Share This:

Through conversations with managed service provider owners, I often hear optimism about AI’s ability to close the cybersecurity talent gap. In Part I of this series, we explored how MSPs can develop talent internally, create career paths, and use AI to remove repetitive work without replacing human judgment.

The reality is more complicated. If AI takes over the tasks that traditionally train new cybersecurity professionals, the industry could create a dangerous feedback loop.

MSPs face growing pressure to use AI for repetitive SOC and help desk tasks. The benefits are clear: smaller teams, faster triage, and lower costs. However, Yulia Plugatyreva, a Senior SOX and IT Auditor at Chime, warns that solving today’s staffing problem could create tomorrow’s skills shortage.

“MSPs understandably want AI to absorb repetitive SOC and help-desk work,” she said. “But much of that work has historically been the training ground for junior security professionals. Someone learns to investigate a real incident by reviewing hundreds of ordinary alerts first.” Her concern is structural. “If we automate that entire layer, we may improve productivity today while weakening the pipeline of experienced security professionals five years from now.”

Redesigning entry-level roles

Plugatyreva does not believe MSPs should preserve manual work solely for training purposes. Instead, she argues that MSPs must redesign entry-level roles around AI. “Juniors should review AI decisions, investigate exceptions, understand why alerts were escalated or dismissed, and gradually take ownership of more complex cases,” she said.

In her view, tomorrow’s cybersecurity professionals will need strong critical-thinking skills. “The valuable cybersecurity professional of tomorrow will increasingly be the person who can challenge the system when its answer looks wrong, not simply process another ticket.” As a result, the industry’s talent question is changing from “How do we hire enough people?” to “How do we create experts when AI does the beginner work?”

Expanding the talent pipeline

Jose Lejin P J, a Principal Member of Technical Staff at Salesforce and IEEE Senior Member, approaches the issue from a hiring perspective. His advice is straightforward: stop searching for the same candidates as everyone else.

“Stop hunting the same senior SOC analyst every enterprise is chasing,” he said. “That person is expensive, scarce, and often does not want ticket queues and customer calls.”

Instead, he recommends hiring people with adjacent experience and developing their cybersecurity skills. “Strong help desk, NOC, and sysadmin people already know your stack and your customers. They just have not been taught to read an alert.” According to Lejin, a curious network professional with some EDR experience can outperform someone with a résumé full of SIEM products but little practical judgment.

Creating career paths that stick

Lejin stresses the importance of creating a clear development path. “Write the path down so it is real,” he said.

He recommends a progression from help desk to junior SOC analyst to incident lead, with certifications and hands-on experience along the way. His suggested path starts with Security+, followed by CySA+ or a vendor EDR certification, and then SIEM work on real incidents.

Lejin also encourages MSPs to provide home labs and dedicated training time. “If training is nights and weekends if you are lucky, you will train them for the competitor who pays more.”

He views partnerships as a temporary solution rather than a long-term strategy. “Partnerships are how you buy time,” he said. “They are not a substitute for one or two people who actually know your environment.”

Where AI adds the most value

Lejin believes AI should handle repetitive work that consumes analyst time. “Use AI to do the L1 grind: enrich the alert, pull the host and user context, close obvious noise, and draft the first customer note. That is where it earns its keep,” he said.

At the same time, he warns against removing humans from important decisions. “Do not let it close anything that touches production or a customer without a person. You will still need humans for judgment, hunting, and the awkward call to the client.”

David Berwick, Director and Co-Founder of Adria Solutions, sees another challenge. Many MSPs limit themselves by looking for candidates who meet every technical requirement. “Holding out for someone who ticks every technical box can significantly restrict the talent pool, particularly for roles where demand already outweighs supply,” he said.

Instead, Berwick recommends focusing on candidates with transferable IT skills and providing a clear route into cybersecurity. “People coming from infrastructure, networking, or technical support may already have many of the foundations needed for SOC and security roles, with the right training and development.”

AI cannot replace human judgment

Berwick believes AI will reshape cybersecurity roles rather than eliminate them. “AI and automation can help relieve some of the pressure, particularly with repetitive, lower-level tasks,” he said. “However, I see this as changing the skills businesses need rather than removing the need for cybersecurity professionals.”

Organizations will still need people who can investigate threats, make decisions, and understand the broader business impact of security incidents.

Although the experts approach the issue from different perspectives, they agree on one point: the industry cannot automate its way to a healthy talent pipeline any more than it can recruit its way there.

AI can remove repetitive work, but only real-world experience and mentorship build the judgment that makes a senior analyst valuable.

Lejin summarized it best: “MSPs will not outbid big tech for hunters. They can out-train, out-document, and use AI so a lean team looks bigger than it is. If you treat the SOC like a help desk with better tools, you will keep losing people. If you treat it like a craft people can grow into, you can staff it.”

Photo: Andrii Yalanskyi / Shutterstock


Share This:
Kevin Williams

Posted by Kevin Williams

Kevin Williams is a journalist based in Ohio. Williams has written for a variety of publications including the Washington Post, New York Times, USA Today, Wall Street Journal, National Geographic and others. He first wrote about the online world in its nascent stages for the now defunct “Online Access” Magazine in the mid-90s.

Leave a reply

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.