Cybersecurity Roadmap 2026: The New Way Into Cyber [5 Steps]
If you're following the usual cybersecurity roadmap, you're probably being pointed at the exact jobs AI is taking over first. Get a few certifications, land a junior job watching alerts or running scans, then climb the ladder for years. That advice isn't wrong about the certifications. It's wrong about where they lead.
I've been in cybersecurity for 30 years, and I've trained over 500,000 people through StationX, so I watch closely what gets people hired and what has quietly stopped working. In this guide, we'll look at what changed, what's happening to entry-level jobs, and the five steps I'd follow if I were starting today. Each step comes with something you can do this week.
First, the thing that changed.
TL;DR if you've only got 30 seconds
AI now finds and exploits real security bugs on its own, cheaply. The hands-on work that entry-level jobs were built on is going to machines.
The two classic first jobs in cyber score badly for how hard they'd be for AI to take over. On a scale where 0 means AI could easily do the job and 100 means very hard to replace, a Tier 1 SOC analyst (the person who watches a company's security alerts and decides which are real attacks) scores 5.4. A junior penetration tester (someone paid to break into a company's systems so the holes get found before criminals find them) scores 6.4. Those are the two jobs the old roadmap aims you at.
The new roadmap: learn to direct AI, learn the foundations for understanding, build real tools, get support, then choose how to use what you can do.
You can start this week for about $20 a month.
How to Get Into Cybersecurity Has Changed
In April 2026, Anthropic (the company behind Claude) pointed a new model, Claude Mythos Preview, at real software. Not practice challenges or training labs. Real code that runs real systems.
One of the things it found was a bug in OpenBSD, an operating system famous for being built with security first. The bug had been sitting there for 27 years. It let an attacker crash any OpenBSD machine that answered over the network, and nobody had spotted it in all that time.
The cost is the part that should change how you think about your career. According to Anthropic's red team (its in-house team that tests what its models could do in the wrong hands), the run that found that bug cost under $50. The whole search, a thousand runs that turned up several dozen more findings, cost under $20,000. The same setup also found a 17-year-old flaw in FreeBSD, logged as CVE-2026-4747 (a CVE is the public ID number every known security flaw gets), and then wrote a working attack for it, fully on its own.
Think about what that replaces. Finding a bug like that used to take an elite team, months of work, and no guarantee of finding anything at all. Now it's a machine and a budget any criminal group could afford.
And it won't stay with one company for long. Logan Graham, who leads Anthropic's frontier red team, told Axios he expects other AI companies to release models with similar abilities in as little as six months, and within 18 at the outside.
So why does a bug in an operating system matter for your first job? Because of what it does to the jobs at the bottom of the ladder.
What's Happening to Entry-Level Cybersecurity Jobs?
I built a tool called JobZone Risk to answer one question: how hard would it be for AI to do this job? It breaks each role into its day-to-day tasks, checks which ones AI can already do, and scores the role from 0 (easy to replace) to 100 (very hard to replace).
Take the classic first job in cybersecurity, the SOC analyst. A SOC (security operations centre) is the team that watches a company's security alerts all day and decides which ones are real attacks. SOC Analyst (Tier 1) scores 5.4 out of 100. A penetration tester is someone a company pays to break into its systems, so the holes get found before a criminal finds them. Junior Penetration Tester scores 6.4.
Those are the two jobs the old roadmap points you at. The reason they score so low is in the tasks. A junior pen tester spends much of the day on reconnaissance: running scanning tools, gathering information, writing up the basic findings. AI agents now do that whole sequence themselves. An AI agent is an AI you hand a goal rather than a single question: it works out the steps and carries them out itself, running a scan, reading the results, picking the next tool, running that, and so on until the job is done. A Tier 1 SOC analyst spends the day sorting alerts. Picture a long queue of warnings every shift: a login from a new country, a file that looks odd, a sudden spike in traffic. Most turn out to be harmless, and the job is to check each one, decide, and pass the real ones up. That's exactly the kind of repetitive judgement AI now does at machine speed.
Will AI Replace Cybersecurity Jobs?
Some of them, yes, and it's worth being honest about which. The problem with the old advice isn't that certifications are bad or that studying is wasted. It's that the old path trains you to work at human speed (typing commands, running tools by hand, grinding through alerts) and then aims you at the exact jobs AI now does well.
Follow that roadmap and you could spend years and thousands of dollars becoming slower competition for a machine. So if the bottom rung of the ladder is disappearing, how does anybody get in now?
Step 1: Learn Agentic Engineering
I'll show you what this step looks like before I give it a name, because the name means nothing until you've seen it work.
Recently I wanted a security review of a feature on one of our live websites. The old way goes like this: a specialist spends a few days on it, writes a report, someone fixes the problems, then someone tests the fixes. A week, maybe two.
What actually happened: I typed one sentence in plain English. Review this feature for security problems. My system started five AI agents:
Three hunters. Each one looked for flaws from a different angle.
A challenger. Its only job was to argue with the first three and throw out the false alarms.
A referee. It weighed both sides and gave the final verdict on what was real.
Then I typed "fix these", and it fixed them, tested the fixes and shipped them to production (the live website real customers use). A few sentences from me, and I never opened the code. That loop used to be someone's full-time job. (If you want the full method, it's written up in our secure code review guide.)
Look at who did what. In the old way of working, a person does the work and you get the result. In the new way, a person directs an AI system and the system does the work. You stop being the worker. You become the one who decides what gets built and whether it's right.
Why the economics matter
Now think about what that does to a business. Take a made-up but typical example: a security consultant who spends about a week on each web application test, between agreeing with the client exactly what will be tested (known as scoping), testing it and writing the report. That's roughly four clients a month. If a system of agents does the scanning, the first draft of the findings and the retesting, and the consultant spends their time checking the results and talking to the client, the same person can take on far more clients in the same month. Scale that up to a whole company, and the one that works this way can win on price and on speed against the one that doesn't. The advantage doesn't go to the smartest people. It goes to the people who learn to work this way first, and that's why it's step one.
What it's called
The method you just saw is called agentic engineering: you direct AI agents to do the work, and you stay responsible for checking that the result is right. Someone who works this way is what I call AI-driven, for example an AI-driven penetration tester or an AI-driven security engineer. You use AI to do your job, and you direct it properly, so what comes out is safe, secure, tested, and something you'd put your name on.
The name comes from Andrej Karpathy, a founding member of OpenAI and the person who coined "vibe coding". In February 2026 he wrote that "agentic engineering" was his favourite name for this way of working.
The difference from vibe coding is easiest to see with an example. Say you ask an AI for a login page for your website. Vibe coding is taking whatever it hands you, putting it live, and hoping nobody tries a million passwords or types something nasty into the username box. Agentic engineering is asking for the same page, then having agents test it, attack it and check it against a security standard, and only putting it live once you've reviewed what they found. Same AI, very different result. It's vibe coding with engineering discipline behind it.
It's also a skill, like learning software development or cloud. It isn't magic and it isn't genius level. You stay in charge the whole way through, and the AI does the labour. We go much deeper on it in our guide to agentic engineering and our free AI-Driven Engineering course.
Do this week
Pick one AI coding assistant. This is a tool where you describe what you want in plain English, and it writes the code, runs it and fixes its own mistakes while you watch. Choose from Claude Code (included in Claude Pro at $20 a month), Cursor ($20 a month for Pro) or OpenCode (free and open source; you pay for the AI model you plug in). It barely matters which. Then give it this first task: "Build me a simple password checker. I type in a password and it tells me whether it's weak, medium or strong, and explains why." To check the result, try "password123" and then a long phrase like "purple-tractor-sings-at-dawn". If the first one doesn't come back as weak, tell the assistant what's wrong and have it fix it. Finally, ask it to explain each part of the code in plain English. That's the first rung, and everything else in this guide stands on it.
Which raises the obvious question. If the AI does the building, do you still need to learn the technical side at all?
Step 2: Master the Foundations Differently
Yes and no. You can't supervise what you don't understand, so you still need the foundations. But you need them differently, and that means learning less and more at the same time.
Less, because the hands-on layer is leaving. Think about how a calculator changed maths. Most of us don't do long division by hand any more, but we still need to know what division is and when an answer looks wrong. The same thing is happening in security. Take a network scan. The old way, you'd memorise the exact command and its options, type it in, and read the raw output line by line. Now you can ask an agent to scan your test network and tell you which machines look risky, and it picks the command, runs it and summarises what it found. What it can't do is tell you whether that summary makes sense. That part is yours. You won't be typing commands for a living, memorising command options, or learning a scripting language by heart. AI already does that part, in companies and at StationX. Every hour you spend on flashcards of command syntax is an hour spent on the part of the job that's already going.
More, because understanding now carries everything. How networks actually work, not how to configure them. How systems break. How an attack unfolds, step by step. What good security looks like, and why.
Why does that matter more now, not less? Because you become the supervisor of the agents. Take away your understanding and you're not an engineer directing AI. You're a passenger hoping it knows where it's going.
So here's a test for everything you study from now on. Am I learning to explain why this works, or just how to type it? The why is yours forever. The typing, let the AI have it.
A Cybersecurity Roadmap for Beginners: Do Certifications Still Matter?
They do, and you should still earn them. If you're starting from scratch, this is the order I'd take them in:
CompTIA A+. How computers and everyday IT work, if you don't already know. Official page
CompTIA Network+. How data moves between machines, and how it can be intercepted along the way. Official page
CompTIA Security+. How systems are attacked and defended. Official page
The order matters because each one builds the picture in your head that the next one needs. You can't follow how an attack moves across a network until you know how a network works. The caveat is how you study them. The exams still teach a lot of the hands-on layer, and I think they'll take time to adapt. Take them for the concepts, not the keystrokes and not the button presses.
There's one problem with knowledge, though, even the right knowledge. Understanding is invisible. Someone hiring you can't see it. There is something they can see, and the next step is about making it.
Step 3: Build Real Things With AI
You've probably heard "do projects and get practical experience" before. That advice was always right, and honestly, always slightly unfair. What could a beginner really build alone? A home lab, a few scripts, some simulations of work.
This is where AI-driven engineering changes everything for you. One person directing AI properly can now build things that used to take a team. For example:
Your own SOC. A real monitoring system watching real traffic, with AI sorting the alerts.
Penetration testing agents. Pointed only at targets you have permission to test.
A phishing analyser. Paste in a suspicious email and get a risk score with the evidence.
A vulnerability scanner with a brain. One that explains what it found and why it matters, instead of dumping a list.
These aren't hypothetical. In our AI Master's Program, the current cohort is building exactly these. One member built an email forensics tool: paste in any message and it scores the phishing risk in seconds, with the evidence laid out. Another built a tripwire system that plants fake passwords and logins around a network and raises the alarm the moment an intruder touches one. These are people who were beginners not long ago, directing AI and using the understanding they built in step two.
Every build goes on GitHub (the website where developers publish their code for anyone to see), where it's public, dated and yours. That's your new CV. Walking into an interview as the person who built a SOC is a completely different conversation from listing the certifications you sat.
Start small
Your first build is not a full SOC. It's something you can finish in a few days, or a week at most. Finish it, ship it, put it up, then build the next one. As you go, learn the engineering habits (testing, reviewing, checking the AI's work) that turn vibe coding into real AI-driven security engineering. The point isn't the first project. The point is becoming someone who ships.
Which path is right for you?
There are a lot of directions within cybersecurity. Offensive security means breaking into systems with permission so the holes get found first, like the penetration tester above. Defensive security means watching for real attacks and stopping them, like the SOC. Cloud security means protecting the systems companies rent from providers such as Amazon Web Services or Microsoft Azure instead of running their own. Governance means setting the rules: writing security policies, weighing risks and checking that the company meets the laws and standards it has to follow. And AI security means protecting AI systems themselves, for example stopping someone from tricking a company's chatbot into leaking private data. We built a free Cybersecurity Career Path Finder to help you choose. Answer a few questions about your background, your budget and your timeline, and it builds a personalised plan: the roles that fit you, their AI risk scores, the certifications and the salaries. You don't have to take its word for which jobs are safe, either. It shows you the tasks in each role and how many of them AI already does, so you can judge for yourself.
Which brings us to the step most people skip. And it's the reason most people who start this never finish.
Step 4: Get Support
Be honest with yourself for a second. Do you start things and not finish them? Most of us do, and the numbers show it.
Researchers at MIT and Harvard looked at everyone who signed up for their free online courses. In 2017-18, only about 3% finished (Reich and Ruipérez-Valiente, Science, 2019). But among the learners who paid and committed to a certificate, 46% finished. Same courses, same material. What changed was how committed people were going in. That study measured commitment, not support. It doesn't show that having people around you makes you finish. It does show that how seriously you take it matters a lot.
I've watched this happen for 30 years. Motivation fades, life gets in the way, and when you're learning alone, nobody notices when you quietly stop. Support is what keeps that commitment alive once the first excitement wears off. That's why, from what I've seen, support is arguably the most important step of the five. Even with all the others in place, I've found that people going it alone are much more likely to stop.
What we've seen in our own programmes points the same way: the people with a mentor and a small group to answer to are the ones who finish. Support isn't a comfort. It's the multiplier on every other step.
Find a mentor. Someone a few years ahead of you who can tell you when you're going the wrong way.
Join or start a mastermind group. A handful of people on the same or a similar path who meet, online or in person, usually weekly, to share progress and hold each other to it.
At the very least, find one peer. One person who checks in with you every Friday is enough to change the odds. Just don't start alone.
So now you have the way of working, the foundations, the builds and the support. That leaves the destination you've probably been picturing this whole time. And it might not be a job at all.
Step 5: Build a Cybersecurity Career on Capability, Not a Job Title
The old roadmap had one finish line: get hired, entry level, bottom rung, work your way up. But look at what you actually have if you follow the first four steps. You can take a security problem, direct AI to build the solution, judge whether it's right, and ship it.
That's a capability, and a capability can be used three different ways. Picture someone who builds a phishing analyser like the one in step three. They could join a company and run it for that company's staff. They could offer it as a service to a handful of local businesses that can't afford their own security team. Or they could turn it into a product anyone can subscribe to. Same skill, three different careers:
The employed expert. Companies need people who can do this, and there aren't many of them. Your builds won't make you senior on day one. You'll still need real experience on the job for that. But you walk in as someone who has shown they can build AI-driven security, not just someone holding certificates, and that is a much stronger place to start than competing for the alert-queue jobs AI is taking.
The consultant. The same capability sold to many companies instead of one. Your rates, your hours, your clients.
The founder. You can now ship a security product that used to need a funded team. Some people will take this capability and simply build the business themselves.
The money is real, too. In the US, the Bureau of Labor Statistics puts the median pay for information security analysts at $129,180 (May 2025), and Glassdoor puts the average for AI security engineers at around $190,000 (September 2026). You can see who is hiring for this right now, and what they pay, in our free AI-driven cyber security jobs tracker.
You pick, and the choice can change. Consult for a while, take a senior role, launch a product later. The capability is the asset. The career is just how you choose to spend it.
The skills AI can't do for you
Notice what matters most at this stage: explaining risk to someone who doesn't speak security, judging what's worth building, and earning trust. The soft skills the old advice mentioned matter more now, not less. And your CV and LinkedIn stop being lists of certificates. They become a portfolio of things you've built and the value you can offer.
Your Cybersecurity Career Roadmap at a Glance
Let's put the whole thing on one page. AI now does the hands-on execution, so the entry-level jobs built on execution are going, and that's why the old advice fails. Here's the new map:
Learn agentic engineering. Direct AI to do real work, and stay responsible for the result.
Master the foundations differently. A+, Network+, Security+, studied for understanding rather than keystrokes.
Build real things with AI. Small first, public on GitHub, then bigger.
Get support. A mentor, a mastermind group, or at least one peer.
Build a capability, then choose. Employee, consultant or founder, and you can change your mind.
There's a name for the person at the end of this roadmap: the AI-driven security engineer. The person who builds the systems that defend at machine speed, instead of running tools by hand. It's the role this field needs most and has least of. Everyone else is competing with a machine that found a 27-year-old bug for under $50.
If you're at the start, our free web-book Become the Cyber Security Expert the AI Era Demands is the best place to begin. And if you want to go all the way, with a mentor, real builds you ship, and a network for life, that's exactly what the AI Master's Program is for. It's application only, so see if it's right for you. Either way, don't do it the old way. Do it the new way.
Frequently Asked Questions
What is the new cybersecurity roadmap?
It is five steps for getting into cybersecurity now that AI does much of the hands-on work: learn agentic engineering (directing AI to do real work), master the foundations for understanding rather than keystrokes, build real security tools with AI, get support from a mentor or peer group, and build a capability you can use as an employee, a consultant or a founder.
Will AI replace cybersecurity jobs?
AI is replacing specific tasks, and the entry-level roles built mostly on those tasks are the most exposed. JobZone Risk scores SOC Analyst (Tier 1) at 5.4 out of 100 and Junior Penetration Tester at 6.4 out of 100 for AI resistance, both in its red, displaced zone. Roles where a person directs AI, judges the output and owns the decision are growing instead.
Do I still need certifications like Security+?
Yes. CompTIA A+, Network+ and Security+, in that order, are still the best way to build the mental model of how IT, networks and security fit together. Study them for the concepts rather than the button presses, because AI now handles more and more of the typing and clicking.
What is agentic engineering?
Agentic engineering means directing AI agents to do real engineering work while you stay responsible for the result: you decide what gets built, you check whether it is right, and the AI does the labour. Andrej Karpathy, a founding member of OpenAI, called it his favourite name for this way of working in February 2026.
How much does it cost to start learning agentic engineering?
About 20 dollars a month. Claude Pro (which includes Claude Code) and Cursor Pro both cost 20 dollars a month, and OpenCode is free and open source, though you pay for whichever AI model you connect to it.
How much do AI security engineers earn?
In the US, the median pay for information security analysts was 129,180 dollars in May 2025, according to the Bureau of Labor Statistics. Glassdoor puts the average for AI security engineers at around 190,000 dollars.
About the Author
Nathan House, Founder & CEO of StationX
Nathan House has 30 years of hands-on cybersecurity experience and is Cambridge-educated, holding CISSP, CISA, CISM, OSCP, CEH, and SABSA. He founded StationX in 1999 — one of the UK’s first cybersecurity companies — and has secured £71 billion in UK mobile banking transactions and the London 2012 Olympics, advising clients including Microsoft, Cisco, BP, Vodafone, and VISA. He authored the world’s most popular cybersecurity course — a #1 Udemy bestseller taken by over 500,000 students — and was named Cyber Security Educator of the Year 2020, AI Security Educator of the Year, and a UK Top 25 Security Influencer 2025. A DEF CON speaker and featured expert on CNN, Fox News, NBC, and the BBC, Nathan leads StationX’s training of more than half a million students worldwide.