Before we talk about replacing the entry-level cybersecurity job, we have to be honest about what that job really is.
When I said this newsletter was coming back, I made one claim and left it there: the first rung in the cybersecurity job ladder is being automated, and a lot of it should be. Here is the rest of that story.
Nearly everyone I respect in this field learned in a very similar way: in an unglamorous chair, doing tedious tasks, facing a seemingly endless alert queue. We came from different places—the military, the IT help desk, a computer science degree, a career change at 38—but we converged on the same roles. The bottom of the ladder in an Incident Response desk, a SOC shift, or across any number of technical cybersecurity disciplines. Working as Tier 1 analysts as the alerts came in.
When you strip away the mystique, here’s what the role really was. You watched a queue. Alerts fired—an anomalous geographical login, an unsigned binary executing in temp, unusual outbound beaconing—and your job was to look at each one and decide: something or nothing. The vast majority of alerts were false alarms. You closed out most alerts, documenting why they were benign, and moved to the next one. You escalated the alerts that might be something up the ladder to Tier 2 and Tier 3. These were people who could investigate further than you could. Monitor, triage, escalate. That was the day. Over and over again.
On paper, it risks looking like data entry with a security badge. Plenty of people treated it that way. However, something was happening in that chair. Something that never showed up in a job description.
You were learning to tell the difference between a real threat and noise. Developing tacit knowledge—knowledge that cannot be codified in documentation or frameworks, but is acquired through repeated environmental exposure. You could see the same innocuous pattern a hundred times. The one time it turned out to be someone inside the network, you built an instinct that no course sells. You learned what “normal” looks like at your company. You learned which servers talk to which, which alerts your finance team trips every month-end, and which vendor software just behaves badly. That context isn’t in any framework. You can only absorb it by sitting close to the traffic for long enough that the abnormal starts to jump out at you.
That context isn’t in any framework. You can only absorb it by sitting close to the traffic for long enough that the abnormal starts to jump out at you.
You also learned from proximity. When you escalated something and a senior analyst walked you through what they saw that you’d missed, you got something most professions would envy: someone showing you how they thought, not just what to do. One-on-one, on real stakes, in real time. The alert queue put you next to people who were really good at what they did. It gave you a reason to talk to them every day and it gave you a steady stream of concrete problems to be wrong about safely. That’s a huge thing. It’s how expertise actually gets transferred. Junior professionals and more experienced leaders working shoulder-to-shoulder on problems that matter.
So the honest description of those entry-level, Tier 1 roles isn’t “the boring job you do before you get to do the real work.” It was the school, the apprenticeship—though nobody ever called it that. It taught you triage instinct, adversary intuition, and organizational context under the cover of a modest title. We wrapped the most important cybersecurity learning inside its least respected role, then wondered why we couldn’t explain how anyone became good at this. The answer was hiding in plain sight: they sat in the seat, and the seat taught them.
We wrapped the most important cybersecurity learning inside its least respected role, then wondered why we couldn't explain how anyone became good at this.
Why did we mistake those entry-level tasks for toil? Partially, because a lot of it was. The repetition and burnout were real. It would be disingenuous to romanticize the after-hours, false-positive marathons in hindsight. Partially, because those who made it to the top of the ladder had a quiet incentive not to look too closely at the tasks at the bottom of the ladder. The mystique flattered everyone. Lastly, if we’re being honest with ourselves, because we never really had to think about it. The apprenticeship ran itself. Every year a new cohort sat down to stare at the alert queue and, a few years later, some of them would graduate to the group of seniors who would train the next cohort. You don’t stare too hard at a process that appears to perpetually keep working.
That’s exactly why this moment—this nascent agentic AI revolution—demands that we finally look at it. The process doesn’t function on autopilot anymore. That entry-level seat is being redesigned, but we’re not really clear what the next iteration will look like. More to the point, those most valuable teaching aspects of entry-role are at risk, because we never precisely named them, measured them, or built them intentionally. You can’t protect what you refuse to see clearly. So this is me trying to see the challenge of this moment clearly, on the record, before the cybersecurity profession really hits crunch time.
More to the point, those most valuable teaching aspects of entry-role are at risk, because we never precisely named them, measured them, or built them intentionally.
Hold that image in your head: the ladder and the role on the first rung that taught everyone who ever climbed it. Next time, I want to look at who actually got to climb the ladder. There are many doors to get into this field, including the strange one that I came through. That’s why the field’s habit of letting people in from uncommon paths was one of its quiet strengths.
If the main door is narrowing, we’re going to need to remember the other ways in.
— Oritse
