IT and tech

Cybersecurity specialist

Changing

AI speeds up both defense and attacks: threat analysis goes faster, while phishing and fakes have become more convincing. More specialists are needed, and there's a new area of work: protecting AI systems themselves.

  • 6 lessons
  • 4 tools
  • 2 resources
  • Checked: October 2026

Where this job sits on the map

In the same group: 78 of 100 professions.

What changes

  1. AI boils thousands of log events down to a short list of what needs attention.

  2. Phishing emails and voice fakes are more convincing, so employees are trained in new ways.

  3. New threats have emerged: prompt injection, leaks through AI services, unsafe plugins.

AI drafts, the person decides

How the work splits here: AI prepares a draft, the person checks it and makes the call.

AI makes the draft

What AI does

  • Reads event logs and flags what looks suspicious
  • Explains a vulnerability and suggests a fix
  • Checks code and configurations for common mistakes
  • Writes reports, policies and instructions for employees
You check itRead it, check the facts, fix it. Without this check the draft goes nowhere.
You decide and stay responsible

What stays with the person

  • Deciding what counts as an incident and how to respond
  • Accountability to the company and to regulators
  • Penetration testing only under a contract and with the owner's permission
  • Training people and dealing with the aftermath of attacks

What to learn first

6 lessons from the course, in order. Start with the first one.

  1. AI ethics and safety: hallucinations, attacks, biasUserHallucinations, prompt injection, bias, privacy and copyright: how not to trust AI blindly.Start here
  2. Security in Claude Code: .env, secrets and data protectionConfident userHow to prevent secret leaks: .env, .gitignore, Claude Code deny rules, a pre-commit hook and secrets in production.
  3. Permissions and securityBuilderClaude Code permission modes, secrets in .env and how to store keys in production.
  4. Plugin Security: 9 attack categories and a trust registryEngineerPlugin security: nine categories of attack, checks before and after installing, and a registry of trusted plugins.
  5. Prompt injection defense, the top security threat of 2026EngineerPrompt injection: six attack types, eight layers of defense, red team tests and an incident response plan.
  6. AI regulation & compliance 2026: the EU AI Act, GDPR, Anthropic's terms, and what small businesses should watch forBuilderAI regulation as of October 2026: the EU AI Act, GDPR, US state laws and a small-business checklist. A general overview, not legal advice.

Which tools to use

  • An AI assistant for long documents, analysis and code, with Claude Code and Cowork on paid plans.

    Freemium
  • Anthropic's coding agent for the terminal, your IDE and a desktop app, included in paid Claude plans.

    Paid
  • GitHub's AI assistant in your IDE and on GitHub, with chat, an agent, code review and a free plan.

    Freemium
  • AI search with sources: answers with links, Deep Research and the Comet browser.

    Freemium

Ready-to-use materials

  • A 30-second check before you hit send: what to remove, how to anonymize and what to do if it's already gone out.

    Free

How to earn with AI

We don't promise income: results depend on your niche, your market and your work.

  • Job

    Give AI the first pass over logs and reports, and keep the investigation and the decisions for yourself.

  • Service

    An audit of how a small company uses AI: what data goes to services, who has what access, what to configure.

  • Product

    A short course or a set of rules for employees: how to spot AI phishing and what never to send to chatbots.

Similar professions

Checked: October 2026