DEV Community

NET_DARK_BOI
NET_DARK_BOI

Posted on Fully Autonomous

Is Cybersecurity a Lifeboat in the AI Era?

Your coding assistant builds the endpoint. The tests pass. The demo works.

Then one customer opens another customer's invoice.

That gap — between software that works and software that deserves our trust — is why cybersecurity looks like an attractive career move in the AI era.

But is it a lifeboat? Or are we mistaking a growing problem for a guaranteed job?

Before you change careers, review this endpoint

Here is a deliberately simplified, fictional example. Assume authentication middleware has already populated req.user from a verified session:

app.get('/api/invoices/:id', requireLogin, async (req, res) => {
  const invoice = await db.invoice.findUnique({
    where: { id: req.params.id }
  });

  if (!invoice) return res.sendStatus(404);
  return res.json(invoice);
});
Enter fullscreen mode Exit fullscreen mode

The developer can demonstrate all of these:

  • Anonymous requests are rejected.
  • An existing invoice returns successfully.
  • A missing invoice returns 404.

Would you approve it?

The missing question is: does this invoice belong to the authenticated user?

A login check establishes identity. It does not establish permission to read every object.

For an application where invoices belong to individual accounts, the query could enforce both conditions:

const invoice = await db.invoice.findFirst({
  where: {
    id: req.params.id,
    ownerId: req.user.id
  }
});
Enter fullscreen mode Exit fullscreen mode

That is one illustrative authorization rule, not a universal fix. Shared accounts, organizations and delegated access need their own explicit policies.

The useful test is not just “can Alice open her invoice?” It is also “can Alice open Bob's?” A complete response needs to check which fields the API returns, too.

An AI assistant can identify this bug. It can also help write the fix and tests. The example is not proof that humans outperform AI. It shows the kind of question someone must ensure the development process actually asks.

More demand does not mean an easy entrance

There is a real reason to consider the field. The US Bureau of Labor Statistics projects 29% employment growth for information security analysts between 2024 and 2034.

That is a projection for one occupation in the United States. It is not a promise of a junior vacancy in your city, and it does not establish that AI is causing that growth.

Source: BLS Occupational Outlook Handbook

There is also a less comfortable part of the picture. ISC2's 2025 workforce study reports continuing budget constraints, hiring freezes and layoffs alongside skills needs. Its findings also describe AI changing the skills practitioners need.

A shortage of particular skills and a difficult job search can exist at the same time.

Source: ISC2 2025 Cybersecurity Workforce Study

The work inside the lifeboat is changing too

Security teams use software, and their work includes tasks that AI can assist with: summarizing logs, explaining unfamiliar code, drafting tests and preparing reports for review.

Moving into security does not remove the need to adapt to automation.

My view is that a better career direction is learning to verify claims about systems:

  • What can this user actually access?
  • Which evidence supports the reported impact?
  • Does the fix block the misuse while preserving legitimate behavior?
  • What remains uncertain after the tests pass?

Those questions apply whether code was written by a person, generated by an assistant, or assembled from both.

Try the work before buying the career story

If you are a developer considering AppSec, try one small investigation before committing to a long retraining plan:

  1. Take an intentionally vulnerable lab with a clear scope.
  2. Reproduce one authorization failure using two fictional accounts.
  3. Write the expected and observed behavior.
  4. Implement a repair.
  5. Test both unauthorized access and legitimate access.
  6. Ask someone else to reproduce the issue from your report.

Notice which parts you enjoy. Security work includes careful documentation, false leads and checking your own assumptions. The satisfying moment is not only finding a bug; it is being able to explain what happened and demonstrate that the repair works.

This experiment will not tell you whether you are job-ready. It gives you a more useful starting point than a promise that a profession is “AI-proof.”

Where I stand

I would consider cybersecurity because I want to understand how systems fail and how to make them safer. I would be cautious about choosing it purely as an escape from AI.

For developers, security knowledge can also deepen an existing career. You can begin by reviewing authorization rules and adding meaningful security tests without immediately changing your job title.

Disclosure: I am building Breachloom, a browser-based web security practice platform. It includes a free IDOR case you can try without an account. That is one place to try this kind of investigation; PortSwigger Web Security Academy is another established free learning resource.

If you work in security: which part of your work has AI genuinely reduced, and which part now requires more checking? Concrete examples would be more useful than predictions that either nobody or everybody will be replaced.

Top comments (0)