AI security is the newest real specialization in cybersecurity - not a rebrand, an actual new discipline with its own attack surface, its own frameworks, and as of mid-2026, more than 60 live roles on our board (already bigger than several established specializations). It is also the seam where security hiring is growing BECAUSE of AI rather than being displaced by it. Almost nobody has written the career path yet, so here it is: what the roles actually are, who they hire, and how to get in from where you stand.
What "AI security" actually means (three different jobs)
- Securing AI systems: protecting models, pipelines, and the applications built on them - prompt injection and jailbreak resistance, data poisoning, model and weight theft, supply-chain risk in training data and model registries, and the very un-glamorous work of putting authz around RAG systems that suddenly have access to everything.
- AI red-teaming: the offensive twin - systematically attacking models and AI applications before release: eliciting harmful behavior, extracting training data, bypassing guardrails, chaining agent tool-use into real-world impact. The fastest-growing niche inside offensive security.
- AI governance and risk: the GRC side of the discipline - the EU AI Act, ISO 42001 (the new AI management-system standard), NIST's AI Risk Management Framework, model inventories, and evidence that the systems behave as claimed. Regulation is creating these seats exactly the way data-protection law created privacy seats a decade ago.
Who gets hired (the three on-ramps)
- From AppSec / security engineering: the most common route. An AI application is still an application - identity, secrets, injection, supply chain - plus a new class of model-specific failure modes. If you can threat-model a web app, you can learn to threat-model an agent. Start from the security engineer path →.
- From ML engineering: the reverse door - people who build models and learn the security mindset. Rarer, and extremely well paid, because they can read the research.
- From GRC: the accessible door almost nobody has noticed. AI governance roles need exactly the skills a GRC practitioner → already has - framework mapping, evidence, audits - applied to a domain where experienced people do not exist yet. Nobody has ten years of ISO 42001 experience; the field is two years old. That levels the seniority playing field.
The skills to build
- LLM fundamentals: how models are trained, fine-tuned, and served; what embeddings, RAG, and agent tool-use actually are. You cannot secure what you cannot describe.
- The attack taxonomy: OWASP's LLM Top 10 is the shared vocabulary - prompt injection, insecure output handling, training-data poisoning, model theft, excessive agency.
- Classic security still carries: most real "AI breaches" so far are ordinary failures around AI systems - leaked keys, open storage, over-permissioned agents. Python (the #1 skill on our board) plus cloud fundamentals remain the base layer.
- For the governance track: the EU AI Act risk tiers, ISO 42001, and NIST AI RMF - readable in weeks, and almost nobody in the hiring pool has done the reading.
Proof-of-work (cheap to build, rare to see)
- A red-team writeup of an open model or an AI app you built yourself: attempted jailbreaks, injection paths through tools, what worked, written like a finding report.
- A threat model of a RAG or agent architecture - one diagram, the trust boundaries, the top five risks with mitigations.
- For governance: a gap assessment of a fictional company against ISO 42001 or the AI Act - the same artifact trick that works for GRC, in a field with no incumbents.
The market, honestly
We track 60+ live AI-security roles as of mid-2026 - titles like AI Security Engineer, LLM Security Researcher, AI Red Team Lead, and Senior AI GRC Engineer - concentrated at AI-native companies, the big security vendors adding AI features, and the enterprises deploying them. Pay generally lands at or above the equivalent security engineering band → because supply is thin. This is the rare corner of security where being early is still possible: browse the live AI security jobs hub →, set an alert, and build one artifact from the list above - you will be competing with far fewer people than in any other specialization on this site.
Live AI security roles
Related guides
Cybersecurity Hiring Pulse - July 2026: Who Is Hiring, What Pays, Where the Market Is Moving
The July 2026 cybersecurity hiring snapshot, measured from live postings across 200+ security companies: 901 o…
6 min read
Cloud Security Engineer Interview Questions in 2026 (IAM, Scenarios & What Senior Sounds Like)
The cloud security interview, decoded - the IAM questions that decide it, incident scenarios (public bucket, c…
8 min read
Security Engineer Interview Questions in 2026: Design, Depth & Judgment
What security engineering interviews actually test in 2026 - the design questions (service auth, CI/CD securit…
8 min read