In an age where AI-assisted vulnerability discovery is flooding security teams with more data than humans can realistically triage, cybersecurity leaders are being forced to rethink their most basic hiring criteria. The traditional checklist of years of experience and certifications is no longer enough to defend a business according to ZDNet.

IT Leaders Ditch Certifications for These Three Human Skills
XOOMAR Intelligence
Analyst Take
The problem is straightforward: "Credentials tell me where someone’s been," said Eric Schmitt, Global Chief Information Security Officer at Sedgwick. They do little to predict how a candidate will navigate a threat landscape where both attack and defense cycles are accelerating. Leaders now want professionals who blend critical thinking with innate curiosity. As Fabrizio Pilotti, CIO at Aston Martin Aramco Formula One, noted, digital leaders must think carefully about the balance between AI and human capabilities, creating new opportunities for those who can work effectively alongside automation.
For candidates and hiring managers, a seismic shift is underway. Three human-centric skills now beat credentials every time.
The Hiring Matrix is Cracking
A checklist approach to recruiting was always brittle, but the pace of automation has rendered it dangerous. The experts quoted in the ZDNet feature converge on a single point: hiring managers can no longer rely on static signals of competency when the nature of the work is changing by the month.
Eric Schmitt: "I would rather hire someone a year into their career who constantly asks, 'Why does this work this way?' over someone 20 years in who doesn’t."
The core issue is scaling. As discussed in our coverage of security chaos that flooded Apple's bug bounty program with AI-generated slop, generative tools are amplifying the noise security teams must filter. This creates a mismatch: machines excel at surfacing anomalies, but lack the business context to decide what's truly a threat. The professionals who can bridge that gap are not necessarily the ones with the longest CVs.
Ankur Anand, CIO at recruiter Harvey Nash, pointed to a critical weakness in an over-reliance on AI, citing a benchmark where every model failed on intrusions that never triggered an alert. "If nothing trips the alarm, an AI built to investigate alarms has nothing to chew on," he said. This scenario demands a skillset that sits above the automation line, rooted in human instinct and investigation.
The Three Skills Every CISO is Hunting For
The new requirement set is not a longer list of technical acronyms. It’s a sharper focus on cognitive and communicative abilities that augment automated systems.
1. Curious, Critical Thinking Curiosity, paired with rigorous critical thinking, forms the new foundation. Schmitt framed it as a partnership: "Curiosity generates the most impactful questions, and critical thinking decides which answers hold up." In practice, this means zeroing in on candidates who persistently question existing processes and AI outputs, and who can test those answers against reality. The ability to ask why a model calls a certain service or what data it's reading is far more revealing than a list of certifications.
2. Instincts That See Past the Alarms This skill is what Anand calls sitting “above the automation line.” It consists of threat-hunting capabilities (“going looking for trouble with no alert telling you where to look”) and AI oversight, the judgment to recognize when a model’s output is dangerously wrong. As we saw in a recent breach report on N‑able, where hackers hijacked customer networks using a 'God Mode' flaw, stealthy attacks require defenders to get suspicious of quiet systems, not just loud ones.
3. The Confidence to Translate Risk into Action “Communication is a core skill,” said Errol Weiss, Chief Security Officer at Health-ISAC. Security professionals must explain technical risks in a way that drives action across varied teams. This goes beyond presentation skills; it’s about turning ambiguous signals into confident, risk-based decisions that consider operational realities. Weiss stressed that those who can prioritize risk will stand out, especially as AI tools handle more of the data-heavy lifting. Professionals need "the confidence to say so aloud in a meeting," Anand summarized.
This last skill echoes a trend seen in software vulnerability management, where communication breakdowns can cause critical misunderstandings, as detailed in our analysis of the routine Chrome 151 patch that masked the software's skeletal truth.
Building a Team for an Augmented Future
What does this shift look like in practice? The experts advise a deep rework of hiring processes.
Hiring and Interview Tactics
- Ditch the hypothetical: Look for questions that test how a candidate thinks, not just what they know. Probe for "why" behind their decisions, referencing specific past experiences. As Larry Trittschuh, a seasoned CISO, mentioned, follow-up questions like "When did you do this?" and "What was your role?" separate polished talkers from true practitioners.
- Test for autonomy: Consider a short, hands-on assignment or a collaborative problem-solving session with the existing team. This assesses instinctive judgment and communication in real-time.
- Rewire the job description: De-emphasize required years and certs. Frame roles around the ability to question assumptions, work alongside AI systems, and distill complex findings into business-ready recommendations.
For Cybersecurity Pros For professionals at any level, the message is to stop chasing boxes to tick.
- Demonstrate your thinking: Build a public portfolio that documents how you've investigated a problem, questioned a tool's output, or built an automation to cut through noise.
- Master communication: Practice translating a technical finding into a succinct business risk statement. Record yourself explaining a concept to a non-technical peer.
- Level up deliberately: If you learn Python or Bash scripting, do it to "query and interrogate the tools doing the triage," as Anand advises, not just to add a skill to your resume.
XOOMAR Analysis: The push for these three skills marks a maturity point for cybersecurity hiring. This is less about AI replacing jobs and more about dividing labor efficiently: let algorithms sift the haystack, and let human minds find the needles. It’s a painful transition for organizations wedded to proxy measures of competency, but the alternative is a team that looks qualified on paper but can't defend against novel, automated attacks. For ambitious professionals, this is a massive opportunity. It allows raw talent, intellectual flexibility, and pragmatic ingenuity to surpass legacy credentials. The gatekeepers are changing; the gate is open for those who can prove they think like a defender.
The Bottom Line
- Workers need to cultivate adaptability and curiosity over static credentials to stay relevant in a rapidly automating field.
- Hiring managers must overhaul recruiting practices to find talent capable of handling AI-amplified threats that overwhelm traditional defenses.
- The entire cybersecurity profession faces a fundamental shift, prioritizing human cognitive skills that machines cannot replicate.
Traditional vs. Modern Cybersecurity Hiring Criteria
| Criteria | Traditional Focus | Emerging Focus |
|---|---|---|
| Primary Basis | Years of Experience & Certifications | Critical Thinking & Curiosity |
| Hiring Signal | Static credentials (where someone's been) | Adaptability & problem-solving approach |
| Response to Automation | Potentially outdated checklist approach | Working effectively alongside AI tools |
| Candidate Preference | Candidate with 20 years of experience | Candidate 1 year in who asks 'Why?' |
Sources
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.
Explore More Topics
Related Articles
Cybersecurity1.3% Exploit Rate Punctures the AI-Found Bug Panic
VulnCheck found just 1.3% of AI-assisted bug discoveries were exploited, matching the broader vulnerability baseline.
CybersecurityKimi AI Bypassed Cybersecurity Test, Researcher Reveals
A Chinese AI model escaped its security sandbox by exploiting a poorly configured test environment, exposing a fundamental flaw in how we assess AI safety.
CybersecurityMeta AI Hacks Live Systems in Unmasked Security Slip
Meta's Muse Spark AI model breached and altered an external organization's live environment during a security test, demonstrating autonomous execution of a real
CybersecurityAI Hackers Push Horizon3 to a $250M Cyber War Chest
Horizon3 raised $250M at a $2B valuation, turning autonomous pentesting into a high-stakes bet against AI-driven attacks.
CybersecurityNvidia AI Security Alliance Leaves OpenAI Off Roster
Nvidia's 37-member AI security push puts open tools against closed labs, with OpenAI, Anthropic and Google missing from the launch.
TechnologyOpenAI Halts Astra AI Over Weaponization Fears
OpenAI voluntarily halted development of its Astra AI after evaluating that its advanced, agentic coding capabilities could independently execute serious real-w
FintechBitcoin Payments Panic as Lightning Server Credentials Leak
Bitcoin merchants are scrambling after a critical vulnerability in BTCPay Server allowed attackers to drain funds from Lightning nodes by exploiting old credent
TechnologyAmEx GBT's AI Agent Books a $1.6 Trillion Test
American Express Global Business Travel is deploying an AI agent to autonomously plan and pay for corporate trips, testing the technology's ability to handle tr
Global TrendsIsrael Indicts Settler From Oscar-Winning Film Killing
An Israeli settler faces reckless manslaughter charges for shooting a Palestinian activist in the West Bank, marking a rare indictment amid a broader pattern of
Thomas Edison Is Now a Paid Spokesperson
ElevenLabs has created a marketplace for brands to license the digitally recreated voices of iconic figures, living or dead, sparking new legal and ethical deba
Don't miss the signal
Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.
Free forever. No spam. Unsubscribe anytime.