The FireAI Security Blog

By FireAI Security & Research Team · Published

A career in AI cybersecurity: what you need to know

A career in AI cybersecurity: what you need to know

"AI cybersecurity" is not a single job title on any employer's org chart. It names a cluster of roles that have appeared inside existing security teams over the past few years, each drawing on a different part of the traditional discipline: testing AI systems the way a penetration tester probes an application, securing the software and pipelines that surround a deployed model, applying AI tools to detection and response work, and governing how an organisation adopts the technology in the first place. None of the standards bodies or workforce studies cited below treats these as one role, and neither does this article.

Background

The reference point most U.S. employers and training providers use to describe cybersecurity jobs in general is the NICE Workforce Framework for Cybersecurity, maintained by NIST and hosted by CISA. It organises the profession into work role categories — Oversight and Governance, Design and Development, Implementation and Operation, Protection and Defense, and Investigation — each broken into task, knowledge and skill statements rather than fixed job titles [1]. As of this writing, the published framework has no AI-specific work role category of its own; the roles described in this article sit inside its existing categories, borrowing vocabulary from newer, AI-specific reference material where the framework is silent.

That newer material comes mainly from three places: OWASP's Gen AI Security Project, which publishes the Top 10 for LLM Applications, a list of risk categories such as prompt injection, sensitive information disclosure, supply chain risk and excessive agency [2]; MITRE ATLAS, a public knowledge base of adversary tactics and techniques targeting AI systems, built as a companion to MITRE's ATT&CK framework [3]; and the NIST AI Risk Management Framework, which structures AI risk work into four functions — Govern, Map, Measure and Manage [4]. A practitioner in any of the four roles below is, in practice, expected to know at least one of these three documents.

On the labour-market side, CyberSeek — a joint project of NICE, CompTIA and the labour-analytics firm Lightcast — tracked 514,359 employer job listings for cybersecurity positions in the U.S. market between May 2024 and April 2025, against an estimated global cybersecurity workforce of about 4,970,000 people. Of those listings, CyberSeek found that 10 percent specifically referenced AI skills as a requirement [5]. That is a minority of postings, which matters for how to read the rest of this article: AI security work is currently an addition to a cybersecurity career, layered on top of a foundation, not yet a separate labour market of its own.

Evidence

AI red teaming is the most publicly documented of the four. Microsoft's AI Red Team, formed in 2018, describes its job as testing AI systems for both malicious misuse and ordinary failure, and its own account of the work highlights two ways it differs from testing conventional software: generative systems are probabilistic, so "the same input twice may provide different outputs," which forces repeated attempts rather than a single deterministic test; and the applications built on top of these models "change at a faster rate" than traditional software, so an assessment done once goes stale sooner [6]. Practitioners in this role use MITRE ATLAS as their working reference for cataloguing attack techniques against machine-learning systems, in the same way a conventional red teamer would reference ATT&CK [3].

Model and agent security is a narrower, more engineering-facing role: securing the application layer around a deployed model rather than the model's own weights or training data. OWASP's Top 10 for LLM Applications is the closest thing this sub-field has to a shared curriculum, and its categories double as a rough job description — prompt injection, insecure output handling, data and model poisoning, excessive agency granted to an autonomous agent, and supply-chain risk in the libraries and third-party models an application depends on [2]. People doing this work tend to come from application security rather than from data science, since the underlying skill is auditing how untrusted input flows through a system, applied to a newer kind of system.

Detection engineering using AI sits inside NICE's Protection and Defense category and overlaps heavily with existing security-operations work: building the rules, models and pipelines that turn raw telemetry into alerts a human can act on, now including AI-generated or AI-assisted signals among the inputs [1]. MITRE D3FEND, a knowledge graph of defensive countermeasures built jointly by MITRE and the NSA's Cybersecurity Directorate, is the closest published reference for this side of the work: it organises defences into six tactics — Model, Harden, Detect, Isolate, Deceive and Restore — and maps specific countermeasures to the offensive techniques they counter, giving detection engineers a shared vocabulary for what a given control actually does [7]. Nothing about D3FEND is AI-specific; the role is applying it to pipelines that now include AI-derived signals.

AI governance is the newest and, on the evidence available, currently the largest single area of stated employer and practitioner concern. NIST's own framework treats governance as one of its four core functions, encompassing organisational oversight, accountability structures and policy before any technical control is applied [4]. ISC2 ran a poll of more than 500 cybersecurity professionals on LinkedIn in September 2026 asking what most needs defining as AI reshapes the profession; 68 percent chose "AI governance and compliance," ahead of AI threat-modelling frameworks (16 percent), securing AI data pipelines (11 percent) and adversarial attack defences (5 percent) [8]. A poll of that size and format is not a scientific sample of the whole profession, a point this article returns to in Limitations, but the direction of the result — governance work outranking every technical category combined — is hard to read any other way.

Compiled from the sources cited in this article; none of these are official NICE work-role titles.
RoleWhat it doesComes fromReference material
AI red teamingProbes deployed AI systems for failures and misuse, repeatedly, given probabilistic outputsPenetration testing, adversarial ML researchMITRE ATLAS [3]
Model / agent securitySecures the application layer and supply chain around a deployed model or agentApplication securityOWASP LLM Top 10 [2]
Detection engineeringBuilds and tunes the pipelines that turn telemetry, including AI-derived signals, into alertsSecurity operations, SOC analysisMITRE D3FEND [7]
AI governanceSets policy, accountability and risk controls for how an organisation adopts AIRisk management, complianceNIST AI RMF [4]

Analysis

Two things stand out once the roles are laid side by side. First, none of them is a clean break from existing cybersecurity work — each is a traditional discipline (red teaming, application security, security operations, governance) applied to a newer kind of target. This matches what CyberSeek's data implies: with only 10 percent of listings naming AI skills specifically, most employers are not yet hiring a distinct "AI security" role so much as asking existing roles to cover more ground [5]. Second, the entry path into each of the four still runs through general cybersecurity foundations first. The NICE Framework's task, knowledge and skill statements for its existing categories — not a separate AI track — remain the baseline employers and training providers describe [1], and ISC2's entry-level credential, Certified in Cybersecurity (CC), which assumes no prior work experience, still covers general security principles, governance, identity and access management, networking, and security operations before anything AI-specific [9].

People enter these roles by a small number of well-worn paths rather than a single pipeline: a cybersecurity foundation (self-taught, a bootcamp or a degree) followed by specialising once inside a team; a software or data-science background that moves toward security once a team needs someone to secure what they built; and hands-on practice through capture-the-flag exercises, which now include AI-security modules. Carnegie Mellon University's CyLab Security Academy runs picoCTF, a free platform that has expanded "from basic security fundamentals to advanced areas such as AI security," and treats sustained participation, not a single certificate, as the evidence of skill it tracks over time [10]. What employers ask for, reading across the sources above, tends to be a working knowledge of one or more of NICE, OWASP's LLM Top 10, MITRE ATLAS or D3FEND, and the NIST AI RMF, alongside the general security fundamentals every one of the four roles is built on.

Recommendations

  1. Build the general foundation before the specialisation: the NICE Framework's existing categories, not an AI-only track, are still what most job descriptions draw on [1].
  2. Read OWASP's Top 10 for LLM Applications and at least skim MITRE ATLAS's case studies; both are free, public, and are the documents practitioners in these roles are expected to already know [2] [3].
  3. Practise on a CTF platform that includes AI-security challenges, such as picoCTF, rather than treating theory alone as sufficient [10].
  4. If governance interests you, study the NIST AI RMF's four functions directly; ISC2's poll suggests employers currently rate this area above any single technical specialisation [4] [8].
  5. Track how the underlying threats and tooling are actually evolving, rather than relying on any one static source, via a running research log such as the FireAI Radar.

Limitations

The NICE Framework, as published, does not yet define AI-specific work roles; the four groupings in this article are this publication's synthesis of adjacent standards, not an official taxonomy, and job titles for the same work vary widely between employers [1]. ISC2's governance poll drew more than 500 respondents from a single LinkedIn audience self-selected to answer it; that is a real signal of practitioner sentiment, not a probability sample of the profession, and its margin of error is not stated [8]. CyberSeek's 10 percent figure counts any listing that mentions AI skills at all, which may include general AI literacy rather than AI-security work specifically, and covers the U.S. market only [5]. On pay: the only fetched source with concrete salary figures, ISC2's 2024 global certification data, is not specific to AI-security roles — it reported global average salaries from $94,948 for the entry-adjacent SSCP credential to $119,577 for CISSP as of May 2024 — and no source consulted for this article gives a separate, reliable figure for AI-security specialists [11].

How FireAI and HisnLabs fit in

None of the four roles this article describes is something a firewall performs; FireAI is a narrower, on-device tool, and the honest link to a career in this field runs through practice and reference material, not through the product itself.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.

Sources