I Scored 3,500 Jobs. These 6 Cyber Skills Win.

13 min readBy Nathan House

Most advice about cybersecurity skills and AI is about hiding: find the corner of the job AI can't reach yet and stay there. I think that's backwards. The safest people in this field right now aren't hiding from AI. They're running straight at it.

I didn't want to say that on gut feel, so I tested it. I built JobZone Risk, a free tool that scores jobs on how exposed they are to AI, and it now covers more than 3,500 of them. So I took the cybersecurity roles that scored best and asked what the people in them actually do. Six skills kept coming up. Each one leads to one or two of those top-scoring roles, but a skill is something you can start building this week, and bolt onto the job you already have.

In this guide, we'll go through all six: what each skill is, why AI makes it more valuable rather than less, what real employers are asking for, and one small thing you can do this week to start. Then we'll work out which one you should learn first.

TL;DR if you've only got 30 seconds

SkillIn one lineJobZone score
1. AI-driven engineeringDirect AI to do real work, to your standardsRuns through all six
2. AI security engineeringDefend the AI a company deploys79.3
3. AI governance and auditingDecide whether AI can be trusted (no code)72.3 / 64.5
4. AI red teamingAttack AI on purpose, then help fix it64.2
5. Security architectureOwn the whole system when it goes wrong71.1 / CISO 83.0
6. OT securityProtect power, water and factories73.3

How I Scored 3,500 Jobs Against AI

JobZone Risk breaks each job into its tasks and asks, task by task: will AI do this instead of a person, help a person do it faster, or not touch it? Then it weighs the evidence around the job, like hiring data, pay trends and new laws. The result is a score from 0 (very exposed to AI) to 100 (safe). It lists 3,649 roles as I write this, so "3,500 jobs" in the video was, if anything, an undercount.

To give you a sense of the range: a tier 1 SOC analyst, the person who checks each security alert against a written procedure, scores 5.4. That's a job made of repeatable steps, and repeatable steps are what AI does best. The roles each of these six skills leads to score between 64 and 83.

The 6 skills on JobZone Risk, score out of 100 for the role each skill leads to: CISO 83.0 and Enterprise Security Architect 71.1 for skill 5 architecture, AI Security Engineer 79.3 for skill 2, OT/ICS Security Engineer 73.3 for skill 6, AI Governance Lead 72.3 and AI Auditor 64.5 for skill 3, AI Red Teamer 64.2 for skill 4. Skill 1, AI-driven engineering, runs through all six

So the six skills are my reading of what those roles have in common, not a separate score for each skill. Skill 1 is the exception: it isn't a role at all, so it has no score of its own. It runs through all the others.

One honest caveat before we start. A high score isn't a promise. It's a reading of what AI can do to each task today, and it will move as the technology and the law move. What a high score does tell you is where the work keeps a person at its centre, and why.

Skill 1: AI-Driven Engineering

The first skill comes first for a reason: it's the one you run all the others through. You may have heard it called agentic engineering. Same thing.

Let me be clear about what it isn't. It isn't vibe coding, where you type a prompt and hope for the best. And it isn't building an AI from scratch or getting a machine learning PhD. It's taking the AI tools that already exist, wiring them together, giving them your standards, and directing them to do real work. Wiring them together can be as simple as one AI tool drafting a report, a second checking it against your checklist, and you approving the result. In my experience, on the kind of work AI is good at, that runs at 10, 20 or 30 times the speed you could manage alone. Without losing the rigour and the security. Fast is easy. Fast and safe is the engineering skill.

Vibe coding versus AI-driven engineering: vibe coding means typing a prompt and hoping; AI-driven engineering means directing AI while keeping rigour and security

Here's a simple way to picture it. Think of a building site. The AI tools are the workforce. You're the architect: you set the goal, the standards and the safety rules, and the workforce builds to them every time. Work that used to need a whole team, you can now stand up on your own in an afternoon.

You're the architect, AI is the workforce: a person sets the vision and instructions, and AI agents carry out research, writing, analysis, development, design and publishing

That's why I put it first. Learn it, and you're not just a security engineer. You're an AI-driven security engineer. Not just a pen tester, an AI-driven pen tester. Same roles, machine speed, you in charge. You're not replaced by AI. You're the one running it.

📄 In real job ads: AbbVie's Agentic AI Security Engineer listing wants someone to "Build and deploy AI agents that automate security workflows" and says "we expect you to build with agents, not just build agents" (AbbVie careers, captured 27 July 2026, still live 1 October 2026). That's skill 1, written into a security job. We archive hundreds of these in AI-Driven Cyber Security Jobs.

🛠️ Try this week: take one boring task you do by hand, like writing up a weekly report. Write down your standard as a short checklist: what a good one must include. Give the checklist and the task to a chat assistant such as ChatGPT or Claude, then check its output against your list and fix what it missed. Once that feels easy, the next step is an AI agent tool like Claude Code, OpenAI's Codex or OpenCode, which can do multi-step work on your files.

If you want to take this seriously from an engineering and security point of view, I've written a free web-book on the whole shift: Become the Cyber Security Expert the AI Era Demands. And once you can build with AI, the next skill is protecting it, because every AI you deploy is a new target.

Skill 2: AI Security Engineering

The next three skills are the three sides of AI security: defend it, govern it, attack it. This one is the defensive side.

The 3 arms of AI security: defend, which means securing AI deployments; govern, which means independent oversight; and attack, which means red-teaming the models

Every company is racing to deploy AI, and every deployment is a new door into the business that has to be locked. Right now, a lot of organisations are doing a poor job of locking it. That's the gap this skill fills.

As an AI security engineer, you're the one who secures the AI. In practice that means three things:

Harden how the model is deployed. Who and what can talk to it, what data it can reach, and what it's allowed to do on its own.

Defend against prompt injection and data leaks. Prompt injection means hiding instructions in text the AI reads, so it does something it shouldn't. Our guide to 23 AI attack types walks through each one.

Build the guardrails. The checks that stop the AI being tricked or turned against the organisation that runs it.

And the demand only grows, because every new AI system is one more thing to protect. On JobZone Risk, AI security engineer scores 79.3. I checked it against all 35 security engineering roles JobZone scores, and it's the highest of them; the next is OT/ICS security engineer at 73.3. In our archive of AI-driven security job ads, 35 of the 661 listings have "AI Security" in the job title itself.

🛠️ Try this week: take one AI tool that you or your company already uses, a chatbot, a coding assistant or an email summariser, and threat model it. Ask: where could a prompt injection get in, and where could data leak out? That's defending AI.

For what these roles pay, see Highest Paying Cybersecurity Jobs, and the AppSec and product security listings show what employers ask for. But someone also has to decide whether an AI should be trusted at all. And that one needs no code.

Skill 3: AI Governance and Auditing

Most people miss this skill completely. AI governance means deciding the rules an AI system has to follow and checking that it does. Auditing is the checking part: can the system be trusted, is it fair, and could the organisation explain it to a regulator?

Regulators keep pointing the same way: towards independent human oversight of high-risk AI. The EU AI Act (Article 14) requires high-risk AI to be designed so people can effectively oversee it. The EU has pushed those high-risk rules back to December 2027, so companies have time to prepare and are hiring for it now. In the US, the NIST AI Risk Management Framework is voluntary, but it's the framework most organisations reach for. Our AI governance framework guide turns all this into ten questions.

There's a simple reason the check has to be a person. AI can help with the audit, but it can't be the independent check on itself. That's like asking a student to mark their own exam. If a model has a blind spot, asking the same kind of model to find it runs into the same blind spot. Someone independent has to own the judgement.

So if you come from compliance, risk or governance, or this just sounds interesting, this is your way in. No coding required. On JobZone Risk, AI governance lead scores 72.3 and AI auditor 64.5. Both are in the green zone.

📄 In real job ads: Liberty in Asia Pacific's AI, Governance and Incident Management Lead will translate global standards into local procedures, "using AI and automation to reduce manual effort and speed detection and response" (LinkedIn, captured 5 September 2026, still live 1 October 2026). Governance people are expected to use AI too. More in the GRC and risk listings.

Auditing an AI, the two questions: can we explain its decisions, and who is accountable when it is wrong? The check has to be independent: an AI can help audit, but it cannot sign off on itself

🛠️ Try this week: pick an AI system whose maker publishes documentation about it, like a public chatbot or an AI hiring tool with a published fact sheet, and ask the two questions that matter. Can they explain how it makes its decisions? And who is accountable when it gets one wrong? Write down what the documentation answers, and where it doesn't say. "The documentation doesn't say" is a real audit finding. That's governance.

Skill 4: AI Red Teaming

We've defended AI and governed it. The last side is attacking it, on purpose, ethically and legally. AI red teaming is the offensive side of AI security.

If the AI security engineer defends the AI, the red team attacks it. You think like an adversary and try to break the model before real attackers do. You jailbreak it, which means talking it out of its own rules. You poison what it reads. You hunt for the prompt that makes it leak secrets or do something it was never meant to do. Then you tell the company how to fix it. There's a whole toolkit for this now, which I cover in AI Red Teaming Tools.

The AI red teaming loop: jailbreak, talking it out of its own rules; poison, planting bad instructions in what it reads; leak, finding the prompt that spills secrets; report and fix, telling the team how to close each hole; then repeat before attackers do

As companies plug AI into everything, they need people who can break it safely. On JobZone Risk, AI red teamer scores 64.2, green zone, for an offensive career that didn't exist a few years ago.

📄 In real job ads: Capital One described a brand new AI Red Team as "building AI to attack AI so we can make our systems safer" (archived copy; the ad has since closed). Amazon's Senior Manager, AI Red Team advertises $208,300 to $281,800 a year in the US and asks for 10+ years in offensive security (Amazon Jobs, captured 26 July 2026, still live 1 October 2026). That's an advertised band for a senior role, not a typical salary. See the offensive security listings.

🛠️ Try this week: try jailbreaking a chatbot: get it to say something it shouldn't. We've built one you can legally practise on: SecureBot, which guards a secret flag across three levels. That instinct, "how do I make this break?", is the whole skill.

Skill 5: Security Architecture

Defend, govern, attack. But someone still has to own the whole system when it goes wrong. That's the fifth skill.

AI can build. AI can advise. But AI can't be accountable. When a decision goes wrong, a board doesn't want to blame a model. They want the person who designed the system, who owns the security and stands behind the results. There's a line I keep coming back to: you can outsource your thinking to an AI, but you can't outsource your understanding. The person who understands the whole system, and can stand behind it, is very hard to replace.

That's why architecture and leadership sit at the top of JobZone Risk. Enterprise security architect scores 71.1. Chief information security officer (CISO), the person in charge of security for the whole organisation, scores 83.0. Of course, you don't start as a CISO. You start by learning to think like an architect: where the trust boundaries are, which trade-offs you're making, and how to explain risk in plain English.

📄 In real job ads: APT-ONE in Berlin is hiring an IT/OT security architect to use AI-assisted tools in discovery, architecture reviews and documentation, "inklusive fachlicher Validierung und Freigabe der Ergebnisse": including expert checking and sign-off of the results (XING, captured 5 September 2026, still live 1 October 2026). The AI does the legwork. The architect signs it off. See the security architecture listings.

Find where trust changes hands, using a company expenses app: a receipt crosses a trust boundary from your laptop to the expenses app, and card details cross another from the expenses app to a payment service run by another company. At each boundary ask what crosses, who can see it, and what happens if the other side is compromised

🛠️ Try this week: take any system you use, your company's expenses app, say, and sketch the data that flows through it. Then find the line where trust changes hands, like the point where your laptop hands data to a cloud service. That's architectural thinking.

Skill 6: OT Security

Everything so far lives in the digital world. The last skill is protected by something AI can't safely get near: the physical world.

OT security means protecting operational technology and industrial control systems (ICS): the computers that run power grids, water plants, factories and production lines. The systems that make real things work.

This skill has a wall AI can't safely get past. These are physical systems, where a mistake can mean an explosion or a blackout. Much of the equipment is decades old. And no regulator is letting an AI run a power station end to end on its own. There has to be a person on site who owns it. AI can assist here, but it can't be trusted on its own.

On JobZone Risk, OT/ICS security engineer scores 73.3, one of the most AI-resistant specialisms in the field. The listings are rarer: only a handful of the ads in our archive are OT roles, so treat any pay or demand figure for this area as a small sample. If you want to go deeper into why this wall holds, the OT section of Will AI Replace Cybersecurity Jobs? covers it with real incidents.

🛠️ Try this week: open the free NIST SP 800-82 Rev. 3, Guide to Operational Technology Security (in the video I called it "NIST 882"; this is the one) and read section 5.2.3 on network security, with its Figure 16. That figure uses the Purdue model as its example: a layered map of a plant, from the physical machines at the bottom to the business network at the top. Sketch the layers in your own words. It's a useful starting map for any OT system.

The Purdue model, simplified: Level 5 enterprise network, Level 4 business systems, Level 3.5 industrial DMZ as the buffer between IT and OT, Level 3 site operations, Level 2 supervisory control with HMI and SCADA screens, Level 1 basic control with PLCs, and Level 0 the physical process of sensors, valves, motors and pumps 6 cybersecurity skills AI makes more valuable: 1 build, 2 defend, 3 govern, 4 attack, 5 architect, 6 protect

So that's six skills. Build with AI, defend it, govern it, attack it, architect the system, and protect what AI can't reach. Notice what ties them together. None of them is about running a tool by hand. They're all about directing AI, or owning what AI can't be trusted with. That's the whole shift.

Which Cybersecurity Skill Should You Learn First?

Start with skill 1. AI-driven engineering is the spine that runs down every one of the other five, and it multiplies everything else you do. My view is that if you don't learn it, you'll end up working next to people who get 10, 20 or 30 times your output on the tasks AI handles well. That's not a threat, it's economics. If you want the full breakdown of how it works, read Agentic Engineering: How to Work 10-40x Faster With AI.

Then pick your second skill by where you're coming from:

You come from compliance, audit or risk. AI governance and auditing. Your background is the qualification, and there's no code.

You're technical and like building things. AI security engineering. The highest-scoring engineering role in cyber.

You like breaking things. AI red teaming. Your pen testing instincts point at a new kind of target.

You see the big picture and explain it well. Security architecture, with the CISO path above it.

You like physical, real-world systems. OT security. Your work keeps the lights on and the water running.

Then check your own role. JobZone Risk is free: look up the job you're in now and the one you're aiming for, see where each one stands, and read its advice on moving up a level, especially if your current role is exposed to AI. Don't run away from this. Run straight at it.

If you want a structured way to build these skills, with real labs, real projects and mentorship, that's what the AI Master's Program is for.

Frequently Asked Questions

Which cybersecurity skills lead to the roles safest from AI?

The skills that pair security with AI. On JobZone Risk, the roles they lead to score among the highest for staying safe from AI: AI security engineer 79.3 out of 100, OT/ICS security engineer 73.3, AI governance lead 72.3, enterprise security architect 71.1 and AI red teamer 64.2. Underneath all of them is AI-driven engineering, the ability to direct AI tools to do real work to your standards.

What skills are needed for cybersecurity in the AI era?

You still need the basics: networking, operating systems, and how attacks work. On top of that, the skills that hold their value are the ones where you direct AI or own what AI can't be trusted with: building with AI, securing AI systems, auditing them, attacking them on purpose, designing whole systems, and protecting physical infrastructure.

Which jobs can AI not replace in cybersecurity?

No job is guaranteed, but roles where a person has to be accountable score highest. On JobZone Risk the CISO scores 83.0, and AI security engineer is the highest-scoring engineering role in cyber at 79.3. Entry roles built on repeatable tasks, like tier 1 SOC analyst, score much lower.

Do I need to code to learn these cybersecurity skills?

Not for all of them. AI governance and auditing needs no coding and suits people from compliance, risk or audit. Security architecture is more about judgement and explaining risk than writing code. AI security engineering and AI red teaming are the most technical.

What is AI red teaming?

AI red teaming means attacking an AI system on purpose, with permission, to find its weaknesses before real attackers do. That includes jailbreaking it, poisoning what it reads and tricking it into leaking data. On JobZone Risk the AI red teamer role scores 64.2, in the green zone.

Which cybersecurity skill should I learn first?

AI-driven engineering, because it multiplies every other skill. Start by taking one boring task you do by hand and getting an AI agent to do it to your standard, with you checking the output. Then pick the second skill by background: governance if you come from compliance, AI security engineering or red teaming if you're technical, OT security if you like physical systems.

About the Author

Nathan House

Nathan House, Founder & CEO of StationX

Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.