do the future leaders come from? Or will they be replaced too in time?