Identity Security as a Career On-Ramp: What One CISO Actually Thinks

Silverfort's John Paul Cunningham argues AI is opening doors in cybersecurity rather than closing them, and identity is where new practitioners should focus first.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 2 min read
A vast server room bathed in cool blue and amber light, rows of illuminated rack units receding into the distance, access control panel with a glowing keypad mo
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Silverfort CISO John Paul Cunningham said publicly that AI in cybersecurity workflows creates opportunities rather than eliminating jobs.
  • Identity security is named as a practical entry point for practitioners new to the field.
  • The comments appeared in a video segment first published by Dark Reading.
  • No CVEs, threat actors or breach data underpin the claims: this is practitioner opinion.

Career advice from CISOs tends to age poorly. Technology shifts, threat priorities rotate; the skill that looks essential in January looks table-stakes by Q3. When Silverfort CISO John Paul Cunningham makes a claim about where newcomers should focus, stress-testing the reasoning matters more than taking it at face value.

His core argument: AI is not compressing headcount in security teams. It is changing what those teams do. The concern that AI automates analysts out of existence assumes the work is static. It isn't. Detection pipelines, triage workflows, identity governance reviews are expanding in scope even as tooling accelerates parts of the process. Our 18 June story "The AI-SOC Is Maturing Fast. Here Are the Human Roles It Actually Creates." found the same dynamic: autonomous triage is displacing Tier 1 work while creating a new class of specialist roles above it.

Identity is the specific domain Cunningham points to. That tracks with where attacker focus has moved. Credential abuse, session token theft, MFA bypass, the bulk of initial access tradecraft in 2024 and 2025 runs through identity infrastructure rather than perimeter exploits. For someone building relevant skills, understanding how authentication and authorization systems fail is foundational, not niche.

Should you take this at face value?

Cunningham works for an identity security vendor. His incentive to frame identity as the essential discipline isn't hidden. That doesn't make the argument wrong, but it should be weighted accordingly.

The claim that AI creates more roles than it displaces is also the standard technology industry position, and the evidence base is still thin. The narrower point is more defensible: AI tools currently augment analyst judgment rather than replace it. Prompt-to-detection pipelines still require someone who understands what they're hunting for.

For defenders considering where to build depth, identity governance and authentication abuse are legitimate focus areas. So are cloud entitlements and non-human identity management, an attack surface that barely existed three years ago.

One CISO's video segment is a data point, not a career plan. The underlying signal, though, is defensible.

© 2026 Threat Vectr