The AI-driven restructuring that hit software engineering-smaller teams, agent-heavy workflows, and machine-speed output-is about to reshape cybersecurity. A March 2026 Federal Reserve Board working paper found annual coder employment growth is roughly 3% lower than before ChatGPT, while Gartner predicts 80% of organizations will evolve large software engineering teams into smaller, AI-augmented units by 2030. Security leaders now say similar forces are bearing down on SOCs, vulnerability management, and the structure of defender teams.
The autonomous SOC is moving from pilot to production
Security operations centers are the most visible front of this shift. AI agents are already handling initial triage work that once belonged to junior analysts. David Lindner, CISO at Contrast Security, described an incident where an agent pulled information from GitHub and Datadog before delivering an initial assessment. "I don't want to even call it a junior SOC analyst. It is a SOC analyst that does some initial triage," he said.
But organizations remain cautious about how much authority to hand over. Lionel Litty, CISO at Menlo Security, said his team uses agents to provide context and prioritize, but stops short of letting them decide unilaterally what to ignore or escalate. Jim Reavis, CEO of the Cloud Security Alliance, expects that boundary to shift quickly. "SOCs absolutely are going to have a layer of activity where it's going to be all agents making the decisions and doing the triage. Then the human in the loop is going to be at a higher level, more senior," he said.
Vulnerability discovery is abundant; absorption is the bottleneck
AI tools can already find and test problems in source code at scale. Caleb Sima, chair of the CSA AI Safety Initiative, said vulnerability discovery in source code "is done," though autonomously validating exploits against complex production environments still has "a bit of ways to go." The larger problem, however, is not finding flaws-it is triaging and fixing them.
"We don't have a problem finding problems. We have a problem triaging and remediating all the problems that we find," Lindner said. Litty pointed to the same dynamic from earlier static analysis tools that overwhelmed engineering teams with findings, most of which were irrelevant. "Engineering will just ignore you," he said. The bottleneck is absorption, and AI has so far widened it faster than it has cleared it.
Machine-speed attacks demand machine-speed containment
Autonomous attacks will force a corresponding shift in defense speed. Sima described a scenario where an attacker's agent lands and spawns 200 agents that map the environment, locate assets, and exfiltrate data before a human can respond. The countermeasure, he said, is environments where "the cloud, the application, and the endpoints should all be able to actively quarantine, move, and adjust controls at machine speed without breaking production."
Litty argued the foundation remains unchanged: least privilege and separation of duties. "How do I make sure that I have separated components, defense in depth, so that one vulnerability being exploited doesn't take my entire company down?" he said. Speed matters, but architecture still determines blast radius.
Teams get flatter, and the middle gets squeezed
Experts do not predict net job losses across cybersecurity. Instead, they see a barbell-shaped workforce emerging. "I think you'll see a barbell: top-tier, senior individual contributors and then juniors and interns. The middle is going to struggle," Sima said. Reavis described a flattening where senior people "go build things" rather than manage layers of coordination.
Lindner said the irreplaceable qualities are experience and judgment. "My team is uber-senior today, and I need that. I need them to fully understand and have the experience and the judgment to know how and when AI is going to work for us, and where we need to add different controls where AI isn't going to work." Litty added: "I'm definitely not seeing the humans going away in those areas for now."
For professionals looking to build these exact skills, structured training in AI for Cybersecurity Analysts covers threat detection, security automation, and SOC optimization-areas the article identifies as the first to transform.
From tool sprawl to an AI control plane
Sima envisions large language models becoming the interface layer across fragmented security products, letting operators control firewalls and endpoint tools conversationally without learning each product's interface. "AI becomes the interface and the glue across all of these fragmented security products," he said. Litty offered a counterpoint: existing tools will evolve rather than multiply. "So far, I'm not seeing an explosion of tools," he said.
What CISOs should do now
Security leaders should identify bounded, high-volume tasks-alert enrichment, initial triage, vulnerability prioritization-where agents can be tested with restricted authority. Reavis advised senior people to "go build things that create a new way of doing your job." Litty emphasized governance: maintain a registry of where AI is in use, monitor output quality, and perform drift detection to catch when agent performance degrades.
Sima stressed accountability. Every agent needs a named human or team responsible for it, with human review reserved for consequential or hard-to-reproduce situations. "There has to be a named owner," he said. The job is not to automate everything. It is to learn where agents work, restrict what they can do, and establish who answers when they fail.
Why this matters for IT and development professionals
The boundary between building software and defending it is thinning. As security teams adopt agent-driven SOCs and machine-speed containment, developers and IT operators will inherit more responsibility for security outcomes-whether through agent governance, vulnerability absorption pipelines, or designing systems that limit blast radius by default. Professionals who understand both AI for IT & Development and the operational realities of autonomous defense will be positioned for the flattened, senior-heavy teams that experts describe, while those in coordination-heavy middle roles face the most pressure.
Your membership also unlocks: