The Cyber Mettle Podcast with Alyson & Omar

The Future of Cybersecurity Jobs in the AI Era | James McQuiggan S1E25

41 min · 19. Mai 2026
Episode The Future of Cybersecurity Jobs in the AI Era | James McQuiggan S1E25 Cover

Beschreibung

“AI won’t take your job” is comforting. But, James McQuiggan explains why that’s not entirely true and what cybersecurity professionals must do next. In this episode of The Cyber Mettle Podcast [https://www.youtube.com/@TheCyberMettlePodcast], Dr. Omar Sangurima [https://www.linkedin.com/in/dromars/] and Alyson M. Laderman, Esq. [https://www.linkedin.com/in/alysonladerman] sit down with cybersecurity veteran James McQuiggan [https://www.linkedin.com/in/jmcquiggan/] to discuss the uncomfortable reality of AI disruption, workforce resilience, human risk, deepfakes, and the future of cybersecurity careers. James brings more than 25 years of experience across cybersecurity, IT, SCADA systems, incident response, security awareness, AI, and cyber threat intelligence. Formerly a CISO Advisor at KnowBe4 and now founder of Apparent Security [https://apparentsecurity.com/], James shares candid insights on:  * Whether AI can actually replace cybersecurity jobs * Why repetitive work is most at risk * The rise of “vibe coding” and AI-generated software * Why human oversight still matters in cybersecurity * Lessons from Stuxnet, SolarWinds, ransomware, and Change Healthcare  * The cybersecurity challenges facing schools and educators * Human risk management and security awareness * The importance of community, mentorship, and paying it forward * Dad jokes as a cybersecurity branding strategy The conversation blends serious industry insight with humor, career advice, practical AI guidance, and a reminder that cybersecurity is ultimately still about people. If you're navigating AI disruption, building a cybersecurity career, or trying to future-proof your skills, this episode delivers practical perspective without the hype. ABOUT JAMES MCQUIGGAN James McQuiggan is the founder of Apparent Security, cybersecurity educator, speaker, and longtime security advocate with experience spanning IT networking, SCADA systems, incident response, AI security, and human risk management. He previously served as a CISO Advisor at KnowBe4 and teaches Cyber Threat Intelligence at Full Sail University. Subscribe to  ⁨@TheCyberMettlePodcast⁩  [https://studio.youtube.com/channel/UCyf4TYnc-0AKW79TbxfK3zw] to hear human conversations at the intersection of cybersecurity, business, law, AI, and human resilience. CHAPTERS 00:00 – Intro & Welcome 01:19 – James McQuiggan’s Cybersecurity Journey 03:56 – Can AI Take Your Job? 06:41 – Repetitive Work vs Human Judgment 09:39 – Why Humans Still Matter in Cybersecurity 11:11 – AI Mistakes, AWS Stories & Empty Databases 13:52 – Vibe Coding & AI-Generated Software Risks 16:34 – “Ship It Now, Fix Security Later” Returns 17:40 – Do We Need a Cybersecurity “Chernobyl”? 19:10 – Stuxnet & Critical Infrastructure Wake-Up Calls 20:21 – Retail Breaches, PCI & Ransomware Economics 22:32 – Why Some Organizations Still Ignore Cybersecurity 24:36 – School Systems, Human Risk & Teacher Targeting 27:56 – OT, SCADA & Availability in Critical Systems 28:46 – The Story Behind Apparent Security 29:27 – Dad Jokes, Presentations & Security Awareness 31:44 – Theater Background & Public Speaking 33:04 – Why the Company Is Called “Apparent Security” 34:35 – Wrestling, Branding & Memorable Gimmicks 37:18 – AI Career Advice & Paying It Forward 40:23 – Conferences, Community & Cyber Networking 41:58 – “The Most Secure Woman in the World” Joke 43:20 – Final Thoughts & Closing   TOPICS COVERED AI and cybersecurity careers, Human-in-the-loop security, SOC analyst evolution, Deepfakes and generative AI, Cybersecurity education, Security awareness training, Supply chain attacks, Stuxnet and critical infrastructure, Ransomware economics, Vibe coding risks, Community and mentorship in cyber    #CyberSecurity #ArtificialIntelligence #AI #CyberMettle #HumanRisk #Deepfakes #CyberCareers #InfoSec #SecurityAwareness #CyberPodcast #GenerativeAI #SOCAnalyst #Ransomware #CyberLeadership #KnowBe4 KEYWORDS: James McQuiggan Apparent Security Cybersecurity AI jobs Will AI replace cybersecurity jobs AI in cybersecurity Human risk management Cybersecurity careers 2026 Deepfake cybersecurity SOC analyst AI Generative AI security Cybersecurity podcast Cybersecurity leadership Cybersecurity education Vibe coding cybersecurity KnowBe4 cybersecurity AI workforce disruption Cybersecurity mentorship Cybersecurity community Ransomware discussion Stuxnet cybersecurity

Kommentare

0

Sei die erste Person, die kommentiert

Melde dich jetzt an und werde Teil der The Cyber Mettle Podcast with Alyson & Omar-Community!

Loslegen

2 Monate für 1 €

Dann 4,99 € / Monat · Jederzeit kündbar

  • Podcasts nur bei Podimo
  • 20 Stunden Hörbücher / Monat
  • Alle kostenlosen Podcasts

Alle Folgen

33 Folgen

Episode Why Cybersecurity's Talent Shortage Isn't What You Think | Jakub Zvernia on CyberPath Cover

Why Cybersecurity's Talent Shortage Isn't What You Think | Jakub Zvernia on CyberPath

Is cybersecurity really facing a talent shortage—or are we looking at the problem the wrong way? In this episode of The Cyber Mettle Podcast, Omar and Alyson welcome Jakub Zvernia, Technical Program Lead for Cyber Path, Australia's national cyber workforce professionalization pilot delivered by the Australian Computer Society. Together they explore why thousands of aspiring cybersecurity professionals struggle to land their first role despite persistent workforce shortages, why organizations need to rethink hiring, and how skills-first career pathways could reshape the future of the industry. The conversation also examines: • Why traditional recruiting models may be holding organizations back • The value of neurodiversity and diverse thinking in cybersecurity • How employers can better support career changers and veterans • Why cybersecurity education alone isn't enough • Building practical career pathways beyond entry-level roles • Why organizations—not just individuals—must invest in workforce development • Lessons from Australia's CyberPath initiative that have global relevance Whether you're a cybersecurity practitioner, hiring manager, executive, educator, student, or someone considering a career transition into cyber, this discussion offers practical insights into building a stronger, more resilient workforce. Chapters 00:00 Opening & Introducing Jakub Zvernia 02:18 What Is Cyber Path? 05:07 Why Graduates Still Can't Get Hired 08:55 The Business Case for Skills-Based Hiring 12:23 Career Changers, Veterans & Hidden Talent 16:55 Building Cyber Talent from Nontraditional Backgrounds 19:33 Why Entry-Level Isn't the Real Skills Gap 25:52 Preparing for an Aging Cyber Workforce 28:43 Learning Beyond Certifications 32:10 Why Employers Must Change Too 35:14 A Call to Action for the Cybersecurity Industry 37:01 Final Thoughts If you enjoyed this conversation, subscribe to The Cyber Mettle Podcast for more discussions at the intersection of cybersecurity, leadership, resilience, governance, and human performance. #Cybersecurity #CyberWorkforce #CyberCareers #Leadership #SkillsBasedHiring #CyberPath #CyberMettlePodcast

Gestern38 min
Episode The Truth About Studying for the IAPP AIGP | AI Governance Isn't About Memorization S1E32 Cover

The Truth About Studying for the IAPP AIGP | AI Governance Isn't About Memorization S1E32

The IAPP AIGP certification is becoming one of the most sought-after credentials in AI governance, but what does preparing for it actually teach you? In this episode of The Cyber Mettle Podcast, Omar Sangurima and Alyson Laderman go beyond exam prep to discuss something much bigger: how professionals actually learn. As Alyson works through an intensive 28-day AIGP bootcamp with Dr. Kyle David (Dr. Privacy) [https://www.drdavidprivacy.com/], the conversation explores: * Why memorization isn't enough * How certification exams can better validate real-world skills * AI governance versus legal practice * Different learning styles * Study strategies that actually work * Why asking questions is a professional strength, not a weakness * The surprising value of learning communities The discussion also highlights Dr. Kyle David's AIGP Master Class and why community, mentorship, and collaboration may ultimately become the most valuable part of the certification experience. Whether you're studying for the AIGP, working in AI governance, cybersecurity, privacy, compliance, legal, or risk management, this conversation offers practical advice that extends far beyond one exam. Chapters 00:00 Welcome Back to Cyber Mettle 03:04 Alyson Announces Her AIGP Journey 06:04 Why the AIGP Is Such a Challenging Certification 07:10 Should Certification Exams Test Memorization? 11:26 Real AI Governance vs. Passing the Test 16:03 What Better Certification Exams Could Look Like 20:54 Everyone Learns Differently 27:37 Inside an AIGP Master Class 33:17 Why Smart People Stay Quiet 39:57 Alyson's Personal Study Strategy 43:20 Learning, Humor & (Yes) Clown College 46:12 Ego Is the Enemy of Learning 53:45 Building Real Professional Relationships 55:09 Omar's Toastmasters Leadership Lesson 1:00:24 How to Create Better Learning Communities 1:02:22 Final Thoughts: Be Human 🎙 Subscribe for conversations on cybersecurity, AI governance, leadership, privacy, resilience, and professional growth. #CyberMettlePodcast #AIGP #AIGovernance #Cybersecurity #ArtificialIntelligence #Privacy #Leadership #ProfessionalDevelopment

14. Juli 20261 h 3 min
Episode Agentic AI vs Traditional Pen Testing | Dan Shallom on the Future of Cybersecurity Cover

Agentic AI vs Traditional Pen Testing | Dan Shallom on the Future of Cybersecurity

Can AI actually improve penetration testing, or does it create an entirely new attack surface? In this episode of The Cyber Mettle Podcast [http://youtube.com/@thecybermettlepodcast], Omar Sangurima and Alyson Laderman sit down with cybersecurity researcher and executive Dan Shallom to explore how agentic AI is reshaping offensive security, vulnerability discovery, and security assessments. Dan explains why today's AI isn't simply making penetration testing faster—it's changing how security teams think about attack surfaces, business risk, and human expertise. Topics include: • Traditional penetration testing vs. AI-assisted assessments • Why consistency and coverage remain major security challenges • Building AI agents that understand application workflows—not just vulnerabilities • OWASP Top 10 for LLMs and the new risks AI introduces • Why AI needs layered security, guardrails, and governance • Business-contextualized vulnerability prioritization • Human judgment vs. AI reasoning in cybersecurity • Why AI should augment—not replace—security professionals Whether you're a CISO, security leader, penetration tester, application security engineer, or simply trying to understand where AI fits into cybersecurity, this conversation offers practical insights grounded in real-world experience. If you enjoy conversations about cybersecurity, resilience, leadership, governance, and emerging technology, subscribe to The Cyber Mettle Podcast for future episodes. Chapters 00:00 Opening and Inspector Gadget nostalgia 01:22 Meet Dan Shallom 02:34 Traditional Pen Testing vs Agentic AI 05:42 Why Coverage and Consistency Matter 07:35 Hidden Attack Surfaces Inside Modern Applications 08:47 AI Guardrails and Secure Implementation 10:14 Can AI Discover Novel Attacks? 15:18 Why Access Control Remains a Major Challenge 17:45 Business Context Beats Raw CVSS Scores 23:08 Moving Beyond Traditional Vulnerability Scanners 25:20 Human Judgment Still Matters 29:21 OWASP for LLMs and AI Attack Surfaces 33:16 Security by Design 36:16 Can Legacy Organizations Adopt AI? 40:14 Infrastructure, LLMs and Modern Risk 43:14 Final Advice for Organizations Using AI 44:49 Closing Thoughts #CyberSecurity #ArtificialIntelligence #ApplicationSecurity #PenTesting #AgenticAI #CISO #CyberMettlePodcast

30. Juni 202643 min
Episode ISACA AAIR Certification Review: What to Expect from the Advanced AI Risk Exam S1E30 Cover

ISACA AAIR Certification Review: What to Expect from the Advanced AI Risk Exam S1E30

Thinking about the AAIR certification from ISACA? Just hours after completing the Advanced AI Risk (AAIR) exam, Omar Sangurima sits down with Alyson Laderman to share his candid experience, preparation approach, key takeaways, and lessons learned from one of ISACA’s newest AI-focused certifications. In this Cert Corner episode, Omar discusses how the AAIR exam compares to certifications like the AIGP, why "ISACA mode" matters when approaching certification exams, the role of AI risk within broader enterprise risk management programs, and what cybersecurity, governance, and risk professionals should understand about AI risk today. The conversation explores practical study strategies, exam structure, governance frameworks, AI risk management concepts, and why understanding business risk may be just as important as understanding the technology itself. Whether you're considering the AAIR certification, working in AI governance, cybersecurity, risk management, compliance, audit, or simply trying to understand how AI risk is evolving inside organizations, this episode offers a real-world perspective from someone who just completed the exam. In this episode: • Omar's immediate reaction after completing the AAIR exam • How the exam compares to AIGP and other ISACA certifications • Understanding "ISACA mode" and certification mindset • AI Risk Management Framework (AI RMF) preparation strategies • Governance, risk, and AI integration challenges • Why context matters when answering certification questions • The relationship between AI risk and enterprise risk management • Whether AI risk deserves its own certification domain • Lessons learned for cybersecurity and risk professionals Chapters 00:00 - Fresh Off the Exam: Initial AAIR Reactions 02:02 - What Is the AAIR Certification? 04:15 - Exam Format, Cost, and Proctoring Experience 06:39 - Comparing AAIR and AIGP Preparation 08:21 - Understanding “ISACA Mode” 11:44 - Certification Study Pitfalls and Exam Dumps 13:11 - Study Strategy and Preparation Approach 20:14 - How the Exam Questions Are Structured 27:04 - Key Domains and AI Risk Concepts 31:25 - Does AI Risk Deserve Its Own Certification? 36:46 - The Real Value of the Certification 40:35 - Final Advice for Future Candidates 42:48 - Why Studying AI Risk Matters #CyberMettlePodcast #AIRisk #AAIR #ISACA #Cybersecurity #Governance #RiskManagement #ArtificialIntelligence #AIGP #CyberLeadership

23. Juni 202641 min
Episode The Cybersecurity Risk Nobody Talks About: Identity Resilience with Muli Motola | Cyber Mettle S1E29 Cover

The Cybersecurity Risk Nobody Talks About: Identity Resilience with Muli Motola | Cyber Mettle S1E29

Your backups may be protected. Your data may be protected. But what happens if you lose access to the systems that let you access everything else? In this episode of  ⁨@TheCyberMettlePodcast⁩  [https://studio.youtube.com/channel/UCyf4TYnc-0AKW79TbxfK3zw], Omar Sangurima [https://linkedin.com/in/dromars] and Alyson Laderman [https://linkedin.com/in/alysonladerman] sit down with Muli Motola, CEO and Co-Founder of Acsense [https://acsense.com], to discuss one of the most overlooked areas of cybersecurity and resilience: Identity and Access Management (IAM). As organizations continue moving to the cloud and embracing Zero Trust architectures, identity systems have become the foundation of modern operations. Yet many businesses still lack a recovery strategy for the very systems that control access to everything else. Muli shares the real-world incident that inspired Acsense, lessons learned from large-scale identity-related breaches, and why identity resilience is becoming a board-level business issue. Topics include: * Why IAM has become a critical business dependency * The hidden risks of cloud-based identity systems * Shared responsibility between vendors and customers * Lessons from MGM and Caesars Palace * Identity resilience and disaster recovery planning * Operational mistakes versus cyberattacks * AI, automation, and identity management risk * Single points of failure in modern IT environments * What boards and executives should be asking today * How organizations can prepare for identity-related disruptions If your organization relies on cloud services, SaaS applications, remote work, customer portals, or Zero Trust security models, this conversation is essential listening. RESOURCES FROM ACSENSE Want to learn more about Identity Resilience, IAM Recovery, and Disaster Recovery Planning? Muli Motola and the Acsense team have published several free resources, including their Disaster Recovery Guidebook for Identity and Access Management. Explore the full resource library: https://acsense.com/resources/white-papers/ [https://acsense.com/resources/white-papers/] Recommended resource: Disaster Recovery Guidebook for Identity & Access Management Whether you're a CISO, IT leader, MSP, security practitioner, or business executive, these guides provide practical frameworks for thinking about identity resilience, recovery planning, and operational continuity. 🎙 About The Cyber Mettle Podcast The Cyber Mettle Podcast explores the intersection of law, business, cybersecurity, technology, resilience, and leadership. Hosted by Omar Sangurima and Alyson Laderman 🔔 Subscribe for future conversations on cybersecurity, resilience, business continuity, leadership, AI, governance, and emerging technology. CHAPTERS 00:00 Introduction 01:07 Meet Muli Motola 02:12 What Is Identity and Access Management? 04:31 Why IAM Is More Critical Than Most Organizations Realize 05:42 The Incident That Inspired Acsense 08:12 The Butterfly Effect of Identity Systems 09:31 Cloud Identity and the New Single Point of Failure 10:56 Lessons from MGM and Caesars Palace 13:56 AI, Automation, and Identity Risk 15:26 Why Identity Recovery Is So Difficult 17:24 Cyber Resilience and Immutable Recovery 19:03 Shared Responsibility in Identity Security 22:11 Who Understands Identity Resilience Today? 24:24 Operational Mistakes vs Cyberattacks 26:52 The Importance of Recovery Autonomy 29:00 AI Agents and Privileged Access Risks 32:34 Why Customers Are Worried About AI Modifying History 34:14 What CEOs and Boards Need to Understand 36:34 Building Effective Recovery Objectives 39:27 Why Identity Is Foundational to Business Continuity 43:33 The Future of Identity Resilience 48:25 Final Thoughts

16. Juni 202644 min