The field · 9 min read

Entry-level cyber security jobs: the first rung is thinning

The work that turns a graduate into a defender is the work being automated first. Someone still has to name the people climbing without it.

The job that teaches a defender how to defend is the one being automated first.

ISC2 surveyed 856 cyber security professionals in May 2026 and published the results on 14 July under the title Rethinking AI’s Impact on Cybersecurity Roles. The line that matters for anyone starting out sits early in it. A majority of participants, 56 per cent, said that AI has somewhat or significantly reduced the need for entry-level positions over the past year. Nineteen per cent reported little or no impact. Twelve per cent said the need had gone up.

Those are practitioners describing their own organisations, and the figure gets read as a hiring story. It is a supply story. Entry-level cyber security jobs are where senior defenders are manufactured, slowly, out of repetition and small mistakes. Remove the rung and nothing breaks this year. It breaks around 2031, when the analysts who should have been promoted into the hard seats never got the five thousand boring alerts that would have qualified them.

56%
of cyber security professionals said AI has somewhat or significantly reduced the need for entry-level positions over the past year.
ISC2, Rethinking AI’s Impact on Cybersecurity Roles, published 14 July 2026. Survey of 856 professionals, fieldwork May 2026.

What the first rung actually taught

Ask any threat hunter where they learned the thing they are best at and you will rarely hear a course name. You hear a queue.

The junior seat taught volume. Two hundred alerts in a shift, nearly all of them nothing, and by month four the analyst can tell at a glance which ones are nothing. That is not a skill anyone can describe on a slide. It is pattern memory, built the only way pattern memory gets built, by seeing thousands of benign events until the malformed one looks wrong before the reasoning catches up.

It taught the estate. Which team deploys on a Thursday, which contractor VPNs in from three countries legitimately, which finance server has always made that odd outbound call because of a 2014 integration nobody will admit owning. None of this exists in a log. It lives in the heads of people who have been there long enough to ask.

It taught being wrong somewhere safe. A first-year analyst escalates something embarrassing, a senior explains why it was nothing, and the lesson lands without a customer ever knowing. Analysts pay a much higher price for that lesson later on. The first rung was where they could afford it.

And it taught the social mechanics: when to phone rather than ticket, how to tell an executive their account is compromised without causing a panic, what to write down at 03:00 so the morning shift can pick it up cold. Those habits transfer to every senior role in defence, and every one of them was learned while doing work that a model can now summarise in a second.

The same survey argues with itself, and the argument is worth reading

Any piece that stops at 56 per cent is quoting selectively. ISC2 asked several questions around it, and the rest of the answers complicate the story properly.

Over half of participants, 53 per cent, believe AI is creating new types of entry-level role. Nearly half, 48 per cent, said AI has made them feel more optimistic about their long-term careers in cyber security. Nearly two-thirds, 62 per cent, do not believe AI has reduced the need for foundational cyber security skills, against 26 per cent who say it has. On hands-on learning the field is split almost evenly: 37 per cent say opportunities have shrunk, 36 per cent say they have not.

Then there is the figure that ties the whole thing together. Nine in ten participants, 89 per cent, have experienced AI recommendations leading to incorrect outcomes at their organisation. Around two-thirds now spend more time deciding when to trust or act on an AI-generated recommendation, 65 per cent, and reviewing or validating AI outputs, 63 per cent.

Sit with that pairing. The field has handed its reading work to systems that are wrong often enough that nine in ten practitioners have watched it happen, and the new work created in exchange is checking those systems. Checking is a senior act. You cannot tell that a confident summary is wrong unless you have seen several hundred right ones, which is the whole argument in augmentation rather than replacement. So the profession has automated the exercise that builds the instinct, and replaced it with a task that requires the instinct. That is the squeeze, stated plainly, and it lands hardest on whoever joins next year.

What the UK numbers show underneath

Perception surveys measure what practitioners feel. The UK government measures what employers advertised, and the two sit oddly beside each other.

The Department for Science, Innovation and Technology published Cyber security skills in the UK labour market 2025 on 19 September 2025, with a correction the following February. It put roughly 143,000 people in cyber security roles across the UK economy, a 5 per cent rise on the year before. In the same release, core cyber job postings came to 32,370, a fall of 33 per cent.

A third fewer roles advertised into a workforce that grew. Both numbers are from one government release, and they rarely get printed together. DSIT does not attribute the fall to AI, and neither do we: hiring freezes, budget cycles and a correction after the post-pandemic advertising surge all sit in that number. What the pair does show is that a person trying to enter the field in Britain in 2026 is looking at a smaller advertised door into an occupation that has more people in it than it did a year ago. The insiders are fine. The doorway is narrower.

The same DSIT release found that about 49 per cent of UK businesses have a basic technical cyber security skills gap and 30 per cent report gaps in advanced technical areas. Those gaps get closed by people who were juniors five years earlier. Nothing else has ever closed them.

What a public record does for someone the ladder skipped

Here is what changes when the first rung thins. A hiring manager can no longer read a career at a glance. A title used to certify a stage: Analyst I, Analyst II, Senior. Strip out the junior post and the person who did the work anyway, in an adjacent role, on a night course, running a community group, arrives at an interview with a real body of work and no accepted way to prove it.

That is a documentation problem, and it is one an independent panel can help with. The Cyber Security Awards publishes four criteria for Rising Star in Cyber Security and scores every entry against them: Achievement, Proactiveness, Dedication and Contribution to the Industry. The Achievement criterion asks for “evidence of early-career accomplishments and measurable successes that demonstrate excellence and potential”. Dedication asks for “evidence of a strong commitment to professional growth, continuous learning, and advancing within the cybersecurity industry”. Every word in both is doing the same job: evidence, and a stranger who can check it.

The category page is blunt about what fails. “Weak nominations lean on potential alone. Promising, eager, one to watch. The panel respects potential, but it scores evidence.” Contribution is weighed against time in the field, so two years of work is read as two years of work rather than measured against twenty.

There is a holder to point at. Jubilian Ho Hong Yi was named Rising Star in Cyber Security in 2026. An Information Security graduate of the Singapore Institute of Technology and an OffSec instructor, he put time into the groups that bring new people into the field, from Division Zero to Cyber Youth Singapore. The panel recognised the breadth of that contribution this early in a career. Read it as a template rather than a biography. Work that helps other people get in, done while still getting in yourself, is legible to a panel even when it never appeared in a job title.

What we checked, and what we are not claiming

  • ISC2, Rethinking AI’s Impact on Cybersecurity Roles, published 14 July 2026. Survey of 856 cyber security professionals, fieldwork May 2026. All percentages attributed to ISC2 in this piece come from that report.
  • Department for Science, Innovation and Technology, Cyber security skills in the UK labour market 2025, published 19 September 2025, updated 2 February 2026. Source for the 143,000, the 5 per cent, the 32,370, the 33 per cent and the skills-gap figures.
  • The four Rising Star criteria and the 2026 holder are published on the category page and on the winner’s page, where anyone can check them.

What this programme does not hold is data of its own on pay, vacancies or hiring. We have not modelled any, and every number above is attributed in the sentence that carries it. The ISC2 figures record what practitioners perceive about their own organisations, which is not the same as a headcount, and the DSIT postings figure is not broken down by seniority in the release. A reader who wants the causal story about AI and junior hiring will not find it in either source, and should be suspicious of anyone who says otherwise.

FAQ

Entry-level cyber security jobs, answered

Are entry-level cyber security jobs disappearing?

They are thinning rather than vanishing. In a survey of 856 cyber security professionals carried out in May 2026 and published on 14 July, ISC2 found that 56 per cent said AI has somewhat or significantly reduced the need for entry-level positions over the past year. In the same survey, 53 per cent said AI is creating new types of entry-level role and 62 per cent said it has not reduced the need for foundational cyber security skills. The shape of the first job is changing faster than the number of first jobs.

How do you get into cyber security if the junior roles are automated?

By producing evidence somewhere other than a job title. The routes that still work are the ones that leave a trace a stranger can check: a tool or script others use, a disclosure handled properly, a community group run for two years, documented work inside an adjacent role such as service desk or infrastructure. Panels, hiring managers and awards all read the same thing, which is what you did and who it helped.

What is the Rising Star in Cyber Security award?

It is one of five individual categories in the Cyber Security Awards and honours an early-career defender whose work is already shaping the field around them. The panel scores four published criteria: Achievement, Proactiveness, Dedication and Contribution to the Industry. Contribution is weighed against time in the field, so a graduate two years in is read on trajectory and evidence. The 2026 holder is Jubilian Ho Hong Yi.

When do nominations for the 2027 Cyber Security Awards open?

Nominations open on 1 December 2026 and close on 28 February 2027. Every entry is read in full and scored against the four criteria published on its category page. A place on the shortlist cannot be purchased.

Somewhere a manager has an analyst who has been in post eighteen months. She arrived when the queue had already been thinned by a model, so she never got the five thousand boring alerts, and she built her judgement the harder way, by asking, reading and staying late. She has closed things nobody logged. She will not put herself forward, partly because she is busy and partly because she suspects eighteen months does not count.

It counts. Nominations for the 2027 Cyber Security Awards open on 1 December 2026 and close on 28 February 2027, every entry is read in full and scored against criteria anyone can read beforehand, and a place on the shortlist has never been for sale. If the ladder skipped a rung under someone you work with, put their name on the record and let the evidence do the rest.