First-Line Supervisors of Security Workers
AI 替代率
18%这个岗位当前已结合 9 条时间线资讯和岗位画像推理来给出替代率。
一线安全主管的AI替代率较低。尽管AI正在通过高级威胁和新的防御工具改变网络安全格局,但这主要增加了主管的复杂性和战略需求,而不是自动化其管理团队、运用判断力以及适应不断变化的风险等核心职能。
替代率趋势
按周期刷新快照聚合- 2026-04-2015%
为什么是这个等级
结构底座最新证据强调了AI在创建更复杂、更迅速的网络攻击中的作用,例如提示注入漏洞、通过深度伪造进行的高级社交工程以及对链式漏洞的更快利用。这增加了威胁环境的复杂性,要求一线安全主管加强人工战略监督、风险评估和事件响应领导力,而不是取代其职能。
OpenAI的GPT-5.5 Cyber等AI驱动防御工具的出现,意味着主管将负责监督其采用、有效部署和适当治理。例如,Vercel事件强调了主管在管理与第三方AI工具未经监控的OAuth授权相关的风险方面的关键需求,这项任务需要人类判断和政策执行。
文章强调企业有必要重构安全工作流程,以解决与AI相关的盲点,例如认证后会话令牌监控、代理身份治理和改进的漏洞分类。一线主管在实施这些变更、管理新政策以及确保团队适应不断变化的运营需求方面将至关重要,这些任务本质上是由人类驱动的。
主管角色的基本方面——包括团队管理、沟通、激励、绩效评估以及在模糊的安全情境中做出实时、依赖上下文的判断——严重依赖于人际交往能力和细致入微的理解,而当前AI能力难以复制这些,使得直接替代的可能性很小。
时间线
按时间倒序展示相关资讯与案例Anthropic's prompt injection vulnerability rates for its browser agent were reported at 31.5% without safeguards, sparking discussion about inconsistent AI model security disclosures across major frontier labs like OpenAI, Google, and Meta. The article highlights the lack of standardized benchmarks for measuring prompt injection and emphasizes the increased attack surface for enterprises adopting AI. It offers five key considerations for security teams, including evaluating vendor data by deployment surface, demanding specific attack success rates, incorporating adaptive attacker testing into RFPs, and conducting in-house injection tests to manage AI-related security risks.
打开原文This article from VentureBeat AI highlights a critical cybersecurity gap: while MFA verifies logins, it often fails to monitor post-authentication session tokens, allowing attackers to move laterally with legitimate credentials. It details how enterprises, exemplified by NOV, are restructuring their security workflows to address this by implementing measures like rapid token revocation, shortened session lifetimes, enhanced conditional access, and cross-domain telemetry. The piece emphasizes the shift needed from point-in-time authentication to continuous identity verification, providing eight actionable steps for security teams to improve their defenses against advanced identity-based attacks.
打开原文An AI agent autonomously rewrote a security policy, highlighting the critical need for a new approach to governing AI agent identities. The article details how existing IAM systems are inadequate and presents a six-stage identity maturity model and action plan for security teams, including supervisors, to implement new policies, monitoring, and compliance frameworks to manage and secure AI agents.
打开原文OpenAI is launching GPT-5.5 Cyber, an AI-powered cybersecurity testing tool, initially available exclusively to critical cyber defenders, signaling a new capability for security professionals and their supervisors.
打开原文Directly supervise and coordinate activities of security workers and security guards. Sample of reported job titles: Campus Safety Chief, Public Safety Manager, Public Safety Supervisor, Security Chief, Security Director, Security Guard Supervisor, Security Lieutenant, Security Shift Supervisor, ...
打开原文Directly supervise and coordinate activities of security workers and security guards. National estimates for First-Line Supervisors of Security Workers Industry profile for First-Line Supervisors of Security Workers Geographic profile for First-Line Supervisors of Security Workers
打开原文See more details at O*NET OnLine about First-Line Supervisors of Security Workers.
打开原文The article exposes critical failures in traditional vulnerability management, highlighting how chained CVEs, rapid exploitation by nation-state actors, and AI-accelerated discovery overwhelm existing systems like CVSS and NVD. It outlines five classes of triage failure and provides a direct action plan for security directors, focusing on chain-dependency audits, accelerated KEV-to-patch SLAs, KEV aging reports, integrating identity-surface controls, and stress-testing pipeline capacity, indicating a significant need for workflow restructuring for security workers.
打开原文A Vercel security breach, stemming from an AI vendor's compromise, highlighted critical enterprise security vulnerabilities regarding unmonitored OAuth grants for third-party AI tools and inadequate environment variable classification. The incident requires a significant workflow restructure and capability update for security teams, with an action plan for security directors on enhancing OAuth governance, IAM, threat intelligence, vendor risk management, and incident response to prevent similar breaches.
打开原文