Table of Contents
ToggleIn 2026, job boards have begun to show a new job title that barely existed three years ago: AI/ML Security Engineer. SANS reported more than 2,500 active postings for this role on job platforms as of 21 March 2026. Separately, SANS’s 2026 workforce report found that 60% of surveyed organisations saw skills gaps as a greater challenge than staff shortages. [sans]
For cybersecurity professionals looking to switch jobs in 2026, AI security skills are rapidly moving from the “nice-to-have” category towards must-have requirements.
What is meant by the term “AI security”?
It can be quite confusing to differentiate between two things:
- Using AI for threat detection
- Protecting AI systems, which includes the models, training data, APIs and user prompts
The latter is the main focus of “AI security” as a specialty. Cybercriminals can:
- Poison training, fine-tuning, or retrieval data, causing a model to learn incorrect patterns or retrieve inaccurate information.
- Exploit exposed APIs or excessive permissions to access models, data, or connected systems.
- Use carefully crafted prompts or untrusted content to manipulate an AI system.
- Extract sensitive information or trigger unintended actions through connected AI tools.
These risks may not be fully covered by traditional network security playbooks, which is why “AI security” is becoming a growing specialty in the IT world.
What is the size of the skills gap at present?
The cybersecurity skills gap remains significant, while demand for AI-related capabilities is increasing.
According to ISC2’s 2025 Cybersecurity Workforce Study, AI was the number one skills need, with 41% of respondents identifying it as a top requirement. Cloud security ranked second at 36%.
ISC2’s 2024 Cybersecurity Workforce Study estimated that the global cybersecurity workforce gap is around 4.8 million people. However, ISC2 stresses that this is not a count of current job vacancies; it represents the difference between the number of cybersecurity professionals organisations say they need and the number currently available in the workforce.
What New Certifications Are Being Introduced?
In 2025, ISACA introduced two AI‑specific credentials with different target audiences:
- AAISM (Advanced in AI Security Management): Aimed at security leaders and people responsible for managing AI-related security risks. It is available to eligible CISM and CISSP holders.
- AAIA (Advanced in AI Audit): Aimed at auditors who review AI systems. It is available to professionals who meet ISACA’s relevant audit-certification eligibility requirements.
| Credential | Built For | Prerequisite |
| AAISM (Advanced in AI Security Management) | Security leaders managing AI security risk | Active CISM or CISSP |
| AAIA (Advanced in AI Audit) | Auditors assessing AI systems | Active CISA certification, or another ISACA-approved audit or accounting credential that meets AAIA eligibility requirements |
Both assume that the candidate already possesses a foundational qualification and is now specialising. That’s why people who already hold the main credential can get started faster.
Which abilities should be developed first?
Begin by identifying ways AI systems can fail, not just the ways that networks can fail.
For two editions in a row—2023/24 and 2025 – prompt injection has ranked first in OWASP’s Top 10 for LLM Applications. It involves embedding malicious or untrusted instructions in the material being processed by the AI system, which can manipulate the system’s behaviour or lead it to bypass intended controls.
Moreover, it makes sense to get a grasp of AI governance frameworks like the NIST AI Risk Management Framework (AI RMF) and its Generative AI Profile.
As organisations adopt AI, CISOs and other security leaders may need to address questions about managing AI models, data and related risks. In 2026, ignoring AI-related risks is becoming increasingly difficult for security teams.
When putting the above into practice, your initial learning loop should look like:
- Identify key LLM risk elements, including prompt injection, sensitive-data disclosure, data or model poisoning, excessive agency, and unbounded consumption.
- Find out how to evaluate AI applications against a standardised framework such as NIST AI RMF and its Generative AI Profile.
- Relate these risks to available security measures such as IAM, logging, DLP and secure SDLC, and identify possible deficiencies.
Wrapping Up
Many individuals entering AI security are experienced security specialists who have incorporated AI into their specialisation. Spoclearn offers CISM certification training in India for professionals seeking security-management training before moving into an AI-security specialisation such as AAISM.
Frequently Asked Questions
1. Is experience in machine learning and artificial intelligence a prerequisite for working in AI security?
No, you don’t have to be an AI or machine learning expert for every AI-security job. But a fundamental understanding of how machine learning and artificial intelligence systems work is getting more and more important for jobs that involve securing AI applications, models, data pipelines, or AI-enabled tools.
2. AAISM or AAIA—which one should you do first?
Pick the one that aligns with your role within the organization.
- If you are responsible for AI security management, AI-related risk, governance, or security leadership, you should choose AAISM.
- If you conduct reviews and assurance assessments of AI systems, you should choose AAIA.
There is no requirement to earn both credentials.
3. Is prompt injection indeed the foremost threat regarding AI safety at the moment?
Prompt injection is a major AI application security risk. Based on OWASP’s Top 10 for LLM Applications, prompt injection—LLM01—has been ranked first for two editions: 2023/24 and 2025. However, it should not be treated as the only important AI-security risk.